Privacy Policy
SiteScanReport LLC · Effective Date: September 1, 2026 · Last Updated: September 1, 2026
SiteScanReport LLC ("SiteScanReport," "we," "us," or "our") operates the website scanning service available at sitescanreport.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, when and with whom we share it, and what rights you may have with respect to it.
We do not sell your personal information. We do not use your information for advertising. We collect only what we need to deliver the Service and operate the business.
1. Information We Collect
1.1 Information You Provide. When you purchase a scan, you provide your email address (used to deliver your report and communicate with you about your order) and the URL you submit for scanning (the website address your report covers). If you request a free scan, you provide the website address you ask us to scan and your confirmation that you are authorized to scan it. The free scan displays a summary of your results on-screen; it does not require an email address or other contact information, and does not deliver a report by email. We keep a record of your authorization confirmation together with the standard request metadata described in Section 1.3. If you ask to be notified when our Monitoring service becomes available, you provide your email address for that single purpose. If you access the customer portal, you sign in with your email address, and we send a one-time sign-in code to that address. We do not collect your name, mailing address, or phone number. Payment information, including card and billing details collected during checkout, is collected and processed directly by Stripe on a Stripe-hosted checkout page and does not pass through our systems (see Section 3).
1.2 Information Generated by the Service. When you submit a URL for scanning, our systems generate scan results (accessibility findings, privacy-mechanism detection results, and security configuration data compiled into your report), scan metadata (scan ID, timestamp, pages scanned, and scan status), and a Stripe payment intent ID (retained to support refunds and dispute resolution).
1.3 Information Collected Automatically. When you visit sitescanreport.com, we collect standard web server log data, such as IP address, browser type, referring URL, and request metadata. We use this data solely for security monitoring, abuse prevention, and service reliability. We do not run third-party analytics or trackers on the site, and we do not use this data for behavioral profiling or advertising.
2. How We Use Your Information
We use the information we collect to: deliver your scan report to your email address; process refunds if your scan fails or you request one within our refund window; respond to support requests submitted to support@sitescanreport.com; detect and prevent abuse, fraud, and unauthorized use of the Service; comply with applicable law and respond to lawful legal process; monitor service reliability and investigate errors; notify you, if you asked, when our Monitoring service becomes available; and authenticate your access to the customer portal.
We do not send promotional or marketing emails. The one exception is that, if you join the Monitoring waitlist, we will send you a single email when Monitoring becomes available; that email includes a way to opt out, and we do not use a waitlist address for anything else. We do not build user profiles. We do not use your information, submitted content, or scan results to train machine-learning models, and we do not permit service providers to use personal information we disclose to them for their own advertising or unrelated model training except as described in this Privacy Policy.
3. Information We Share
We do not sell, rent, or trade your personal information. We share information only as described below.
3.1 Service Providers. We use the following third-party service providers to operate the Service. Each receives only the information reasonably necessary to perform its function on our behalf.
- Stripe, Inc. — payment processing. You complete checkout on a Stripe-hosted checkout page. Stripe collects and processes your payment card and billing information directly. We receive payment confirmation and a payment intent ID; we do not receive your full payment card details. stripe.com/privacy.
- Postmark (ActiveCampaign, LLC) — transactional email delivery. We provide your email address and the rendered PDF report to Postmark solely to send order-related emails and deliver your report on our behalf. Postmark does not use this information for its own marketing purposes. postmarkapp.com/privacy-policy.
- Amazon Web Services, Inc. (AWS) — cloud infrastructure and storage. Your email address, submitted URL, scan metadata, scan results, and PDF report are stored on AWS servers located in the United States, including the us-east-1 region. If you use the customer portal, we use Amazon Cognito (an AWS service) to email you a one-time sign-in code and authenticate your access. aws.amazon.com/privacy.
- Anthropic, PBC — AI narrative generation. Public content from your submitted URL may be transmitted to Anthropic's API to generate the narrative analysis included in your report. We do not intentionally send your email address or payment data to Anthropic, and we rely on Anthropic's applicable API terms governing use of submitted data. anthropic.com/privacy.
