Privacy Policy
Last updated: June 10, 2026
Who we are
Scanlo provides trackable QR codes for small businesses. This policy explains what we collect when you use the app and when someone scans a code you created.
Scan data (the people who scan your codes)
When a QR code is scanned, our redirect service logs the event to provide you with analytics. We deliberately minimize what we store:
- No raw IP address is ever stored. The scanner's IP is used transiently at the edge to derive an approximate country and network type, then discarded.
- We store: timestamp, country, network (ASN), device type and OS family, referrer, the browser's user-agent string, and a bot flag.
- No cookies or local storage are set on the scanner's device. The scan is logged server-side from request metadata, so no consent banner is required for the scan itself.
Account data (you)
When you sign up we store your email address and authentication credentials, your plan, and the codes you create (destination URLs, names, placement labels). Billing is handled by Stripe; we never see or store your card details.
Subprocessors
We share data only with the infrastructure providers needed to run the service:
- Supabase: database, authentication, and serverless functions.
- Cloudflare: DNS, the redirect edge network, and scan logging.
- Stripe: subscription billing and payment processing.
Retention
Account data is retained while your account is active. Scan events are retained to power your analytics history; because they contain no identifying information without an IP, they may be kept to support long-term trends. You can request deletion of your account and its data at any time.
Your rights
You may access, correct, export, or delete your account data by contacting us. To exercise any right, email privacy@scanlo.io.
Changes
We may update this policy; material changes will be reflected in the "last updated" date above.