Last updated: 15 August 2026
Scanely ("we", "us", or "our") operates the website and service at scanely.io (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Some processing is necessary to provide the Service you request. Optional website analytics and attribution are used only after you make an affirmative choice in our cookie preferences. Merely using the Service does not constitute consent to optional analytics.
When you create an account directly, we collect:
If you choose Sign in with Google, Google authenticates you and sends us the account information needed to create or access your Scanely account, such as your name, email address, profile image, and provider account identifier. We do not receive your Google password.
When someone scans a QR code created through Scanely, we automatically collect the following data about the scan event so that the code can be routed and its owner can receive scan reporting:
Payment processing is handled by Stripe. We store subscription and customer references needed to manage your plan, but we do not store complete card or bank account details on our servers. Payment details are sent directly to Stripe and are handled under Stripe's Privacy Policy.
To operate accounts, billing, QR creation, and scan reporting, we record service events such as account creation, QR creation, a first scan, checkout status, subscription changes, and refunds. These records may contain a timestamp, internal account or resource identifier, plan, and limited technical context. Their event properties do not contain payment card details.
If you allow analytics, we also record first-touch attribution consisting of the landing page path, referring website hostname and origin, and standard UTM campaign fields. We do not retain the full landing-page query string in this first-touch record, and UTM values are length limited. You should not place personal or sensitive information in URLs or UTM fields.
With the same permission, Google Analytics 4 may process page paths and selected product interactions such as calls to action, sign-up steps, QR downloads, and checkout steps, together with browser and device information, approximate location, and online identifiers. Page locations and referrers supplied by our integration contain only a sanitized origin and path; URL credentials, query strings, and fragments are excluded. Google Analytics is not loaded on authenticated dashboard, authentication, sign-in, registration, password, or try-form routes, or on any URL that contains a query string. We do not use Google Analytics for advertising on Scanely.
Hotjar is disabled in the current Service. We do not load its script or create Hotjar heatmaps or session recordings.
We use information to:
Our legal bases depend on the activity. We rely on performance of a contract to provide requested account, QR, billing, and support features; legitimate interests to secure, diagnose, and improve the operation of the Service; and legal obligations where required. We rely on your consent for optional first-touch attribution and Google Analytics. Operational account, billing, and service events may still be processed where necessary for the contract, security, accounting, or our legitimate interests even if you decline optional analytics.
Scanely uses secure session and authentication cookies needed to keep accounts signed in and protect the Service. A QR code with A/B testing enabled may set a 30-day, SameSite=Lax cookie named scanely_ab_<QR ID> so a returning scanner is routed to the same active variant. It is limited to that QR experiment and is not used to profile visitors across websites.
Your analytics choice is stored in your browser's local storage under scanely:analytics-consent. The record contains the choice, consent-policy version, and time it was updated, but no account identifier. This preference storage is necessary to remember and respect your decision. A new decision is requested when the stored policy version is no longer current.
Google Analytics scripts, cookies, and similar browser storage are loaded only after you select Allow analytics. Hotjar remains disabled even when analytics are allowed. We may also set a 30-day, first-party, httpOnly cookie named scanely_attribution containing the limited first-touch attribution described above. Declining analytics does not affect account or QR features. We do not use advertising or session-recording cookies.
You can change or withdraw your choice at any time. Withdrawal stops future optional analytics collection, clears the first-touch attribution cookie, and removes analytics cookies or storage accessible to Scanely where possible. It does not affect processing that occurred lawfully before withdrawal.
We do not sell personal data. We use providers that process data for the purposes described in this policy. Depending on where a provider operates, information may be processed outside your country, including outside the EEA, subject to applicable transfer safeguards.
Stripe processes payments, subscriptions, refunds, and related fraud-prevention data. See Stripe's Privacy Policy.
Cloudflare provides hosting, edge delivery, security, Workers, and database infrastructure. It may process request data such as IP addresses when delivering and protecting the Service. See Cloudflare's Privacy Policy.
Google provides optional account authentication and, only after analytics consent, Google Analytics 4. The data Google receives depends on which of these features you use. See Google's Privacy Policy.
Resend processes recipient address, name where used, message content, scheduling, and delivery information to send account, password reset, onboarding, and QR notification emails. See Resend's Privacy Policy.
We retain account data while your account is active or as needed to provide the Service. QR configuration and scan analytics are retained to provide historical reporting for the account. Operational product and billing events are retained for as long as reasonably needed for service delivery, security, billing, dispute handling, and legal compliance.
Optional website analytics are retained according to our applicable provider settings and only for as long as needed for the purposes described above. Your browser keeps the versioned consent preference until you change it, clear browser storage, or a later policy version requires a new choice.
If you delete your account, we will delete or de-identify personal data within 30 days, except where retention is required for billing, legal, fraud-prevention, or dispute purposes. Provider systems and backups may require additional time under their retention schedules.
Depending on your location and the circumstances, you may have the following rights:
To exercise these rights, contact hello@scanely.io. We will respond within the period required by applicable law. We may need to verify your identity before completing a request.
You may also lodge a complaint with a competent data protection supervisory authority, including in the EU Member State of your residence, workplace, or the place of an alleged infringement.
We use technical and organisational safeguards appropriate to the nature of the data, including:
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
The Service is not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact hello@scanely.io so we can investigate and take appropriate action.
We may update this policy and will revise the date shown at the top. If a material change affects optional consent, we will invalidate the stored consent version and request a new choice. Where appropriate, we may also provide notice through the Service or by email.
For questions, requests, or concerns about this policy or our data practices:
Scanely
Email: hello@scanely.io
Website: scanely.io