Privacy Policy

Last updated: 15 August 2026

Scanely ("we", "us", or "our") operates the website and service at scanely.io (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Some processing is necessary to provide the Service you request. Optional website analytics and attribution are used only after you make an affirmative choice in our cookie preferences. Merely using the Service does not constitute consent to optional analytics.

1. Data We Collect

1.1 Account Information

When you create an account directly, we collect:

  • Name
  • Email address
  • Password hash; we never store your plaintext password

If you choose Sign in with Google, Google authenticates you and sends us the account information needed to create or access your Scanely account, such as your name, email address, profile image, and provider account identifier. We do not receive your Google password.

1.2 QR Scan Analytics Data

When someone scans a QR code created through Scanely, we automatically collect the following data about the scan event so that the code can be routed and its owner can receive scan reporting:

  • Country, city, and approximate coordinates when supplied by our infrastructure
  • Device type, browser, and operating system derived from the user agent
  • Referrer URL, when supplied by the browser
  • Timestamp of the scan and the QR or A/B variant involved
  • IP address transformed with SHA-256 before storage; we do not store the raw IP address in the scan record

1.3 Payment Information

Payment processing is handled by Stripe. We store subscription and customer references needed to manage your plan, but we do not store complete card or bank account details on our servers. Payment details are sent directly to Stripe and are handled under Stripe's Privacy Policy.

1.4 Product, Attribution, and Website Analytics

To operate accounts, billing, QR creation, and scan reporting, we record service events such as account creation, QR creation, a first scan, checkout status, subscription changes, and refunds. These records may contain a timestamp, internal account or resource identifier, plan, and limited technical context. Their event properties do not contain payment card details.

If you allow analytics, we also record first-touch attribution consisting of the landing page path, referring website hostname and origin, and standard UTM campaign fields. We do not retain the full landing-page query string in this first-touch record, and UTM values are length limited. You should not place personal or sensitive information in URLs or UTM fields.

With the same permission, Google Analytics 4 may process page paths and selected product interactions such as calls to action, sign-up steps, QR downloads, and checkout steps, together with browser and device information, approximate location, and online identifiers. Page locations and referrers supplied by our integration contain only a sanitized origin and path; URL credentials, query strings, and fragments are excluded. Google Analytics is not loaded on authenticated dashboard, authentication, sign-in, registration, password, or try-form routes, or on any URL that contains a query string. We do not use Google Analytics for advertising on Scanely.

Hotjar is disabled in the current Service. We do not load its script or create Hotjar heatmaps or session recordings.

2. How and Why We Use Data

We use information to:

  • Create, authenticate, and manage accounts
  • Generate, route, secure, and report on QR codes and scans
  • Process payments, administer plans, and keep billing records
  • Send account, password reset, onboarding, and requested notification emails
  • Enforce limits, prevent duplicate scan counts, and detect fraud or abuse
  • Diagnose the Service and understand activation and feature performance
  • Measure campaigns and improve website usability when you allow analytics
  • Comply with legal obligations and establish or defend legal claims

Our legal bases depend on the activity. We rely on performance of a contract to provide requested account, QR, billing, and support features; legitimate interests to secure, diagnose, and improve the operation of the Service; and legal obligations where required. We rely on your consent for optional first-touch attribution and Google Analytics. Operational account, billing, and service events may still be processed where necessary for the contract, security, accounting, or our legitimate interests even if you decline optional analytics.

3. Cookies and Similar Technologies

3.1 Essential and Functional Technologies

Scanely uses secure session and authentication cookies needed to keep accounts signed in and protect the Service. A QR code with A/B testing enabled may set a 30-day, SameSite=Lax cookie named scanely_ab_<QR ID> so a returning scanner is routed to the same active variant. It is limited to that QR experiment and is not used to profile visitors across websites.

Your analytics choice is stored in your browser's local storage under scanely:analytics-consent. The record contains the choice, consent-policy version, and time it was updated, but no account identifier. This preference storage is necessary to remember and respect your decision. A new decision is requested when the stored policy version is no longer current.

3.2 Optional Analytics Technologies

Google Analytics scripts, cookies, and similar browser storage are loaded only after you select Allow analytics. Hotjar remains disabled even when analytics are allowed. We may also set a 30-day, first-party, httpOnly cookie named scanely_attribution containing the limited first-touch attribution described above. Declining analytics does not affect account or QR features. We do not use advertising or session-recording cookies.

You can change or withdraw your choice at any time. Withdrawal stops future optional analytics collection, clears the first-touch attribution cookie, and removes analytics cookies or storage accessible to Scanely where possible. It does not affect processing that occurred lawfully before withdrawal.

4. Service Providers and Data Transfers

We do not sell personal data. We use providers that process data for the purposes described in this policy. Depending on where a provider operates, information may be processed outside your country, including outside the EEA, subject to applicable transfer safeguards.

4.1 Stripe

Stripe processes payments, subscriptions, refunds, and related fraud-prevention data. See Stripe's Privacy Policy.

4.2 Cloudflare

Cloudflare provides hosting, edge delivery, security, Workers, and database infrastructure. It may process request data such as IP addresses when delivering and protecting the Service. See Cloudflare's Privacy Policy.

4.3 Google

Google provides optional account authentication and, only after analytics consent, Google Analytics 4. The data Google receives depends on which of these features you use. See Google's Privacy Policy.

4.4 Resend

Resend processes recipient address, name where used, message content, scheduling, and delivery information to send account, password reset, onboarding, and QR notification emails. See Resend's Privacy Policy.

5. Data Retention

We retain account data while your account is active or as needed to provide the Service. QR configuration and scan analytics are retained to provide historical reporting for the account. Operational product and billing events are retained for as long as reasonably needed for service delivery, security, billing, dispute handling, and legal compliance.

Optional website analytics are retained according to our applicable provider settings and only for as long as needed for the purposes described above. Your browser keeps the versioned consent preference until you change it, clear browser storage, or a later policy version requires a new choice.

If you delete your account, we will delete or de-identify personal data within 30 days, except where retention is required for billing, legal, fraud-prevention, or dispute purposes. Provider systems and backups may require additional time under their retention schedules.

6. Your Rights Under the GDPR

Depending on your location and the circumstances, you may have the following rights:

  • Access - request a copy of personal data we hold about you
  • Rectification - request correction of inaccurate personal data
  • Erasure - request deletion of personal data where applicable
  • Restriction - request limits on processing in certain circumstances
  • Portability - receive certain data in a structured, commonly used format
  • Objection - object to processing based on legitimate interests
  • Withdraw consent - withdraw optional analytics consent at any time

To exercise these rights, contact hello@scanely.io. We will respond within the period required by applicable law. We may need to verify your identity before completing a request.

You may also lodge a complaint with a competent data protection supervisory authority, including in the EU Member State of your residence, workplace, or the place of an alleged infringement.

7. Data Security

We use technical and organisational safeguards appropriate to the nature of the data, including:

  • Hashing account passwords before storage
  • Transforming scan IP addresses before they are written to scan records
  • Encrypting data in transit using TLS/HTTPS
  • Restricting access to production systems
  • Using managed infrastructure and secure, httpOnly cookies where appropriate

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. Children's Privacy

The Service is not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact hello@scanely.io so we can investigate and take appropriate action.

9. Changes to This Privacy Policy

We may update this policy and will revise the date shown at the top. If a material change affects optional consent, we will invalidate the stored consent version and request a new choice. Where appropriate, we may also provide notice through the Service or by email.

10. Contact Us

For questions, requests, or concerns about this policy or our data practices:

Scanely
Email: hello@scanely.io
Website: scanely.io