Privacy Policy
How Scan Yer Van collects, uses, and protects your personal information.
Last updated: 29 September 2026
The short version
If you scanned a sticker: we record the time and your device type. We record where you were only if you choose to share it, and then only to about 100 m (about 1 km after 90 days) — never worked out from your IP address. Your IP address is kept, encrypted, for 30 days to stop abuse, then deleted. The business sees how many scans it had and which button was tapped, never who you are. Calls, texts, WhatsApp messages and emails go straight from your phone to the business; we never see them.
If you're a subscriber: we hold your business, vehicle, delivery and billing details to run your account. Your business name, logo, number plate, vehicle make and contact buttons are public on your contact page. No adverts, no selling data. Questions: [email protected], and you can always complain to the ICO.
Who we are
Scan Yer Van is a service operated by SCAN YER VAN LTD, a company registered in Scotland (Company No. SC858856), with a registered office at 5 Longmorn Crescent, Elgin, Scotland, IV30 6GP.
We are the data controller for the personal information you provide when using this website and service. If you have any questions about how we handle your data, email [email protected], write to us at the address above, or use our contact page.
This policy covers two groups of people: subscribers (businesses that hold a Scan Yer Van account) and members of the public who scan a sticker.
If you scanned a sticker
You scanned a QR sticker on a work van and landed on that business's contact page. Scan Yer Van provides the sticker and the page; the business is the one you're contacting.
- Contacting the business — tapping Call, Text, WhatsApp or Email opens your own phone's apps and the conversation is directly between you and the business. We don't receive, store or pass on anything you say. We only count that a button was tapped.
- Saving the contact — "Save to my contacts" downloads the business's public details as a contact file for your phone. It is made when you tap and is not stored by us; we only count that it was tapped.
- What we record about the scan — the time, your device type and browser, and the network (IP) address of the request, which is stored encrypted, used only to investigate abuse, and deleted after 30 days.
- Your location — only if you choose to share it, and only as an approximate area. See Location data below.
- What the business sees — how many scans it had, when, which button was tapped and, if you shared it, the rough area. It never sees who you are.
What information we collect
We collect the following categories of personal data:
- Business details — your business name and email address, provided during sign-up, and any profile details you add (such as your logo, description, website and social links, company number and VAT number).
- Contact phone number — if you add one to your profile. It is stored encrypted, and we confirm it by sending a one-time code by text message (SMS).
- Delivery address — the address your stickers are posted to. It is stored encrypted.
- Vehicle details — the UK registration numbers of your vehicles, stored encrypted (AES-GCM). We use each registration to look up the vehicle's details from the DVLA Vehicle Enquiry Service and the DVSA MOT History API — for example make, colour, MOT and tax status, and MOT and tax expiry dates. We use these details to design your stickers, to show your Van Health (MOT and tax) status in your dashboard, and to send MOT and tax reminder emails about 30, 14 and 7 days before each due date. You can switch these reminders off at any time in your dashboard notification settings.
- Payment information — processed securely by Stripe. We do not store card details.
- Referrals — if you sign up through another subscriber's referral link, we record that they referred you (so they get their discount) and keep a scrambled (hashed) form of your email address against your one-off discount code, so each address gets one code per referrer. We never email anyone on a subscriber's behalf: subscribers share their link themselves.
- Scan analytics — when someone scans your QR code: the device type and browser, the time of the scan, and — only if the person allows their browser's location request — their location, which we then reduce to an approximate area (see Location data below). Location comes from the visitor's own device, never from their IP address. We also record the network (IP) address of the request. It is stored encrypted and used only for security and abuse prevention; we do not use it to work out where a scan happened.
- Public Van Health check — if you use the free check on our Van Health page, the registration you enter is sent to the DVLA and DVSA to get the results. We do not store it. We only count that a check was made, whether it found a vehicle and how long it took — not the registration, and not who made it.
- Discount code requests — if you ask us to email you a discount code, the email address you give us and the code we send you.
- Pre-registration details — if you register early interest: your name or business name, email address, business type and approximate number of vans.
- Contact enquiries — the name, email address and message you submit through our contact page.
- Technical data — server logs including IP addresses, pages visited, and browser/device information, collected automatically for security and performance purposes.
What is public: a subscriber's business name, logo, description, website and social links, and each vehicle's number plate, make, model and colour appear on that vehicle's contact page, which anyone who scans the sticker can see. The phone number and email address power the contact buttons, so a person who taps Call, Text or Email will see them. A delivery address is never public.
