Legal

Privacy Policy

Last updated: February 28, 2026

This Privacy Policy explains how SignalScan collects, uses, stores, and discloses personal data when you use our website, scanner, and launch engine services.

1. Who We Are

Controller: SignalScan Inc. ("SignalScan", "we", "us", "our"). Contact: [email protected].

Full legal publisher and company details are available in our Impressum.

2. Scope

This policy applies to visitors, users, and customers of SignalScan. It covers data processed via our website, account system, scan/report features, launch engine, billing flows, and support channels.

3. Data We Collect

  • Account data: name, email, authentication identifiers.
  • Service data: scanned domains/URLs, scan results, launch configuration data, logs, and timestamps.
  • Billing data: order/customer identifiers and purchase status from LemonSqueezy.
  • Technical data: IP address, device/browser data, request metadata, and error telemetry.
  • Cookie and online identifier data used for authentication, security, and analytics.
  • Communication data: support emails and messages.

We do not intentionally collect special-category personal data. Do not submit sensitive personal data through scan or launch fields.

4. Purposes and Legal Bases (EEA/UK)

  • Providing and operating the service (GDPR Art. 6(1)(b)).
  • Account security, fraud prevention, abuse monitoring (Art. 6(1)(f), legitimate interests).
  • Billing, bookkeeping, and tax compliance (Art. 6(1)(c), legal obligation).
  • Product improvement and diagnostics (Art. 6(1)(f), legitimate interests).
  • Analytics and similar technologies where permitted by law (Art. 6(1)(a) consent, or Art. 6(1)(f) legitimate interests where consent is not required).
  • Marketing communications where permitted (Art. 6(1)(a) consent or Art. 6(1)(f)).

5. Cookies and Analytics

We use cookies and similar technologies for authentication, security, checkout flows, and optional analytics.

  • Essential cookies: session and authentication cookies required for login and secure account use.
  • Analytics: Google Analytics may be used in production to measure traffic and product performance, only when analytics consent is granted.
  • Payments: LemonSqueezy checkout may set its own cookies under its own policies.

You can manage preferences via our cookie banner and the footer "Cookie settings" link at any time. You can also control cookies through your browser settings. Blocking certain cookies may affect functionality.

Full details are available in our Cookie Policy.

6. US Privacy Disclosures

For applicable US state privacy laws (including California CPRA), we may process identifiers, internet activity data, commercial data, and inferences for service delivery, security, and analytics.

  • We do not sell personal data for money.
  • We do not knowingly share personal data for cross-context behavioral advertising.
  • You may request access, deletion, correction, and portability where applicable.
  • You may submit requests directly or through an authorized agent, where applicable.
  • You may exercise applicable opt-out rights by contacting [email protected].

7. Payments and LemonSqueezy

Payments are handled by LemonSqueezy. LemonSqueezy may act as merchant of record and independently process payment, tax, anti-fraud, and invoicing data under its own legal terms and privacy notices. SignalScan receives limited order/customer metadata needed to unlock paid features and provide support.

8. Processors and Third Parties

We use vetted service providers, including infrastructure and tooling providers such as:

  • Hosting/CDN and edge infrastructure providers.
  • Database and authentication providers (including Supabase).
  • Payment and billing providers (including LemonSqueezy).
  • Analytics providers (including Google Analytics).
  • Operational logging and security tooling.

9. International Transfers

Where data is transferred outside the EEA/UK, we apply appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms required by law.

10. Retention

We retain personal data only for as long as necessary for the purposes described above and as required by law.

  • Account profile and service data: generally for the duration of your account.
  • Security and technical logs: typically limited retention unless required for investigations.
  • Billing and tax records: retained for the period required by applicable accounting and tax law.
  • Support communications: retained as needed to resolve support and legal issues.

11. Security

We apply technical and organizational safeguards appropriate to risk. However, no method of transmission or storage is 100% secure.

12. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access a copy of your personal data.
  • Correct inaccurate personal data.
  • Delete personal data.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent (where processing is based on consent).
  • Appeal denial of a rights request (where applicable).
  • Lodge a complaint with your local data protection authority.

Submit requests at [email protected]. We may verify identity before processing requests.

13. Children

SignalScan is not directed to children under 16. If you believe a child submitted personal data, contact us and we will take appropriate action.

14. Changes

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date.

Related documents: Terms of Service and Impressum.