Privacy Policy
Last updated: April 2026
Who we are
ScanJunki is operated by Robert Scotts Commerce LTD ("we", "us", "our"). We are the data controller for personal data collected through the Service.
What we collect
- Account data: Email address, name, and hashed password when you sign up
- Google account data: Email, name, and profile picture if you sign in with Google
- eBay account data: eBay username and OAuth tokens when you link your eBay account. We never receive your eBay password.
- Usage data: Products you scan, your preferences (marketplace, VAT settings), and scan history
- Search data: Search queries (barcodes, keywords, photo searches), result counts, and search type. This helps us understand product demand and improve the Service.
- Location data (opt-in): If you enable location sharing, we collect your approximate location (city and country) when scanning. This is used for location-based features and aggregated market insights. You can opt out at any time in your account settings.
How we use it
- To provide the Service — looking up products, calculating fees and profits
- To maintain your account and preferences
- To fetch eBay data on your behalf using your linked eBay account
- To improve the Service based on usage patterns
- To produce anonymised, aggregated market intelligence (e.g. trending products, demand signals by region). This data contains no personal identifiers.
We do not sell your personal data. We do not use your data for advertising. We may share anonymised, aggregated market intelligence with third parties. This data cannot identify you. You can opt out of contributing to aggregated insights in your account settings under Privacy & Data.
Data storage
Your data is stored securely in our database hosted on Supabase (cloud infrastructure). Passwords are hashed with bcrypt. Session data is encrypted. eBay tokens are stored in encrypted HTTP-only cookies.
Your rights
Under UK GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data in a portable format
- Object to processing of your data
To exercise any of these rights, contact us at sales@robertscotts.com.
Your choices
You can control how your data is used in your account settings:
- Anonymised data sharing (on by default) — Toggle off to stop your search activity from contributing to aggregated market insights.
- Location sharing (off by default) — Toggle on to share your approximate location when scanning. This enables location-based features.
Go to Account Settings → Privacy & Data to manage these preferences.
Cookies
We use an essential session cookie on every platform. On the web we additionally load Microsoft Clarity for anonymous product analytics — it is disabled in the iOS app. See our Cookie Policy for a full breakdown.
Tracking & Analytics
- On the web, we use Microsoft Clarity for anonymous product analytics — heatmaps and session replay with input masking (typed content such as email, password and card fields is never recorded).
- On the iOS app, Clarity is disabled. No analytics scripts run on iOS. The iOS app sets a flag (
window.__SCANJUNKI_NATIVE_IOS) that our code checks before loading Clarity. - We log search and scan intents anonymously (Anonymised data, default on) to power our aggregate Market Intel feature. You can opt out at any time in Settings.
- Optional location data (Location sharing, default off) is stored only with your explicit permission, to enrich Market Intel insights for your region.
- We do not use advertising tracking pixels, retargeting cookies, Facebook Pixel, or any similar tracking tools.
Data processing partners
We share data with the following third-party processors only to deliver the Service:
- Apple — authentication and In-App Purchase on iOS (policy)
- Google — OAuth sign-in (policy)
- Stripe — web billing (policy)
- eBay — product pricing API, with your consent via account linking (policy)
- Resend — transactional emails (policy)
- Microsoft Clarity — web analytics, web only (policy)
- RevenueCat — iOS purchases (policy)
- Twilio — SMS marketing, opt-in only (policy)
We do not share user data with any third-party data brokers. We do not link data collected by the app with third-party data for marketing or advertising purposes.
Data retention
We retain your data for as long as your account is active. If you delete your account, we will delete all your personal data within 30 days. Anonymised, aggregated data may be retained for analytics.
Changes
We may update this policy from time to time. We will notify you of material changes via email.
Contact
Data protection queries: sales@robertscotts.com