Privacy
Privacy notice
ScanTheLink processes only the data needed to run public scans, protect the service, save reports when you sign in, and receive pilot access requests.
Controller
Đedović Mustafa, Hasanović Jusufa Juke 57, 71000 Sarajevo, Bosnia and Herzegovina. Contact: contact@scanthelink.com.
Data we process
We may process the target URL or public profile handle you submit, scan status, scan results, timestamps, share identifiers, claim tokens, account email address, magic-link session data, IP address, user-agent data, and security logs required for abuse prevention and rate limiting.
Beta and feedback requests
If you request a free VIP beta scan, we process your email address, submitted target, use case, message, request status, and related communication so we can review the request, run or discuss the report, improve the product, and prevent abuse.
Account and sign-in
Accounts use passwordless magic links. We use session cookies and related security storage to keep you signed in, claim eligible guest scans, and protect account access. Password fields are not used.
Connected data
Connected owner-data features are disabled for the public beta. If they are enabled later, ScanTheLink may request authorized Search Console, GA4, or YouTube owner signals only after account consent. Provider access tokens must remain encrypted and are never shown in the user interface.
Analytics and cookies
Necessary cookies and storage are used for security, sessions, scan claiming, rate limiting, abuse prevention, and basic service operation. Optional analytics and marketing storage are off until you allow them in Privacy choices. Optional analytics may use product events and privacy-friendly aggregate analytics when configured for the ScanTheLink domain.
If your browser sends a Global Privacy Control signal, ScanTheLink treats future sale/share-style marketing signals as opted out. No advertising pixels or sale/share marketing flows are active right now.
External providers
Depending on configuration, scans may use hosting infrastructure, queue infrastructure, Google PageSpeed Insights, YouTube APIs, Meta/Facebook or X-related public providers, Resend for email delivery, and optional analytics providers such as Plausible and Google Analytics 4 after consent. Payment providers are not used while paid flows are disabled.
Payments
Paid self-serve flows are disabled during the public beta. If payment features are launched later, payment data will be processed by the payment provider, and ScanTheLink will store only the metadata needed to confirm access, issue receipts, support users, and keep audit records.
Retention and deletion
Scan and account data are kept only as long as needed for product operation, support, security, abuse prevention, audit records, and legal obligations. You can request deletion or anonymization by email. Signed-in users can also use account deletion where available.
Your choices
You can change optional cookie and analytics preferences at any time.