This describes what Scanified collects, why we collect it, and what you can do about it. It is written to be understood rather than to be defensible.
We collect the minimum needed to run an asset ledger: who you are, what you own, and what your drivers scanned. We do not sell it, we do not share it for advertising, and we do not use it to train models. There are no third-party advertising or analytics trackers on the application.
Name, work email, company name, role, and a password hash. We never see your password in readable form.
Your assets, your customers and their contact details, orders, rentals, invoices, and the scans your people record. This is your business data. We are the processor of it; you are the controller.
Each scan records who submitted it, the time the device recorded it, the time the server received it, and — only where the device grants permission — the location at the moment of the scan. Location is captured to corroborate a delivery, and it is visible to managers in your own company. It is never sold and never shared outside your organisation. You can turn it off in the mobile app, and the ledger still works.
IP address, browser or device type, and error diagnostics, kept for up to 30 days to keep the service secure and working.
We do not collect payment card numbers at all — Scanified is invoiced, and no card is ever taken through the product. We do not read your contacts, your photo library, or anything on the device outside the app. We do not track you across other websites.
Data is stored in Postgres hosted by Supabase in North America, encrypted at rest. The web application runs on Netlify. Transactional email is sent through an email provider that receives only the address and the message.
These providers process data on our instructions under their own data-processing agreements. They are not permitted to use it for their own purposes.
For as long as your account is active. After you close it we keep your data for 30 days so you can export it, then delete it from live systems. Ask us to delete sooner and we will.
You can see, correct, export or delete your data. Most of that is self-service inside the product; for anything that is not, email privacy@scanified.com and we will act within 30 days. If you are in Canada you have rights under PIPEDA, and if you are in the EEA or the UK you have rights under the GDPR, including the right to complain to your data protection authority.
If an individual whose details you stored in Scanified — a customer contact, for instance — asks you to delete their information, you can do it yourself. If you need our help, we will help.
If we discover a breach affecting your data, we will tell the account owner without undue delay and within 72 hours of becoming aware, with what we know and what we are doing about it. We would rather send an early, incomplete notice than a late, tidy one.
We use cookies to keep you signed in and to remember interface preferences. That is all. There are no advertising cookies and no third-party trackers, which is why you have not been shown a consent banner.
Scanified is a tool for businesses and is not directed at anyone under 16.
If we change this policy materially we will email the account owner before it takes effect. The date at the top always reflects the current version.