Privacy Policy
Effective date: August 10, 2026 · Last updated: August 10, 2026
1. Who We Are
Digital Footprint Scanner (“the Service,” “we,” “us”) is operated by TRUTH Communications Media & Publications, a sole proprietorship registered in Ontario, Canada, owned by Wayne Hinds. The Service is the companion application to the book Reclaim Your Digital Gold (2nd Edition). We are a privacy-first company: this policy is written to meet Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) first, and also to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) for our international users.
Privacy questions or requests: support@digitalfootprintscanner.com
2. What Information We Collect
Information you provide: your name, city/region, and email address when you run a scan; your account credentials (email and password, or Google sign-in) when you create an account; and billing details when you subscribe (processed by Stripe — we never see or store your full card number).
Scan results: when you run a scan, the Service queries publicly available sources — search engines, social platforms, people-search directories, and known data-breach databases — and compiles the results (“findings”) linked to your account.
Collected automatically: basic technical data needed to run and secure the Service, such as IP address, browser type, device information, and pages visited. We use this for security, rate limiting, abuse prevention, and to understand how the Service is used.
3. How We Use Your Information
- To run your scans and generate your Digital Inventory, risk scores, and removal guides
- To operate your account, save your scan history, and power features you have enabled (cleanup tracker, monitoring, reappearance alerts)
- To process payments and manage subscriptions through Stripe
- To send service emails (scan results, account and billing notices) and, only with your consent, product updates and educational content — you can unsubscribe anytime
- To secure the Service, prevent abuse, and comply with legal obligations
We do not sell your personal information. We do not share it with data brokers. We do not use your scan findings for advertising.
4. Consent and Legal Bases
Under PIPEDA, we collect, use, and disclose personal information with your knowledge and consent, for purposes a reasonable person would consider appropriate. By running a scan or creating an account, you consent to the collection and use described in this policy. You may withdraw consent at any time by deleting your account or contacting us, subject to legal or contractual restrictions.
For users in the European Economic Area or UK, our legal bases under GDPR are: performance of a contract (running your scans and account), consent (marketing emails), and legitimate interests (security and abuse prevention).
5. Scan Data and Retention
- Anonymous free scans (no account): inputs and results are processed to display your findings and are automatically deleted from our systems within 24 hours.
- Account scans: your scan history and findings are encrypted and stored to power your tracker, monitoring, and alerts — that is their only purpose. They are retained while your account is active.
- Deletion: you can delete individual scans or your entire account at any time from your account settings, or by emailing support@digitalfootprintscanner.com. Account deletion permanently removes your profile, scan history, and findings within 30 days, except minimal billing records we must keep for tax and accounting law.
6. Scanning Only Yourself
The Service is designed for you to scan your own digital footprint, or that of a person who has given you their clear consent (for example, a family member on a Pro family plan). Running scans on another person without their consent violates our Terms of Service and may violate privacy law. We apply email verification, rate limits, and abuse detection to enforce this.
7. Service Providers We Share Data With
We share personal information only with the service providers required to operate the Service, under contracts that limit their use of your data:
- Supabase — secure database and authentication (data encrypted in transit and at rest)
- Lovable — application hosting
- Stripe — payment processing (PCI-DSS certified; we never store card numbers)
- Google — optional “Sign in with Google” authentication
- Data sources — when you run a scan, your search terms (such as your name and city) are submitted as queries to public search and breach-lookup services in order to retrieve your results
We may disclose information if required by law, court order, or to protect the rights and safety of our users or the public.
8. Where Your Data Is Stored
Our infrastructure providers store data on secure servers that may be located in Canada, the United States, or the European Union. Where personal information is processed outside Canada, it may be subject to the laws of those jurisdictions. We use providers with strong contractual and technical safeguards regardless of location.
9. How We Protect Your Data
We protect personal information with encryption in transit (TLS) and at rest (AES-256), database-level row security that restricts every record to its owner, access controls and least-privilege keys, rate limiting and bot protection, and continuous security review of our infrastructure. No system is perfectly secure; if a breach affecting your personal information creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
10. Your Rights
Wherever you live, you can: access the personal information we hold about you; correct inaccurate information; delete your data; withdraw consent; and receive a copy of your data in a portable format. To exercise any right, use your account settings or email support@digitalfootprintscanner.com — we respond within 30 days.
- Canada (PIPEDA): you may challenge our compliance and may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
- EEA/UK (GDPR): you additionally have rights to restrict or object to processing, and to lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of sale/sharing. We do not sell or share personal information as defined by the CCPA, and we honour Global Privacy Control signals.
11. Cookies and Analytics
We use essential cookies required for sign-in and security, and privacy-respecting analytics to understand aggregate usage. We do not use advertising cookies or cross-site tracking. Where consent for non-essential cookies is required by law, we ask for it before setting them.
12. Age Requirement
The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. Parents or guardians who believe a minor has provided us information may contact us for deletion. (Educational institutions interested in supervised classroom use should contact us directly.)
13. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be announced on this page and, for account holders, by email. The effective date above always reflects the current version.
14. Contact
TRUTH Communications Media & Publications — Ontario, Canada. Email: support@digitalfootprintscanner.com