scanpass

Privacy Policy

Last updated: July 26, 2026

scanpass (scanpass.us) provides QR check-in tools for in-person events. This policy explains what information we collect, why we collect it, and what happens to it — whether you're an organizer running an event or an attendee checking in at the door. Questions are always welcome at hello@scanpass.us.

Information we collect

Organizer accounts. Sign-in is handled by our authentication provider, Supabase, using either an email and password or Google sign-in. scanpass stores your email address, an account identifier, and the time you accepted our terms. scanpass never stores your password — credentials live with Supabase, and Google sign-in shares no password with anyone.

Event and guest-list data. Organizers upload participant names and email addresses (via CSV or manual entry) to run check-in. When someone checks in, we record the time, how they checked in (QR scan or organizer action), and any name typed at the door.

Technical data. We set only the essential session cookies needed to keep organizers signed in — scanpass uses no analytics, no advertising cookies, and no tracking of any kind. IP addresses are used transiently to rate-limit requests and are not stored. If an error occurs, our optional error-monitoring service (Sentry) receives a technical report with personal-data collection disabled; error replays mask all text and block all media.

How we use information

Solely to operate the service: authenticating organizers, matching attendees against guest lists at the door, showing organizers their live roster, and keeping the service reliable. We never sell personal data, never share it for advertising, and build no profiles.

Google user data

If you sign in with Google, we receive your name and email address from your Google account and store only the email address. We request nothing else — no contacts, calendar, files, or other Google data. scanpass's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who can see your data

Organizers see only their own events and guest lists. Attendees see only their own name and check-in confirmation — never the rest of the list. Access by scanpass staff is limited to what's needed to operate and support the service.

We rely on a small set of service providers to run scanpass: Supabase (authentication), Render (hosting and database), Sentry (error monitoring), and Google (optional sign-in). Each processes data only as needed to provide their service to us.

If you're an attendee

If you check in to an event, the event's organizer added your email address to their guest list. We record your check-in time and any name you enter, visible only to that organizer. To have your information corrected or removed, contact the organizer — or email us and we'll help.

Retention and deletion

Organizers can delete an event at any time from its dashboard page, which permanently removes the event, its guest list, and every check-in record. Uploading a new CSV replaces the previous list entirely. To delete your account and everything in it, email hello@scanpass.usand we'll remove the account and all of its events.

Security

All traffic is encrypted with HTTPS, and access to data is scoped to the account that owns it. scanpass is free and collects no payment information.

Children

scanpass is not directed at children under 13, and organizers are responsible for ensuring they may lawfully upload the guest lists they provide.

Changes to this policy

When this policy changes, we'll update the date above and post the new version here. Material changes will be called out on the site.

Contact

Questions? Reach us at hello@scanpass.us.