Privacy

Local tools with minimal data collection

ProductPassKit is designed so that core identifier, Digital Link, AI parsing and QR generation workflows run on your device.

Tool inputs

Your input is processed locally in your browser and is not uploaded to ProductPassKit. Version 1 does not have user accounts, a database or an identifier history feature. Tool values are not intentionally added to URLs, query strings, cookies or server-side requests.

This local processing statement applies to the utilities currently published on ProductPassKit. If a future feature needs a server or external service, its data flow will be disclosed at the point of use and this policy will be updated.

Optional analytics

Google Analytics can load only when a site administrator has configured a GA measurement ID and you grant analytics consent. Events are limited to interaction metadata such as a tool identifier, success or error status, and download format.

Analytics events must never include GTINs, UPCs, EANs, Digital Link URIs, serial numbers, batch values, expiration values, AI strings, custom domains or parsed product identifiers. Declining analytics does not affect any tool.

Current optional analytics preference: not set

Preferences and hosting

Your analytics choice is stored in your browser’s local storage. ProductPassKit is designed for deployment on Vercel, whose infrastructure may process ordinary web request metadata such as IP address, user agent and requested path for delivery and security purposes. Static assets and WebAssembly may be delivered through the hosting platform’s CDN.

Third-party standards and libraries

The official GS1 Syntax Engine and the QR encoder are downloaded as application assets and execute locally. Validating a Digital Link does not cause ProductPassKit to request the user-supplied destination URL.

Policy baseline: 20 September 2026.