We do not ask for special category data (such as health information) or criminal-offence data, we do not make decisions about you by automated means alone, and we do not knowingly collect data from children under 16.
Lawful basis for processing
Under UK GDPR, we rely on the following lawful bases:
- Contract performance — to create and manage your account, process payments, print and deliver your QR code stickers to your delivery address, look up your vehicles' details and send MOT and tax reminders, confirm your contact phone number, and provide the service you've subscribed to.
- Legitimate interests — to provide scan analytics to your dashboard, record the network (IP) address of scans to detect and prevent fraud or abuse, maintain the security of our platform, send a referral invite to a business a subscriber has asked us to invite, run the public Van Health check you have asked for, and see where signing up and using the dashboard are hard so we can make them easier. We've weighed these against your rights: scan counts contain no names, the business never learns who scanned, and scan IP addresses are deleted after 30 days.
- Legal obligation — to retain financial records as required by HMRC (6 years from the end of the accounting period).
- Consent — when a person scanning your QR code agrees to share their GPS location, and when someone registers early interest to receive launch updates. Consent can be declined and withdrawn at any time.
- Things you ask us for — where you use our contact form or ask us to email you a discount code, we use what you send to reply or to send the code, on the basis of taking steps at your request and our legitimate interest in answering you.
How we use your information
- To create and manage your Scan Yer Van account and subscription.
- To generate, print and deliver your personalised QR code stickers.
- To provide scan analytics in your dashboard (scan counts, device types, approximate areas, and the weather and type of area at the time of a scan).
- To show your vehicles' MOT and tax status and send MOT and tax reminder emails.
- To process payments and issue receipts via Stripe.
- To send service emails (account access codes, account setup, order updates, MOT and tax reminders you can switch off, and important service notices).
- To send the emails you asked for when registering early interest (your invite and occasional launch updates).
- To detect and prevent misuse of the platform.
- To comply with our legal obligations.
We do not use your data for advertising, profiling, or sale to third parties.
Location data
When someone scans a QR sticker, we may record the rough area the scan happened in — but only if that person chooses to share it, and only from their device's browser. We never work out location from IP addresses.
- Consent first — the person scanning is asked before any location is read, and can decline. Declining still lets them reach the business; the scan is simply recorded without a location.
- Weather and area context — straight after a scan, the shared location is sent to the providers that tell us the weather, daylight, postcode area and local area information for that spot (see Third-party processors below). This happens before the location is reduced.
- Approximate only — once those lookups are done (normally within about a minute), the location we keep is reduced to an approximate area of roughly 100 m. If the lookups fail, it is reduced anyway within 24 hours. After 90 days it is reduced further, to roughly 1 km.
- Areas, not addresses — the business sees scans grouped by postcode district (a whole town area, such as "IV30"), never a street or an address.
- What it is for — it gives the business owner a rough sense of which areas their van gets noticed in (area lists and a hot-spot map). It is never used to track or identify the person scanning.
- Your control — sharing location is optional at every scan; there is nothing to opt out of beyond declining the prompt.
Third-party processors
We use the following providers to run the service. Each receives only the data it needs for its purpose:
Hosting and infrastructure
- Smaoin Ltd — operates on our behalf the UK server that runs the website, the database that holds your information, its backups, and the collection of our server logs. Smaoin Ltd is a separate Scottish company, connected to us by common directors, and acts as our processor under a data processing agreement.
- Fasthosts — provides the UK data centre and the virtual private server itself.
- Microsoft Azure — file storage (such as sticker print files), secure storage of encryption keys and passwords, internal messaging between parts of the service, and storage of our software releases.
- Cloudflare — content delivery, DNS and security for our websites, Turnstile (privacy-friendly bot prevention on forms), and Web Analytics: page-view statistics for our public website (pages visited, referring site, browser and device type, country, and page speed), used to improve the website. It uses no cookies, doesn't store your IP address or follow you across other sites, isn't used for advertising, and isn't used on signed-in pages or on the scan links printed on stickers. You can turn it off, and we honour the Global Privacy Control browser signal. See Cloudflare's Privacy Policy.
- Grafana Labs — storage and search of our server logs, for security and diagnostics, in an account operated by Smaoin Ltd on our behalf.
Payments, email and printing
- Stripe — payment processing, subscriptions, invoices and discount codes. Card details are entered directly with Stripe and are not stored by us. See Stripe's Privacy Policy.
