Privacy policy
How ScanZX handles your personal data, what we collect, who we send it to, how long we keep it, and the control you have over it. Last updated 2 August 2026.
In plain English
- We collect what running the product requires: your account, the tokens and addresses you scan, your watchlist, your alerts, and your billing status.
- We never ask for, and cannot accept, a seed phrase, private key, or wallet connection. ScanZX reads public blockchain data only.
- Card details never reach our servers. Payments are handled entirely by Stripe or, in the iOS app, by Apple.
- We do not sell personal data, and we do not track you across other companies’ apps or websites.
- You can export everything we hold and delete your account yourself, from inside the app.
This summary is for orientation and is not the binding text. The numbered clauses below govern.
Who is responsible for your data
Altivar Systems Ltd is the controller of the personal data described in this policy, registered at 1 Elmfield Park, Bromley, BR1 1LU, United Kingdom.
For any privacy question, or to exercise the rights set out below, contact support@scanzx.com.
What we collect, and why
Account and authentication
Your email address, an optional display name, your role and account status, your language and reading preferences, and the dates on which you accepted the terms, this policy, and the risk disclosure. If you set a password we store a scrypt hash of it, never the password itself. Session tokens and password-reset tokens are stored only as hashes, so a copy of the database does not yield a usable credential. We record a coarse last-active timestamp, updated at most every ten minutes, to expire dormant sessions.
Addresses and tokens you submit
When you run a scan, the wallet, token, or contract address you enter is stored against your workspace so the report can be reopened, compared, and monitored. Those addresses are also sent to the third-party data sources listed below in order to produce the report. A blockchain address can sometimes be linked to a person, so we treat the addresses you submit as personal data even though they are public on-chain. Scans are attributed to your workspace, not published, unless you explicitly create a shareable report link.
Product activity
Your watchlist and monitoring rules, alerts and notification preferences, onboarding progress, saved reports, API keys, and support tickets. API keys are stored as a hash plus a short non-secret prefix so we can show you which key is which without being able to reconstruct it.
Billing
Your plan, subscription status, and the identifiers your payment provider gives us — a Stripe customer and subscription reference, or for iOS an Apple account token scoped to your workspace. We never receive or store card numbers. Invoices and payment records are held by Stripe.
Referrals and affiliates
If you arrive through a referral or affiliate link we record the attribution so credit can be assigned correctly, and we keep enough of that record to detect fraudulent self-referral.
Security and operations
Rate limiting stores a hash of your IP address rather than the address itself. Audit records note who did what and when. Incoming webhook payloads are recorded as hashes for replay protection. Where the hosting platform provides a country signal we use it only to suggest a display currency; we do not collect precise location.
Marketing
Marketing email is a separate, off-by-default consent with its own timestamp. It is never required to use ScanZX, and turning it off does not stop essential security, billing, or alert email, which you cannot opt out of while you hold an account.
Cookies
All ScanZX cookies are first-party. There are no advertising or cross-site tracking cookies.
scanzx_session— keeps you signed in. Strictly necessary.scanzx_locale— remembers your language choice.scanzx_ref_attr— records a referral or affiliate attribution. Signed so it cannot be forged.scanzx_mkt_touch— records how you first reached the site, so attribution is not double-counted.scanzx_pending_scan— carries a scan you started before signing in, so it is not lost at the login step.
Who we share data with
We do not sell personal data. We share it only with the providers that make the product work:
- Stripe — subscription payments and the billing portal.
- Apple — in-app purchases and push notifications for the iOS app.
- Resend — transactional email (security notices, billing, alerts).
- DexScreener, GoPlus, block explorers, and public blockchain RPC endpoints — receive the addresses you scan in order to return market, security, and on-chain data. They do not receive your identity.
- Upstash — rate-limit counters keyed by hashed identifiers.
- Our hosting and database providers — operate the servers and store the data described above.
- Your browser or device push service — delivers notifications you have enabled.
- Telegram or Discord — only if you connect a community integration yourself.
Some of these providers operate outside the UK. Where personal data is transferred internationally it is done under the transfer mechanisms those providers make available, such as the UK addendum to the EU standard contractual clauses.
How long we keep it
- Account data — for as long as your account exists.
- Scan and report history — retained per your workspace’s retention setting, 90 days by default.
- Shareable report links — until you revoke them; revoked at account deletion.
- Push subscriptions — until you disable them or the device stops accepting delivery.
- Billing records — retained for the statutory period that applies to financial records, even after deletion, because we are required to keep them.
- Audit and fraud records — retained in minimised form for accountability.
Your rights and how to use them
Under UK data protection law you have the right to access, correct, delete, restrict, object to, and port your personal data, and to withdraw consent where we rely on it. Two of those are built into the product and need no request:
- Export — the privacy page produces a structured JSON copy of your account, scans, reports, watchlist, alerts, referrals, and preferences. The download link is single-use, tied to your signed-in session, and expires after 24 hours.
- Deletion — you can request deletion from the same page. It completes after a 7-day window during which you can cancel it, so an accidental or hostile request is reversible. On completion your personal fields are anonymised, sessions, API keys and push subscriptions are removed, and shareable report links are revoked. Records we are legally required to retain are kept in minimised form.
If you hold an active subscription, cancel it before deleting your account, or it will stop renewing when the deletion completes. Apple subscriptions must be cancelled in iOS Settings, because only Apple can end them.
For anything else, contact support@scanzx.com. If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk.
Children
ScanZX is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
We record the version of this policy you accepted, along with the date and language. If we make a material change we will tell account holders by email rather than relying on you to notice the date above.