Privacy Policy
The honest summary: we collect the minimum needed to run a certificate monitor - your e-mail, the endpoints you ask us to watch, and what those endpoints publicly present. We run no advertising trackers, we sell nothing about you to anyone, and your card details go to our payment provider, never to us.
1. Who is responsible
The data controller is SSL Scan - reachable at privacy@sslscan.net. For payment data, Paddle.com Market Ltd acts as merchant of record and processes your payment details under its own privacy policy.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | E-mail address, organisation name, a one-way scrypt hash of your password | You, at signup |
| Monitoring configuration | Hostnames, ports, imported server lists, internal-CA patterns | You, in the product |
| Scan results | Certificates as publicly presented by the endpoints you monitor, their chains, protocol details, findings and their history | Your endpoints, when we check them at your request |
| Billing state | Plan, subscription status, renewal date, order identifiers | Paddle, via signed webhooks |
| Operational logs | IP address and user agent of requests to our API, timestamps, error records | Automatically, as any web service |
| Usage analytics | Pages viewed, clicks, device and browser, approximate location from IP; in the app, events tied to your account | PostHog - an anonymous, cookieless visit count on this website (no consent needed, nothing stored on your device); richer, identified analytics only if you accept; in the app, as part of using it |
| Correspondence | E-mails you send to support, security or privacy addresses | You |
3. Why we process it, and on what legal basis
- To provide the service - monitoring the endpoints you configured, alerting you, operating your account. Basis: performance of our contract with you.
- To bill you - matching subscription state to your account via our merchant of record. Basis: performance of contract; legal obligations around bookkeeping.
- To keep the service secure - abuse prevention, rate limiting, investigating incidents, enforcing the acceptable-use policy. Basis: legitimate interest in running a safe service.
- To communicate - service e-mails such as alerts you asked for, trial-conversion reminders, security notices, and replies to your questions. Basis: performance of contract. We do not send marketing e-mail unless you explicitly opt in, and every such e-mail unsubscribes in one click.
- To improve the product - privacy-friendly analytics of how the site and app are used, so we can make them better. Basis: legitimate interest for the anonymous, cookieless website visit count and for in-app analytics; your consent for identified analytics and session replay on the website.
We do not profile you, and no decision with legal effect on you is automated.
4. Cookies & analytics
This website sets no cookies and stores nothing on your device unless you accept the banner shown on your first visit. What runs before any choice is a single anonymous, cookieless measurement: PostHog (US-hosted) counts the visit using an identifier it derives on its own servers from coarse signals (a key that rotates daily, your IP and your browser), so we can see how many people visit and which pages are popular. Nothing is written to your device, and it cannot be used to identify you. Basis: our legitimate interest in understanding traffic.
If you accept, we additionally enable identified product analytics - pages viewed, clicks, device and browser, approximate location from your IP - and, only if you also switch on session replay, a recording of how visitors move through the public pages (anything you type, such as a domain in the check box, is masked). This is product analytics, not advertising: no ad networks, no cross-site profiling, nothing about you sold to anyone. Basis: your consent. If you decline, none of it runs - and the anonymous count above stops too, so nothing at all is collected from you on this website beyond a small record of that choice. In the signed-in app the same product analytics runs as part of the service and is tied to your account so we can see which features help. It is cookieless: the app stores nothing on your device for analytics - your sign-in is what identifies you - which is why the app shows no banner, there being no local identifier to consent to. It records which screens and features you use, never certificate contents, private keys, or the host names in your inventory. Basis: our legitimate interest in improving the app. You can change your choice any time from “Cookie settings” in the footer, or by e-mailing privacy@sslscan.net.
5. Who we share data with
No selling, no renting, no “data partnerships”. Data leaves our systems only to the short list of processors needed to run the service - hosting, payments, e-mail delivery - each bound by contract to process it only on our instructions. The current list, with roles and regions, is public at /legal/subprocessors. Beyond that, we disclose data only if a law or court order genuinely compels it, and where lawful we tell you first.
6. Where data lives
Production systems run on Google Cloud Platform in European regions, with static assets served by Firebase Hosting’s CDN. Where a processor handles data outside the EEA/UK, transfers rest on recognised safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
7. How long we keep it
| Data | Kept |
|---|---|
| Account, configuration, scan results | While your account exists. Deleted when you delete the account. |
| Backups | Encrypted, rotated on a fixed schedule; deleted data leaves backups as they cycle out, within 35 days. |
| Operational logs | Rotated on a short schedule, typically within 90 days. |
| Invoices and tax records | Retained by Paddle for the period tax law requires. |
| Support correspondence | As long as useful for the relationship, then deleted. |
8. Your rights
Depending on where you live (including under the EU/UK GDPR), you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable format, and to withdraw consent where processing rests on consent. To exercise any of them - including a copy of your inventory, or deletion of your account - e-mail privacy@sslscan.net - we respond within 30 days. You also have the right to complain to your data-protection authority, though we would appreciate the chance to fix things first.
9. How we protect it
Encryption in transit and at rest, tenant isolation at the data layer, passwords hashed with scrypt, secrets in platform secret management rather than code, and a deliberately small data footprint - the fullest protection is not holding the data at all. Details are on the security page. If a breach ever affects your personal data, we will notify you and the competent authority as the law requires, and plainly.
10. Children
SSLScan is a business tool, not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
When the product gains a capability that changes what we process - a new alert channel, a new integration - this policy is updated first, the date at the top changes, and material changes are announced by e-mail before they take effect.
12. Contact
privacy@sslscan.net · or in writing: SSL Scan.