Privacy Policy
Last updated August 7, 2026
ScanToRun is a sole proprietorship based in Texas. This policy describes what we collect, why, who else sees it, and how to get it back or get rid of it.
What we collect
- Account details. Your name, work email, and a hash of your password. We never store the password itself.
- Business details. The name of the business and the short code phones use to join it.
- Your documents. The files you upload and the text extracted from them, plus the titles, descriptions, tags, and revisions you enter.
- Enrolled devices. The name the person enters when they enroll the phone, its browser user-agent string, and when it was last used. We do not collect location, contacts, photos, or anything else from the device.
- A record of who opened which document. When someone opens a document we store their name, the document, the revision they saw, and the time. These records are deleted after 90 days. We keep a running per-document view count, which carries no names, for longer.
- Confirmations that a revision was read. When someone taps to confirm they have read a revision, we store their name, the document, that revision, and the time. This is different from the record above: it is a deliberate statement by the person, and it is the evidence a business produces when asked to show that a change was communicated. Confirmations are kept for as long as the account is open, because a record that expires is not evidence.
- Checklists worked through. When someone works through a checklist we store their name, the document, the revision they were working from, what it was done on if they say (a room, a line, a machine), which items they checked and the time each one was checked, and whether they finished. An unfinished checklist is kept too, because a checklist somebody started and did not complete is part of the record rather than an absence from it. These are kept for as long as the account is open.
- A little kept on the device itself. Text size and light or dark, so the reader looks the way you left it. The id of a checklist you are part-way through, until the tab closes. And a confirmation you tapped while out of signal, held until it can be sent. That is all. Documents are not stored on the device, so the reader needs a connection. They stay on that device until the browser data is cleared.
- Minimal usage data. The time of each sign-in.
- Setup milestones for the business. The first time each business does a handful of things (signs up, publishes a document, prints tags, enrolls a phone, starts a checklist, subscribes or cancels) with the date. Recorded once each, so we can see where businesses get stuck setting up. These name nobody. There is no person, phone or document attached to any of them: the record says that a business published its first document in March, never who published it. It is kept for the life of the account, because a date with no name in it does not become a record about anyone however long it is held.
- If you try the guided demo. It gives you a workspace of your own for a few hours: a shop code, a tag, whatever procedure you put on it and the first name you type when you enroll the phone. All of it is deleted within four hours, including any file you uploaded and the file itself in storage. Nothing from it is added to any account, and nothing you upload there is read by us or used for anything.
What we keep afterwards is which of the six steps the visit reached, and whether the tag came from us in the mail or from the website, so we can see where the demo loses people. Those rows name nobody — no name, no phone, no file, no address, and no way back to who it was once the workspace is gone. That is the whole of it, and it is why they are kept without a date after which they are removed. - Billing details. Handled by Stripe. We store only your Stripe customer and subscription identifiers and your subscription status. We never see or store card numbers.
What we do not do
- No advertising pixels and no tracking scripts, anywhere. The product itself, meaning the reader you scan a tag to open, the operator app and the admin panel, loads no third-party code at all. Our public marketing pages (this one, the home page, the terms, and the pages we publish) count visits using Vercel Web Analytics, which sets no cookie, stores no identifier that could follow you between sites, and never receives the address of a document. It is how we know whether anybody read the home page. It is switched off everywhere your work is.
- No selling or renting of personal information to anyone, ever.
- No using your documents to train machine-learning models.
- No reading your documents, except where you ask us to for support and we have your permission.
Cookies
We set three, none of them used to follow you to any other site. One identifies a signed-in person and lasts 30 days. One identifies an enrolled device and lasts a year, so an operator does not have to sign in every time they scan a tag. Both are signed, and both can be ended by you: sign out, or revoke the device from settings.
The third records how you first reached us and which page you landed on — a search engine, a link from another site, or a tag we mailed you — and lasts 30 days, so that an account opened a fortnight later can be counted against whatever brought you. It holds no identifier, nothing that names you, and nothing that distinguishes you from anyone else who arrived the same way, and it is deleted the moment an account is created. It is never sent anywhere but here.
Who else processes it
These providers hold data on our behalf so that the service can run:
- Vercel: hosting and file storage for your uploaded documents, and visit counts for our public marketing pages only.
- Neon: the database holding accounts, businesses, and document metadata.
- Stripe: payments. Card details go directly to Stripe and never touch our servers.
- Resend: sending password reset links and team invitations.
We disclose data to no one else, except where the law requires it. Data is stored in the United States.
How it is protected
- Passwords are hashed with scrypt. A copy of our database does not reveal anyone’s password.
- Password reset and invitation links are stored only as hashes, so a copy of the database is not a set of working links.
- Every customer’s data is separated at the database level. A request cannot name an organization other than the one it belongs to, and automated tests cover that on every change.
- Everything travels over HTTPS.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you promptly and tell you what we know.
How long we keep it
Account and document data is kept while your account is open. When an account closes we keep it for 30 days so you can ask for an export or change your mind, then delete it. Deleting a document removes its file too. Invoices are kept as long as tax law requires.
Records of who opened which document are deleted after 90 days, automatically and without anyone asking. The limit is the point: a log of what each person read, kept indefinitely, stops being a way to check that procedures are being followed and becomes a way to watch people. Ninety days covers a training review or a question about a recent job, and then it is gone.
Confirmations that a revision was read are kept while the account is open, and go with everything else when it closes. They are held longer than view records on purpose, and the difference is worth stating plainly: a view is something we observed, and a confirmation is something the person said. The second is what an auditor asks for, and it would be worthless if it expired.
Records of checklists worked through are kept on the same footing as confirmations, and for the same reason: a business is asked to show that the opening checks were done, and a record that expired would not answer it. The honest thing to say about these is that they are the most detailed records here: a time against each item is a picture of somebody’s shift, not just a fact about a document. We keep them because “the fridge was checked at 06:12” is the question an inspector actually asks, and a record that only says “sometime that morning” cannot answer it. They are visible to the people who administer your account and to nobody else, and they are deleted with everything else when the account closes.
Your choices
Ask us at hello@scantorun.com and we will export your data, correct it, or delete it. We answer within 30 days and we do not charge for it. If you are in a place with statutory rights over your personal data (California, the EU, the UK and others), those rights apply and this is how you exercise them. We will not treat you differently for asking.
The people whose data appears here are usually employees of our customer rather than our customer. If you are one of them, contact your employer first. They control the account. We will help either way.
Children
The service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially we will email account owners before it takes effect. The date at the top always reflects the last substantive change.
Contact
ScanToRun, hello@scantorun.com.