Legal · privacy policy
Privacy Policy
Effective date: February 2026 — placeholder until launch
ScanItHub (www.scanithub.com) takes privacy seriously. This policy explains what we collect, why, and how to exercise your rights.
What we collect
- Email — for delivery, magic-link sign-in, and security notifications. Stored as plain text.
- PIN hash — bcrypt-hashed; we never store your PIN.
- Uploaded content — photos, video, PDFs, captions. Stored on Cloudflare R2 (SOC 2 Type II).
- Scan events — hashed IP (never raw), country (ISO-2), bucketed user-agent class. Raw events purge after 7 days; daily aggregates retained for analytics.
- Audit log — every PIN attempt, magic-link use, and account-level action, retained for chargeback and abuse defence.
What we do NOT collect
- Passwords (we use email + PIN + magic-link)
- Card details (Paddle, our Merchant of Record, handles all payment data)
- Raw IP addresses
- Cross-site tracking pixels
Your rights
- Access — `/buyer/data-export` returns a ZIP of everything we hold.
- Delete — `/buyer/delete-account` hard-deletes your buyer record, codes, magic-link tokens, and audit log.
- Object — email legal@scanithub.com to opt out of any specific processing.
- Lodge a complaint — with your local data protection authority.
Contact
legal@scanithub.com