Privacy Policy
Last updated 30 September 2026This policy explains what personal data Scanlync collects, why, how we protect it, how long we keep it and what you can do about it. We act as the data fiduciary / controller for this data. We never sell your data and we don’t show ads. A short version is on Your data & security.
1. What we collect
- Account details: your name and email address; with Google or Microsoft sign-in, the account ID and (for Google) your profile picture link.
- Your QR codes: what each saved code contains and its settings. Wi-Fi passwords are stored encrypted.
- Business details (if you sign up for Business): business name, type, city, number of locations, an optional tax ID (stored encrypted) and the email addresses of team members you invite.
- Sign-in and security data: the date, sign-in method, device type (for example “Chrome on Android”) and country of each sign-in, and your signed-in sessions. A scrambled copy of each email sign-in code is kept only to check it.
- Messages: what you send through the contact and report forms.
- Payments (when passes and packages launch): plan, amount and invoice. Card and UPI details are handled only by Razorpay.
2. Why we use it
To run your account, save and show your QR codes, sign you in securely and warn you about sign-ins from new devices, answer your messages, prevent abuse and issue invoices. We email you only about your account unless you opt in to product news.
3. Cookies
We use only essential cookies: one to keep you signed in, one that recognises your browser so we can alert you about sign-ins from new devices (we store only a scrambled version of it), and one that remembers the currency you chose. No advertising or tracking cookies. Pages people see when they scan a code set no cookies.
4. How we protect it
- Encrypted connections (HTTPS) everywhere; sensitive fields (Wi-Fi passwords, tax IDs) encrypted when stored.
- No passwords: you sign in with Google, Microsoft or a one-time email code.
- Our team signs in to the admin area with a second step. Personal data is masked by default, and every time the team opens your details it is logged with a reason.
- Links are checked against lists of unsafe websites before a code is made.
5. Who else is involved
- Google and Microsoft — only if you choose to sign in with them. Google also serves our web fonts.
- Our hosting and email providers — to run the website and send emails.
- Razorpay — to process payments when passes and packages launch. We never see or store card or bank details.
6. How long we keep it
- Account, codes and business details: while your account exists.
- Sign-in history: 90 days. Email sign-in codes: 24 hours. Records of emails we sent: 90 days.
- Closed support messages and abuse reports: 12 months.
- When you delete your account, your data is removed straight away and backups roll over within 30 days. Invoices are kept as long as tax law requires.
7. Your rights and controls
In Privacy & security you can see where you’re signed in and sign out any device, see your sign-in history, choose email alerts, download a copy of your data and delete your account. You can also ask us for a correction, raise a question or a grievance by emailing support@scanlync.com with “Privacy” in the subject; a named person replies, usually within 7 days. This applies wherever you live, including under India’s Digital Personal Data Protection Act and the EU/UK GDPR.
8. If something goes wrong
If personal data is exposed, we tell affected people without delay — what happened, what it means for them and what to do — and report it to the authorities as the law requires.
9. Children
Scanlync is intended for people aged 18 and over. We don’t knowingly collect data from children.
10. Changes
We’ll update the date above when this policy changes and email account holders about significant changes.