Scanlotz Cloud

Privacy Policy

Last updated August 2026 · applies to Scanlotz Cloud and everything served from https://scanlotz.quickbidz.com.

1. What this covers

This policy explains what we collect when you visit this site, create an account, and use Scanlotz Cloud. For the personal data inside your own workspace — your staff, your customers — you are the controller and we are the processor; see the Data Processing Addendum.

2. What we collect

  • Account data — company name, your name, work email, phone if you give one, and the workspace address you choose.
  • Sales enquiries — what you type into our contact form, kept so we can reply and so we know where a customer came from.
  • Authentication and security data — password hashes (never the password), session records, sign-in times, IP addresses and user agents, and failed sign-in counts.
  • Usage metering — counts of scans, lookups and API calls per month, which is how plan limits and invoices are calculated.
  • Operational logs — request paths, timings and errors, retained for a short period for debugging and abuse prevention.
  • Payment data — handled by our payment processor. Card numbers never reach our servers; we store the processor's customer and subscription identifiers.

3. What we do not do

We do not sell personal data. We do not run advertising trackers on this site. We do not read the contents of your workspace except when you ask us to help and grant time-boxed access, which is logged and shown to you in your own console.

4. Cookies

One cookie: a signed session cookie set when you sign in, so the console knows who you are. It is HTTP-only, expires, and is deleted when you sign out. No analytics or advertising cookies are set by this site.

5. Why we may lawfully process this

To perform our contract with you (running your account), for our legitimate interests (securing the platform, preventing abuse, replying to sales enquiries), and to meet legal obligations such as keeping tax records.

6. Sharing

We use a small number of infrastructure and data subprocessors — hosting, email delivery, payment processing, and the sources behind product identification and retail pricing. Each is bound by contract, receives only what it needs, and appears on our current subprocessor list, available on request to any customer and to anyone who asks at support@quicklotz.com. We also disclose data where the law compels it, and will tell you unless we are forbidden from doing so.

7. Retention

Account and workspace data is kept while your account is live and for 30 days after cancellation, then deleted. Security and audit records are kept for up to 12 months. Sales enquiries are kept for up to 24 months. Invoices are kept as long as tax law requires.

8. Your rights

You can ask for a copy of your data, correct it, delete it, or object to a particular use. Because each customer's workspace is a separate database, an access or deletion request is a single, verifiable operation on one file set. Write to support@quicklotz.com and we will answer within 30 days.

9. Security

Passwords are hashed with PBKDF2. API and device credentials are stored only as hashes and shown once. Traffic is encrypted in transit. Each customer's data lives in its own database file rather than a shared table, and staff access to a customer workspace requires a logged, expiring grant that the customer can see.

10. Contact

Privacy questions: support@quicklotz.com.


This page is a plain-English statement of how we operate. If you need a countersigned copy or your own paper, write to support@quicklotz.com.