Barcode to PC Version 5.0 · Effective 5 September 2026

Privacy Policy

Barcode to PC mobile application and desktop application

This Privacy Policy supersedes and replaces in their entirety all previous privacy statements applicable to the Barcode to PC applications, including the statement dated 14 March 2024.

Summary

Barcode to PC transmits barcodes scanned on your mobile device to your own computer over your local network. The barcodes you scan are never transmitted to us.

We process two categories of data, and only with your consent: anonymous usage analytics and crash reports. A single control governs both. It is disabled by default and may be changed at any time in the application's Settings. We display no advertising, use no advertising identifiers, and do not sell personal data.

1.Controller

The controller of personal data processed through the Barcode to PC applications is:

Eagle Eye Systems S.r.l.
Via Villagrande 220, 61024 Mombaroccio (PU), Italy
Email: [email protected]

The applications are distributed on Google Play under the publisher name BarcodeByte and on the Apple App Store under the name Barcode to PC. References in this Policy to "we", "us" and "our" are references to Eagle Eye Systems S.r.l.

2.Scope and definitions

This Policy applies to the Barcode to PC mobile application for iOS and Android (the "App") and to the Barcode to PC desktop application for Windows, macOS and Linux (the "Desktop Application"), together the "Services". It does not apply to the website barcodetopc.com, which is governed by its own privacy statement.

"Personal data", "processing", "controller" and "processor" have the meanings given to them in Regulation (EU) 2016/679 (the "GDPR").

3.Data that remains on your devices

The following data is processed locally on your devices and is not transmitted to us.

3.1 Scan data. Barcode values, scanning sessions and scan history are stored on your mobile device and transmitted directly to the Desktop Application on your computer over your local network. We do not receive, store or have access to this data.

3.2 Images. Where an output template is configured to capture an image, the image is stored on your mobile device and transmitted to your computer in the same manner. Images are not uploaded to us.

3.3 Location data. Location is processed only where an output template contains a GEOLOCATION component. Where no such component is present, the App does not request location permission and does not access location services. Where it is present, the coordinates are incorporated into the scan output and transmitted to your computer in the same manner as the barcode. Location data is not transmitted to us. The operating system will request your permission before location is accessed for the first time, and you may decline.

4.Personal data we process, purposes and legal bases

4.1 Usage analytics

Data. Application events (such as which features are used and whether scans reach your computer), a random installation identifier generated on your device, the application version, the operating system version, the device model, and the country derived from the IP address of the request. The IP address itself is not retained.

Purpose. To understand how the Services are used and to improve them.

Legal basis. Your consent (Article 6(1)(a) GDPR). No analytics data is processed unless and until you have given consent.

Processor. PostHog, Inc., with data hosted in the European Union.

The installation identifier is not linked to your name, email address, telephone number or any advertising identifier, and cannot be used by us to identify you.

4.2 Crash and diagnostic reports

Data. Technical information about application failures, including stack traces, the application version, the operating system version and the device model. Reports are configured to exclude personal information.

Purpose. To identify and correct defects in the Services.

Legal basis. Your consent (Article 6(1)(a) GDPR).

Processor. Functional Software, Inc. (Sentry), with data hosted in the United States.

4.3 Contact data provided through the download-link form

Data. The email address and name you enter, where you choose to use the optional form to receive a link to download the Desktop Application. This is the only function of the App that requests an email address.

Purpose. To send you the download link and, where you have agreed, occasional product communications.

Legal basis. Your consent (Article 6(1)(a) GDPR). Each communication contains an unsubscribe link, and you may withdraw consent at any time by using it or by contacting us.

Processors. Our own workflow infrastructure, and The Rocket Science Group LLC (Mailchimp) for delivery.

The consent given through this form is independent of the analytics consent described in Section 5; neither implies the other.

4.4 Desktop Application account and usage data

Data. Where you have signed in or activated a licence: the number of scans processed, the number and names of connected mobile devices, the output settings in use, licence activation events, and an identifier derived from your computer's hardware.

Purpose. To provide and support the Services, to enforce the terms of your licence (including binding a licence to a specific computer), and to understand how the Desktop Application is used.

Legal basis. Performance of a contract (Article 6(1)(b) GDPR) and our legitimate interest in preventing licence misuse (Article 6(1)(f) GDPR).

Where no account email address is associated with the installation, this data is not transmitted. The Desktop Application also periodically verifies the licence with our server by transmitting the licence serial number and the hardware identifier.

