Privacy policy

Effective 2026-10-04. The short version: we collect what the service needs and deliberately avoid collecting things that would make scan data personal.

Who we are

ScanMePlz is operated by Municipal Web Works, Irvine, California. For data protection purposes we are the controller of account data, and the processor of scan data on behalf of the customer whose codes are being scanned. Contact: [email protected].

If you have an account

We store:

  • your email address, and your name if you give us one;
  • a salted PBKDF2 hash of your password — never the password;
  • your codes, their destinations, designs and any files you upload;
  • your plan, and a Stripe customer identifier. We never see or store card details; payments are handled entirely by Stripe;
  • session records, containing a hashed identifier, a hashed IP and a truncated user-agent string, so you can see and revoke active sessions.

If you scan someone's code

This is the part we have designed most carefully, because it concerns people who never chose to use us. When a code is scanned we record:

  • the time;
  • country, region and city, as derived by Cloudflare from the network connection;
  • device class (mobile, tablet, desktop), operating system family and browser family;
  • the referring host, if there is one — the host only, never the full URL;
  • a salted hash that is unique to one code on one day, used only to tell a repeat scan from a new one.

We deliberately do not record:

  • the raw IP address;
  • the full user-agent string;
  • any cookie or identifier that persists across days or across different codes;
  • anything that would let us, or our customers, identify an individual who scanned.

The daily hash rotates every day and is specific to a single code, so it cannot be used to follow a person over time or build a profile. That is a design choice, not an oversight: a café should be able to count scans without acquiring a surveillance dataset.

Cookies

We use two first-party cookies and no third-party tracking cookies at all: a session cookie when you are signed in, and a CSRF token cookie that protects your account from cross-site request forgery. Both are strictly necessary, which is why there is no cookie banner. See the cookie page.

Analytics about this website

We use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors.

Who we share with

  • Cloudflare — hosting, database, storage and email routing.
  • Stripe — payments, if you subscribe.

We do not sell personal data, and we do not share it for advertising.

How long we keep things

  • Account data: while your account exists, then deleted within 30 days of closure.
  • Scan records: retained while the code exists, so that history is there if you upgrade. Your plan limits how far back you can view, not what we store.
  • Error logs: 90 days.
  • Support tickets: 2 years.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to processing. Email us and we will action it within 30 days. You can export most of it yourself at any time from Account → Export.

California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we will not discriminate against you for exercising any right.

Security

Passwords are hashed with PBKDF2-HMAC-SHA256 at 210,000 iterations. Sessions use HttpOnly, Secure, SameSite cookies, and only a hash of the session token is stored. All traffic is HTTPS with HSTS. Admin actions are recorded in an audit log.

If you believe you have found a vulnerability, email us with "security" in the subject.

Changes

We will post changes here with a new effective date, and email account holders about anything material.