Privacy Policy
This policy explains how Scandars processes user account information, submitted website data, scan results, reports, payments and technical service records.
Privacy Overview
Scandars processes information needed to provide website security scans, user accounts, premium payments, reports and service support.
We aim to collect only information relevant to operating, securing and improving the service.
Information We Collect
The information processed by the service may include:
Website Scan Data
When you submit a website, the scanner may collect and store information such as:
- Submitted and final website URLs.
- Domain names and resolved public IP addresses.
- Public DNS and email-security records.
- HTTP response status and headers.
- Public TLS certificate information.
- Public cookies sent by the assessed response.
- Technology fingerprints and public page-content indicators.
- Scan findings, recommendations and generated reports.
- Scan duration, request counts and transfer metrics.
The service does not require website login credentials for its normal passive external scans.
Payment Information
Premium payments are processed through Stripe. Payment-card information entered during checkout is handled by Stripe under its own privacy and security practices.
We may store payment-related records such as:
- Stripe checkout and payment references.
- Payment amount and currency.
- Payment status and timestamps.
- The related free and premium scans.
- Whether a premium entitlement has been successfully used.
How Information Is Used
Information may be used to:
- Create and manage user accounts.
- Perform requested website scans.
- Calculate findings, scores and grades.
- Generate and deliver PDF reports.
- Process and reconcile premium payments.
- Provide scan retries and payment entitlements.
- Send account, report and password-reset communications.
- Detect abuse, fraud and security threats.
- Diagnose errors and improve service performance.
- Meet legal and accounting requirements.
Data Security
We use administrative and technical safeguards intended to protect service data. These may include:
- Password hashing.
- Session and CSRF protections.
- Restricted administrative access.
- Encryption for configured sensitive settings.
- Request validation and rate limiting.
- Logging and error monitoring.
- Secure payment processing through Stripe.
Data Retention
Account, scan, report and payment records may be retained while needed to provide the service, maintain account history, resolve disputes, prevent abuse and meet accounting or legal requirements.
Some information may remain in backups, security logs or transaction records for a limited period after deletion from active systems.
Retention periods may differ depending on the type of data and the reason it is stored.
Your Choices
Depending on the available service features and applicable requirements, you may:
- Review and update account information.
- Change your account password.
- Review your scans, reports and payments.
- Request assistance with inaccurate account information.
- Contact us regarding account deletion or privacy questions.
Certain payment, fraud-prevention, security or legal records may need to be retained even after an account request.
Children’s Privacy
The service is intended for website owners, developers, agencies and other users able to enter binding agreements and obtain scanning authorization.
The service is not intentionally designed to collect personal information directly from young children.
Policy Changes
This policy may be updated when service features, infrastructure, payment flows or privacy practices change.
The updated date at the top of this page identifies the current version.
Privacy or Data Question?
Contact us regarding account data, website scan information, reports, payments or privacy-related requests.