Skip to content

Privacy Policy

We collect the store URL, what our scanner read from public pages, and the IP that asked — plus an email address if you create an account. No advertising trackers, no selling data, no scraping of your customers.

last updated 26 July 2026

1. What we collect

DataWhyKept for
Store URL and scan results (checks, evidence, score)To produce and re-open your reportUntil you delete it, or 12 months after the last scan of that store
IP address of the request that started a scanPer-hour rate limiting and abuse preventionStored with the scan row; not used for profiling
Email address and password hash (accounts only)Sign-in, alerts, receiptsUntil you delete the account
Server logs (request id, path, timing, status)Keeping the service up and debugging failures30 days
Billing recordsTax and accounting obligationsAs long as the law requires

We do not collect your customers' data. The scanner reads public storefront pages — product pages, robots.txt, sitemaps, policy pages, public product feeds. It never signs in, never submits forms, and never touches an order, a cart or an admin area.

2. What we never do

  • Sell or rent personal data.
  • Run advertising or cross-site tracking pixels.
  • Use your store's content to train machine-learning models.
  • Email you marketing you did not ask for.

3. Legal bases (UK/EU GDPR)

  • Contract — running scans you request, keeping your account, delivering alerts you enabled.
  • Legitimate interests — rate limiting, abuse prevention, keeping logs, and improving the checks. We keep this to the minimum that works.
  • Legal obligation — tax and accounting records for payments.

4. Who processes data for us

  • Paddle.com Market Ltd — merchant of record for paid plans. They handle card details; we never see them.
  • Hosting and database — a European VPS provider running our application and PostgreSQL, plus object storage for encrypted backups.
  • Cloudflare — DNS and edge protection for the website.
  • Email delivery — a transactional email provider for alerts, receipts and password resets.

Some providers operate outside the UK/EU. Where they do, transfers rely on standard contractual clauses or an adequacy decision.

5. Report links

Every finished scan gets an unlisted URL. It is not listed in a directory and we do not submit it to search engines, but anyone with the link can read it — that is what makes it shareable. Ask and we will delete any report.

6. Cookies

The marketing pages and public reports set no cookies at all. Signing in sets one httpOnly session cookie, required for the dashboard to work. There are no analytics or advertising cookies.

7. Your rights

You can ask for a copy of your data, correction, deletion, restriction, or portability, and you can object to processing based on legitimate interests. Email [email protected] and we will respond within 30 days. Account holders can delete stores, reports and the account itself without asking us. If you are in the UK or EU and think we have it wrong, you can complain to your data protection authority.

8. Security

Traffic is encrypted in transit. Passwords are stored as argon2 hashes. Database access is restricted to the application, secrets are held in the server environment, and backups are encrypted. No system is perfect; if we ever have a breach affecting you, we will tell you and the relevant authority without undue delay.

9. Children

Agentoray is a business tool and is not directed at anyone under 16.

10. Changes and contact

Changes are posted here with a new date above; material changes are emailed to account holders. Data protection questions: [email protected]. Anything else is on the contact page.