- Google LLC (Web Risk) — security screening. We submit the domain or URL you ask us to scan to Google's Web Risk service to screen it against Google's lists of known unsafe web resources, as part of security screening and abuse prevention. This submission is limited to the publicly accessible address being scanned. policies.google.com/privacy.
- Qualys SSL Labs — SSL/TLS analysis. We submit the domain from your submitted URL to the Qualys SSL Labs API to evaluate certificate, protocol, and cipher configuration as part of the security portion of your report. This submission is limited to the publicly accessible domain being scanned. qualys.com/privacy.
3.2 Legal Requirements. We may disclose your information if required to do so by law, subpoena, court order, or other legal process, or if we believe in good faith that the disclosure is necessary to protect our rights, enforce our agreements, protect your safety or the safety of others, or respond to fraud, security, or technical issues.
3.3 Business Transfers. If SiteScanReport LLC is acquired, merged, or its assets are transferred, your information may be transferred as part of that transaction. We will notify you via email if your information becomes subject to a materially different privacy policy as a result.
4. Data Retention
We keep your information only as long as we need it for the purposes for which it was collected and to meet our legal, operational, and recordkeeping obligations, and then we delete it. Because you receive and keep your own copy of every report, we do not need to retain your scan data indefinitely.
- Content fetched during the scan. The full public content we fetch from your submitted URL to generate your report, including any privacy-policy text or similar page content, is used only to produce your report and is discarded once that processing is complete. We do not retain the fetched source pages after your report is generated. Your scan results, retained for the period described below, may include short excerpts of the specific page elements associated with a finding, such as the markup of an element flagged for an accessibility issue, which we keep as evidence supporting that finding.
- Scan results. Your scan results are retained for up to 90 days and then deleted.
- Report PDF. Your report PDF is retained for up to 12 months so that you can re-download it from the customer portal and so that we can support any refund or dispute, and then it is deleted. You may request earlier deletion (see below).
- Order metadata. Your email address, scan ID, and Stripe payment intent ID are retained for up to 24 months to support refunds, disputes, and legal recordkeeping, and then deleted.
- Payment records. Payment records and payment card data are retained by Stripe in accordance with Stripe's policies and applicable legal and regulatory requirements.
Our stored scan records are held in tamper-resistant storage so that they cannot be altered in the ordinary course, but they remain deletable by us through a controlled, audited process — including to honor a valid deletion request or to remove content we are required to remove. To request deletion of your personal information, contact us at support@sitescanreport.com. We will review and honor deletion requests to the extent required by applicable law, subject to any active refund or dispute window and to our remaining legal and recordkeeping obligations.
5. Data Security
We implement technical and organizational measures designed to protect your information against unauthorized access, disclosure, alteration, and destruction. These measures include: encryption of stored data on AWS using AWS Key Management Service (KMS); encryption of data in transit using TLS; access controls that limit which system components can read or write specific data; tamper-resistant storage of retained scan records; and no payment card data stored on our infrastructure.
No method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we take our obligations seriously and maintain safeguards appropriate for a service of this type.
6. Third-Party Websites
Our reports or Service may include references or links to third-party websites and resources (such as accessibility guidance at dequeuniversity.com or WebAIM). We are not responsible for the privacy practices of third parties. This policy applies only to information collected through the Service.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at support@sitescanreport.com and we will take appropriate steps to delete it or otherwise address it as required by applicable law.
8. Your Privacy Rights
Depending on applicable law, you may have certain rights regarding your personal information, including rights to access, correct, or request deletion of your data. To exercise any applicable rights, contact us at support@sitescanreport.com with your request. We will respond within a reasonable timeframe and in accordance with applicable law, subject to any legal exceptions, active refund or dispute windows, and retention requirements that apply to particular records.
We do not sell personal information and therefore do not offer a "Do Not Sell" opt-out. We do not use personal information for targeted advertising.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. If we make material changes, we will make reasonable efforts to notify affected users as appropriate. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
10. Contact
SiteScanReport LLC · support@sitescanreport.com · sitescanreport.com