Privacy
What we hold.
What a scan reads
Scopras requests publicly available pages and files from the address you give it — the product page, the homepage, robots.txt and the sitemap. A separately agreed audit may also read a feed you supply for that audit. The public scanner does not connect to a store account. Scopras never submits a form or writes anything to your store.
Requests are refused before they are made if the address resolves to a private network, a non-standard port, or carries credentials. That applies to every redirect the store sends us through, not only to the address you typed.
Scans without an account
The report is not stored. The findings and evidence are returned to your browser and are not saved as a scan. The short-lived abuse ledger described below still records the store domain, a salted hash of the caller address and the request time.
Scans with an account
A scan you run while signed in is saved so the next one can be read against it. It holds the addresses read, the excerpts quoted as evidence, and the findings.
Only you can read it. Access is enforced by the database through row-level security rather than by the application filtering a query, so a scan belonging to another account is not readable even by a request that names its identifier exactly.
Deleting your account deletes your profile, your stores and every saved scan filed against them. A rate-limit row may remain without the account identifier until its normal cleanup pass.
Rate limiting
The free scanner keeps a count so it cannot be turned into an open proxy against other people’s servers. Your IP address is hashed with a secret salt before it is written and is never stored in the clear. Each row also holds the requested store domain and the request time. Rows stop counting after 24 hours and are deleted by a later cleanup pass. They exist only to enforce the scanner’s caller and service ceilings.
Payments and founding audits
Founding-audit checkout is hosted by Stripe. Stripe receives the payment details; Scopras does not receive or store your card number. We store the Checkout session and payment references, contact email, amount, currency and payment status so an order can be verified and fulfilled. We also store that the terms checkbox required by Stripe Checkout was accepted; Scopras does not use that checkbox for marketing consent. If a payment is partly or fully refunded, or disputed through a bank, we retain the refund amount and Stripe’s dispute status and reason so work is not performed against a reversed or contested payment.
After payment, the scope form stores the contact name and email, store address, target markets, available product sources and any scope note you provide. This information is used to agree and deliver the audit. Checkout-attempt rows contain only a salted caller hash and time; they stop counting after 24 hours and are deleted by a later cleanup pass.
Scopras uses Resend to alert its operator when a payment, audit scope, refund or payment dispute needs attention. The alert contains an internal order identifier and a link to the private order panel. It does not contain your email address, store address, payment amount or scope notes. The operator’s destination email is processed by Resend to deliver that alert.
Order and scope records are currently retained after delivery for customer support and accounting history. You can ask us to delete the scope details; a limited transaction record may still be kept where tax, accounting or dispute obligations require it. Send that request to yusufegeusta07@gmail.com.
Accounts
Authentication is handled by Supabase. If you sign in with Google, we receive your email address and nothing else; we do not request access to any Google service. Passwords are never seen by this application — the form posts to the server, which passes the credentials straight to the authentication provider.
Catalogue monitoring
When you add a monitored store, Scopras stores its domain, product addresses discovered from public sitemaps or homepage links, the sitemap change date when one is published, observation status, findings and change history. This is required to compare one complete observation with the next and to avoid treating an incomplete response as a change. Removing a monitor deletes its queued products, observations and alerts.
The latest reliable observation for each product and observations linked to an alert are kept while the monitor exists. Other intermediate product observations are removed after seven days; sent email-delivery records are removed after 30 days.
Stripe hosts subscription checkout and the billing portal. Scopras stores the Stripe customer, subscription and price references, plan, billing status and period end; it does not receive your card number. When a verified catalogue change creates an alert, Resend processes your account email, the store domain, product address and short change summary to deliver it.
Analytics and tracking
There are none on Scopras. No analytics script and no advertising pixel. The only cookies this site sets are the ones that keep you signed in. Stripe’s hosted checkout has its own privacy and cookie practices while you are on Stripe’s domain.
Asking us anything
To see or delete account data, open your account settings. For anything else, write to yusufegeusta07@gmail.com.
