Privacy Policy
Last updated 2026
This policy explains what we collect, why, and your choices. We collect as little as we can to run the Service, and we never sell your data.
1. Your account
Your email and authentication details, the QR codes you create and the destinations you point them at, plus basic security logs. That is what an account holds.
2. Scan data
When someone scans one of your codes we record the time, a coarse location (country and city, derived from the network, never GPS), the device type, the referring site, and a one-way hash of the IP address. We do not store raw IP addresses, and the redirect sets no cookies and does no cross-site tracking. The hash only lets us tell a repeat scan from a new one; it cannot be turned back into an address.
3. Why we collect it
To resolve your codes, to show you the scan analytics you are paying for, to keep the Service secure and free of abuse, and to handle billing. Preview bots and crawlers are identified and excluded from your counts.
4. How long we keep it
Individual scan records are kept for your plan's analytics retention period and then deleted. Daily totals may be kept longer in aggregate form, which describes no individual. Account data stays until you delete your account, after which it is removed following a short grace period.
5. Sharing
Only with the processors that run the Service: our hosting, database and authentication, payment, and email providers. Each is bound by an agreement limiting their use of the data. We also disclose where the law requires it. We do not sell personal data and we do not share it for advertising.
6. Your rights
You can access, export, or delete your data at any time from Settings, or by contacting us. If you use Scanburst to collect scan data about your own customers, you are the controller of that data and we process it on your behalf; contact us for a data processing agreement.
7. Contact
Privacy requests? Email hello@scanburst.com.