Privacy Policy

Last updated: April 2026

1. Who we are

ScanTheGap is operated at scanthegap.com. We provide an AI-powered market gap discovery and product validation platform. When this policy refers to "we", "us", or "our", it refers to ScanTheGap. You can contact us at info@scanthegap.com.

2. What data we collect

Account information: When you register, we collect your name, email address, and a hashed password. We never store your password in plain text.

Payment information: Payments are processed by Stripe. We do not store your full credit card details. We receive only a tokenised reference and the last four digits of your card for display purposes.

Scan activity: We store the scans you run, the categories and markets you select, and the results generated. This data is tied to your account and used to provide your scan history.

Usage data: We collect standard server logs including IP addresses, browser type, pages visited, and time of access. This is used for security and performance monitoring.

Waitlist emails: If you join our waitlist before launch, we store your email address to notify you of launch and early access availability.

3. How we use your data

  • To provide and operate the ScanTheGap service
  • To process your subscription payments via Stripe
  • To send you transactional emails (account verification, password reset, billing receipts)
  • To notify waitlist members of product launch and early access
  • To monitor and improve platform performance and security
  • To comply with our legal obligations

We do not sell your personal data to any third party. We do not use your data to train AI models. We do not share your scan results or research activity with other users.

4. Public data we collect during scans

During a scan, ScanTheGap collects publicly available data from sources including Reddit, Apple App Store, Google Trends, Quora, and Product Hunt. This data is already publicly visible on the internet. We process it temporarily to generate your scan results. Raw collected data is automatically deleted from our systems after 90 days. We do not collect any private or login-protected content from these platforms.

5. Data sharing and third parties

We share your data only with the following categories of third-party services necessary to operate the platform:

  • Stripe — for payment processing
  • Mailgun / email provider — for transactional emails
  • AI API providers (DeepSeek, OpenAI, or Anthropic) — scan data is sent to the active AI provider for analysis. Data sent is anonymised scan content, not your personal information.
  • Hosting provider (Hostinger) — for server infrastructure

All third-party providers are contractually required to handle your data in accordance with applicable data protection laws.

6. Data retention

We retain your account data for as long as your account is active. If you delete your account, your personal data is anonymised immediately and permanently deleted within 30 days. Scan raw data is automatically purged after 90 days. Billing records may be retained for up to 7 years as required by financial regulations.

7. Your rights (GDPR)

If you are located in the European Union or European Economic Area, you have the following rights under GDPR:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate personal data
  • Right to erasure — request deletion of your personal data
  • Right to portability — request your data in a structured machine-readable format
  • Right to object — object to processing of your data for direct marketing
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent

To exercise any of these rights, email us at info@scanthegap.com. We will respond within 30 days.

8. Cookies

ScanTheGap uses essential cookies only — specifically a session cookie to keep you logged in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No cookie consent banner is required for essential cookies under GDPR.

9. Security

We implement industry-standard security measures including HTTPS encryption for all data in transit, bcrypt password hashing, encrypted storage of API keys, and regular security updates. No system is perfectly secure — if you believe you have found a security vulnerability please contact us immediately at info@scanthegap.com.

10. Children

ScanTheGap is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to this policy

We may update this privacy policy from time to time. We will notify registered users of material changes by email. The date at the top of this page indicates when the policy was last updated. Continued use of ScanTheGap after changes constitutes acceptance of the updated policy.

12. Contact

For any privacy-related questions or to exercise your data rights, contact us at info@scanthegap.com.