1. Introduction
ScanAuctions (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal data when you use our platform at scanauctions.com and app.scanauctions.com.
2. Data we collect
We collect the following data:
- Account information: email address, company name, display name
- Platform credentials: encrypted AutoTrader, Motorway, and CarWow connection tokens (stored encrypted at rest using Fernet AES)
- Scan data: filter preferences, scan results, search history
- Usage data: login timestamps, feature usage, IP addresses for rate limiting
3. How we use your data
We use your data to provide the ScanAuctions service, including scanning auction platforms on your behalf, cross-referencing vehicle valuations, and delivering scan results. We do not sell your data to third parties.
4. Data security
All platform credentials are encrypted at rest using Fernet symmetric encryption (AES-128 in CBC mode with HMAC authentication). Our application uses HTTPS for all communications. Authentication uses JWT tokens with 24-hour expiry. No ScanAuctions employee can read stored marketplace credentials.
5. Data retention
Scan results are retained for 30 days. Account data is retained for the duration of your subscription and for 30 days after cancellation so you can export anything you need. You may request immediate deletion of your data by contacting us at any time.
6. Your rights under UK GDPR
Under UK GDPR you have the right to access, rectify, erase, or restrict the processing of your personal data. You also have the right to data portability and the right to object to processing. To exercise any of these rights, email us at hello@scanauctions.com and we will respond within 30 days.
7. Cookies
We use three categories of cookies:
Essential cookies: required for the app to function (session tokens, authentication). These are always on.
Affiliate tracking cookie (sa_ref): when you click an affiliate referral link, we store a cookie to track the referral for 30 days. This cookie is only set if you accept cookies via our cookie banner.
Analytics: if enabled, we use Google Analytics to understand how visitors use our site. You can opt out via our cookie banner at any time.
8. Children’s privacy
ScanAuctions is a B2B service for licensed UK car dealers and traders. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced via email to active account holders at least 14 days before they take effect.
10. Contact
For any privacy-related question or to exercise your GDPR rights, email hello@scanauctions.com. ScanAuctions Ltd, registered in England & Wales, Companies House #15234567.