Terms, Privacy & Refunds
Last updated
Terms of service
This service is operated by devpitot OÜ, established in Estonia, reachable at support@devpitot.com. Using the site means you accept these terms.
What the service does
You supply an image, a PDF or a camera view of a document containing a QR code or barcode. Your browser decodes the code itself, locally. To fill in the pass's details we then send the document — a PDF's text, or a downscaled copy of the picture — to our server, which passes it to Anthropic's Claude; see Privacy. If you choose to build a pass, the decoded value and the fields you selected are sent to our server, which signs an Apple Wallet pass file (.pkpass) with a certificate Apple issued to us, and returns it. Nothing is sent to Apple at any point.
What it does not do
- It does not create, validate or transfer tickets. The pass reproduces a code you already hold. It carries no value of its own.
- Acceptance is not guaranteed. Whether a venue, airline or operator accepts a reproduced code is entirely their decision. Some require their own app or the original document. We cannot promise any pass will be accepted, and a rejected pass is not a fault in the service.
- Apple Wallet only. Passes do not work with Google Wallet. See the notice on the main page.
Your responsibilities
- Only scan documents you are entitled to use.
- Do not use the service to copy, share or resell tickets in breach of the terms of whoever issued them, or to defraud anyone.
- Do not attempt to overload, probe or work around the limits on the service.
Availability and liability
The service is provided as-is, without warranty. We do not guarantee it will be available, uninterrupted or error-free, and we may change or withdraw it. To the extent the law allows, our total liability to you is limited to the amount you paid in the twelve months before the claim. Nothing here limits liability that cannot legally be limited.
Governing law
These terms are governed by the laws of Estonia. If you are a consumer, you keep the mandatory protections of your country of residence.
Privacy
There are no accounts. We hold as little as the service can function on.
Handled in your browser only
Reading the barcode happens entirely on your device: the image, the PDF or the camera stream is decoded locally, and the original file is never uploaded. The camera is not recorded, and nothing is sent while you are lining up a shot.
Sent to our server
- To read the ticket's details, once a code has been decoded: the text layer of a PDF, or — for a photo, a camera shot, or a PDF with no text layer — a copy of the picture, downscaled to at most 1600px and re-encoded as JPEG. This is the whole document as it was given to us, before you have chosen any fields; it is passed straight to Anthropic (below) and is not stored.
- The decoded code and the fields you left checked, when you build a pass. They are used to generate and sign the pass and are not stored afterwards.
- Your access code, to check and spend a credit.
Passes are signed on our own server, using a certificate Apple issued to us. Building a pass sends nothing to Apple.
Sent to third parties
- Anthropic — to read the ticket's details into pass fields, the extracted text or a downscaled image of the document is sent to the Claude API. Do not scan documents whose contents you are not willing to have processed this way. This step is optional to the service and can be declined by simply not building a pass.
- Polar — sells the credit bundles as merchant of record and handles payment and tax. We never see your card details.
- Brevo — delivers your access code by email.
- Supabase — stores the hashed codes and their balances.
Each is a processor acting on our instructions, except Polar, which is the seller of record and an independent controller for the payment itself. Anthropic and Polar are established in the United States, so using the service involves a transfer outside the EU/EEA; those transfers rely on the standard contractual clauses in our agreements with them. Brevo is established in the EU.
Stored
- A one-way hash (SHA-256) of your access code plus its remaining balance. The code itself is never stored, which is why it cannot be recovered if lost.
- The purchase's order reference and the email address you gave at checkout, to deliver the code and to prevent a duplicate payment being credited twice.
- Ordinary server logs — IP address, time and the request line — kept for up to 30 days to keep the service available and prevent abuse. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Your code is also kept in your own browser's local storage so you do not have to re-enter it. Clearing site data removes it.
Your rights
The data controller is devpitot OÜ, established in Estonia. Under the GDPR you may access, rectify, erase, restrict, object to and port your personal data. In practice we hold very little: mainly the purchase record and server logs. Write to support@devpitot.com — because purchases are not tied to an account, we will usually need the order reference to find yours.
You may also complain to the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon (aki.ee), or to the authority where you live.
Refunds
Pass credits are sold in prepaid bundles. A bundle is delivered as a code immediately, on screen and by email. Delivery is the code reaching you: each credit is spent later, when you mint a pass with it.
Delivered credits are not refundable. Before paying you tick a box asking us to supply the code at once and acknowledging that you thereby lose the 14-day right of withdrawal that EU and UK law gives for digital content. That consent is what removes the right, and we cannot supply the code without it.
Two things are not refunds, and you keep them either way:
- A pass that fails to build returns its credit to your code automatically. If it does not, tell us and we will restore it.
- A bundle you paid for but never received — no code on screen and none by email — is either delivered or refunded in full. Write to us with the order reference.
A pass that builds correctly but is refused by a venue is not grounds for a refund; see the acceptance note in the terms.
Payments are handled by Polar as merchant of record. Polar applies its own policies as the seller, and where it issues a refund it may take a few working days to appear.
Contact
devpitot OÜ, Estonia — www.devpitot.com
Email support@devpitot.com. Include your order reference if your message is about a purchase. We aim to reply within 5 working days.