- Brevo — sending our emails (such as login codes, account and order emails, and reminders) and the text messages that confirm your phone number.
- Migadu — our email mailboxes (such as [email protected]), which receive the emails you send us, including messages from our contact form. Migadu is based in Switzerland.
- Our print and delivery partner — a UK sticker printer that prints your stickers and posts them to you. It receives the name and delivery address for the order, and the sticker designs.
Vehicle and business checks
- DVLA Vehicle Enquiry Service and DVSA MOT History API — vehicle details and MOT and tax status. They receive the vehicle registration.
- Ideal Postcodes — address lookup when you enter your delivery address. It receives the postcode or address you type.
- Companies House and HMRC — checking a company number or VAT number you add to your profile. They receive that number.
- Google — Safe Browsing (safety checks on the website links you add). See Google's Privacy Policy.
- Cloudflare — the family filter (1.1.1.1 for Families), which checks the website links you add are not adult or malware sites. It receives the website's domain name only. See Cloudflare's Privacy Policy.
Scan context and maps
- OpenWeatherMap — the weather at the time and place of a scan. It receives the shared scan location.
- sunrise-sunset.org — whether a scan happened in daylight. It receives the shared scan location.
- postcodes.io — the postcode area of a scan. It receives the shared scan location.
- data.police.uk — local area information for scans in England and Wales. It receives the shared scan location.
- OpenStreetMap and CARTO — background map imagery for the scan hot-spot map. Only the map area being viewed is requested; no scan, location or customer data is sent to them. See OpenStreetMap's Privacy Policy.
Feedback
- Formbricks — the software behind our feedback surveys. It is not run as a service by Formbricks: it is self-hosted on the UK server operated on our behalf by Smaoin Ltd (see Hosting and infrastructure above). Your answers are not sent to Formbricks.
We do not share your data with any other third parties unless required by law. Where any processor stores or processes personal data outside the UK, we rely on the UK's approved safeguards — a UK adequacy decision for the country concerned (as for Switzerland), the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework, as applicable.
How long we keep your data
- Account data — kept while you have an account. You can ask us to delete your account from your dashboard; we then delete your account, profile, vehicles, QR codes and scan records, along with your logo, the print files made for your stickers, and anything else we hold under your email address (your waiting-list entry, any discount code, sign-in codes), normally within a day. Payment and invoice records are held by Stripe, and we keep financial records for 6 years, as HMRC requires.
- Scan records — kept while your account is active. Your plan affects what your dashboard shows, not how long scans are kept.
- Scan network (IP) addresses — kept, encrypted, for 30 days and then deleted from the scan record. They are only ever used to investigate abuse of a public page, never to work out where a scan happened. So that refreshing the page is not counted as a second scan, we also keep a scrambled code made from the address and browser type; it cannot be turned back into either, and it is deleted within 24 hours.
- Scan locations — reduced to roughly 100 m straight after the weather and area lookups (or within 24 hours if they fail), and to roughly 1 km after 90 days.
- Audit logs — records of account activity, kept for 90 days.
- How customers use the service — while you sign up and when you use your dashboard, we record the steps you take: which step, whether it worked, and how long it took. It shows us where the service is hard to use. It is kept for 13 months, and deleted with your account. Nothing like this is recorded for anyone who scans a sticker.
- Contact-form messages — kept for as long as needed to deal with them, and no longer than 12 months; you can ask us to delete them sooner.
- Discount-code requests — a code you ask for after scanning a sticker lasts 90 days. The code and the email address it was sent to are deleted 30 days after it expires, whether or not you used it.
- Pre-registration details — kept until you sign up. If you don't, they are deleted 12 months after we invite you to sign up (or 12 months after you joined the list, if we haven't invited you by then). They are removed sooner as soon as you ask, by replying to any email from us.
- Sign-in and verification codes — deleted within a day of expiring.
- Payment notifications — our record that Stripe told us about a payment (a reference number, no card or personal details) is deleted after 90 days. The payment itself stays in Stripe.
- Server logs — retained for up to 90 days for security and diagnostic purposes.
Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data, subject to our legal retention obligations.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests. You can object to marketing emails at any time and we will always stop.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email [email protected] or use our contact page. We will respond within one calendar month.
Complaints
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) — the UK's supervisory authority for data protection. Visit ico.org.uk for details.
Changes to this policy
We may update this Privacy Policy from time to time. We'll update the "last updated" date above and, for material changes, notify you by email or a prominent notice on the site.