Barcode Pro (barcode.fitinview.com) is operated by FitInView, Switzerland. You can reach us at support@fitinview.com. This page explains what data the service touches, why, and for how long. It is written to satisfy the Swiss Federal Act on Data Protection (FADP) and, for visitors in the EU/EEA, the GDPR.
The short version
- Designing a barcode happens in your browser. The value you type is not sent to us until you export or share.
- We keep no account data unless you log in or pay. Then we store your email and Stripe identifiers.
- Uploaded images and emoji are traced on our server in memory and discarded immediately. Nothing you upload is stored.
- We log anonymous-ish usage events (IP address, event name, time) for 90 days to see whether anyone uses the tool.
- The page loads a Google Ads tag for conversion measurement, and libraries and fonts from public CDNs.
What we process and why
| Data | When | Purpose | Kept |
|---|---|---|---|
| Barcode value, format, colours, shape | Export (Download/Copy) or the Copy link button | Rendering the file you asked for; the link puts the design in the URL | Not stored. Processed in memory per request. Web server logs record the request path (see below). |
| Uploaded image or rendered emoji | Shape mode: Upload or Emoji tab | Tracing it into an outline | Not stored. Discarded after the response. |
| IP address, event name (e.g. download_click), target, timestamp | While you interact with the studio | Usage statistics and abuse prevention | 90 days, then deleted automatically |
| IP address, first and last visit time | Trial timer when the paywall is on | Enforcing the free preview period | 90 days |
| Web server access logs: IP, user agent, URL, status, time | Every request | Security, debugging, traffic analysis | About 15 days (daily rotation) |
| Email address, login token, IP | You request a login link | Passwordless login | Token expires after a short time; email stays with your subscriber record |
| Email, Stripe customer and subscription IDs, subscription status and period end | You buy a pass or subscription | Granting and checking access, billing | For the life of the account, then up to 10 years for accounting records as required by Swiss law |
Cookies and local storage
- __Host-bk_auth: set only after you log in. Keeps you signed in. Secure, HttpOnly, same-site.
- __Host-bk_pending: short-lived, set while a Stripe checkout is in progress so we can match the result to your browser.
- bkTrialStart (localStorage): the time of your first visit, used for the free preview timer when the paywall is on.
- The Google Ads tag may set its own cookies (see below).
No cookie is set for pure design work before you log in or pay, apart from those the Google tag sets.
Third parties
- Stripe (Stripe Payments Europe Ltd, Ireland) handles all payments. We never see your card number. Stripe's privacy policy: stripe.com/privacy.
- Google Ads (Google Ireland Ltd). The page loads the gtag.js conversion tag to measure whether advertising leads to purchases. It sets cookies and transmits your IP address and page URL to Google. You can block it with a content blocker or Google's ad settings; the tool works fine without it.
- jsDelivr (CDN) serves the barcode, QR, decoder and colour-picker libraries and the emoji name list. Google Fonts serves the typefaces. Loading these sends your IP address and browser details to those providers.
- Hetzner Online GmbH (Germany) hosts the server and the encrypted backups. Backups are stored in Hetzner object storage in the EU.
We do not sell data and do not share it with anyone beyond the providers above, unless the law requires it.
We send email only for login links and payment-related notices. Stripe sends receipts separately. There is no newsletter.
Your rights
You can ask what we hold about you, have it corrected or deleted, receive a copy, or object to processing. Email support@fitinview.com; we answer within 30 days. Deleting your subscriber record ends any active access. If you are in the EU/EEA you may also complain to your local data protection authority; in Switzerland to the Federal Data Protection and Information Commissioner (FDPIC).
Security
All traffic is TLS-encrypted. Login cookies are host-bound, HttpOnly and signed. The server enforces strict content security and rate-limit policies, and the API only accepts image uploads within tight size limits.
Changes
We update this page when the service changes. The date at the top tells you when.