Privacy Policy
Effective date: 13 July 2026. POPIA (South Africa) and GDPR aligned. Template — please have a qualified attorney review and complete the legal details before launch.
ScanStand helps exhibitors capture and manage leads at trade shows and events. This policy explains what personal information we process, why, and your rights. The Service is operated by [registered company name — to be added], trading as ScanStand (“ScanStand”, “we”, “us”), the responsible party for the processing described here.
Information we process
- Exhibitor accounts: names, email addresses, and login credentials (passwords are stored only as a secure hash).
- Captured leads: the contact details a visitor provides (name, email, mobile, company, job title) and any notes, tags, or interest information, captured with consent.
- Business cards: where you use card scanning, the card image and the details extracted from it.
- Billing: billing contact details and payment references. Card payments are handled by our payment providers; we do not store full card numbers.
- Technical and usage data: limited log, device, and diagnostic data used to operate and secure the Service.
How we use your information
We use personal information to provide and operate the Service, capture and manage leads, deliver follow-up emails, process payments, provide support, secure the platform and prevent abuse, and comply with legal obligations.
Lawful basis and consent
Visitor details are captured with explicit consent for follow-up. Exhibitors are the responsible party (operator) for the leads they collect; ScanStand processes that data on their behalf and under their instructions. Account and billing data is processed to perform our contract with you and to meet legal obligations.
Sharing and sub-processors
We do not sell personal information. We share it only with service providers who process it on our behalf:
- Payment processing: Paystack and Stripe.
- Email delivery: Resend and our own SMTP mail service.
- AI features: Anthropic (Claude), for optional business-card scanning and lead-assistant suggestions.
- Error monitoring: Sentry, configured not to send personal data by default.
- Hosting and infrastructure: our cloud hosting provider.
We may also disclose information where required by law or to protect our rights.
AI processing
When you use optional AI features, the relevant data (a business-card image, or a lead’s captured details) is sent to our AI provider to return the extracted fields or suggested text. This processing is transient, is used only to provide the feature to you, and your data is not used to train the provider’s models. AI output may be inaccurate and should be reviewed.
Cross-border transfers
Some of our sub-processors (including our AI, email, error-monitoring, and payment providers) are located outside South Africa. Where personal information is transferred abroad, we take reasonable steps, as required by POPIA section 72 and applicable law, to ensure it receives an adequate level of protection.
Where data is stored and retention
Personal data is stored in our PostgreSQL database. Leads may be automatically anonymised a configurable period after an event ends, and we retain other data only as long as needed for the purposes above or as required by law.
Security
We use reasonable technical and organisational measures to protect personal information, including encryption in transit, hashed account passwords, encrypted credentials for connected integrations, tenant isolation, and access controls. No system is completely secure, but we work to protect your data and to notify you of material breaches as required by law.
Cookies
We use a strictly necessary, HttpOnly session cookie to keep you signed in, and limited cookies for security and error monitoring. We do not use advertising or third-party tracking cookies.
Your rights
You may request access to, correction of, or deletion of your personal information, and may object to or restrict certain processing. Exhibitors can export, delete, or anonymise any lead from their dashboard at any time.
Complaints
If you have a concern about how we handle personal information, please contact us first. You also have the right to lodge a complaint with the Information Regulator (South Africa) or, where applicable, your local data protection authority.
Children
The Service is intended for business use and is not directed at children under 18.
Changes to this policy
We may update this policy from time to time. The updated version will be published here with a revised effective date.
Contact
For privacy requests, contact our Information Officer at [email protected], or write to [registered company name — to be added], [registered business address — to be added], South Africa.