4.5 Template assistant

Data. Where you use the optional assistant to generate an output template: the description you provide, the conversation with the assistant, the template under construction, the list of available components, and the output settings that shape the result, which include any file paths you have configured for CSV or spreadsheet output. Your licence serial number, account email address and hardware identifier accompany the request for the purpose of metering your allowance.

Purpose. To provide the assistant feature.

Legal basis. Performance of a contract (Article 6(1)(b) GDPR).

Processors. Our own server infrastructure and the artificial-intelligence model provider engaged to generate the response.

Scan data, barcode values and scan history are not transmitted to the assistant under any circumstances. The text of your requests is not retained in our usage analytics; only the number of requests is recorded. The assistant is entirely optional.

4.6 Account and authentication

Data. Where you choose to sign in: your email address and display name, obtained from your Google or Microsoft account through our authentication provider.

Purpose. To identify your account and associate it with your licence and allowances.

Legal basis. Performance of a contract (Article 6(1)(b) GDPR).

Processor. Okta, Inc. (Auth0).

Local use of the Services does not require an account.

4.7 Orders and payments

Data. Your order details, licence serial number, email address and plan. Payment card details are processed directly by our payment provider and are not received by us.

Purpose. To fulfil your purchase, deliver and administer your licence, and comply with tax and accounting obligations.

Legal basis. Performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).

Processor. FastSpring (Bright Market, LLC), acting as merchant of record. Certain historical orders were processed by Paddle.com Market Limited.

5.Consent management

On first use, the App asks once whether you consent to the processing described in Sections 4.1 and 4.2. No such data is processed until you have responded. If you decline, no such data is processed and the request is not repeated. A single control, located in Settings under Privacy, governs both categories and may be changed at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6.Recipients

Personal data is disclosed only to the processors identified in Section 4, each of which processes data on our documented instructions and under a written agreement, and to competent authorities where disclosure is required by law.

We do not sell personal data and do not disclose it to any third party for that party's own purposes.

7.International transfers

ProcessingProcessorLocation
Usage analyticsPostHogEuropean Union
Crash and diagnostic reportsSentryUnited States
Licensing, accounts, Desktop Application usageOur own infrastructureUnited States
Download-link contact dataOur own infrastructure; MailchimpEuropean Union; United States
AuthenticationAuth0As determined by the provider
PaymentsFastSpringAs determined by the provider
Template assistantOur own infrastructure; the model providerUnited States; as determined by the provider

Where personal data is transferred outside the European Economic Area, the transfer is made under appropriate safeguards pursuant to Chapter V of the GDPR, including the standard contractual clauses adopted by the European Commission, or under an adequacy decision where one applies.

8.Retention

DataRetention period
Usage analytics and crash reportsRetained for as long as necessary for the purposes in Sections 4.1 and 4.2, and deleted on a rolling basis
Desktop Application usage recordsDetailed records are aggregated after three months and the underlying rows deleted
Licence and order recordsFor the duration of the licence and thereafter for the period required by applicable tax and accounting law
Download-link contact dataUntil you unsubscribe or request erasure
Account dataFor the duration of the account

9.Your rights

Subject to the conditions set out in the GDPR, you have the right to request access to your personal data, its rectification or erasure, the restriction of its processing, and its portability, and the right to object to processing based on legitimate interest. Where processing is based on consent, you have the right to withdraw that consent at any time.

Requests may be submitted to [email protected]. We will respond within one month of receipt, extendable in accordance with Article 12(3) GDPR where necessary.

You also have the right to lodge a complaint with a supervisory authority. The supervisory authority in Italy is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

10.Security

Data transmitted to our infrastructure is protected in transit by encryption, and access to our systems is restricted to authorised personnel.

The connection between the App and the Desktop Application operates directly over your local network and is not encrypted. It carries your scan data. On a trusted network, this data does not leave that network; on a shared or public network, it could in principle be observed by another device on the same network. This is disclosed so that you may choose the network on which you use the Services with full knowledge of that characteristic.

11.Children

The Services are intended for professional use and are not directed at children. We do not knowingly process personal data relating to individuals under the age of 16.

12.Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

13.Changes to this Policy

We may amend this Policy from time to time. The version number and effective date at the top of this document identify the current version. Material changes will be communicated within the App.

14.Contact

Eagle Eye Systems S.r.l.
Via Villagrande 220, 61024 Mombaroccio (PU), Italy
[email protected]