Skip to content
scavo
Features Pricing
Tools Test SEO, AI visibility and reliability Blog Research, fixes and product updates Guides Evidence-led help for every check Service status Live uptime and incident history
About Contact Login Start free trial
scavo
Features Pricing About Contact
Resources
Tools Blog Guides Service status
Login
Start free trial 7 days free, cancel anytime Run free scan

Founder support from Alex

Legal

Privacy Policy

How Scavo collects, uses, and protects your data.

Last updated: July 19, 2026
Skip to policy: Cookies · Your Privacy Choices · Retention · Scanner identity
We hold ourselves accountable — publicly

Most privacy policies are static documents nobody checks. Ours is backed by the same monitoring engine that powers every Scavo dashboard — our scanner periodically runs privacy and legal checks on this site, compares them to what the policy promises, and publishes the results below. If something drifts, visitors see the mismatch directly.

Monitored · auto-updated
Operational privacy snapshot

This panel shows current privacy-related product defaults and the latest linked privacy/legal self-check where available. It supplements the formal policy below; it does not replace it.

A 100/100 privacy & legal checks only 7 passed Based on privacy/legal checks from the latest linked self-check only. Excludes performance, SEO, uptime, and other non-privacy checks.
July 19, 2026 Formal document Legal policy date
Consent-gated Analytics mode Optional analytics stays off until consent
8 items First-party storage 6 cookies + 2 local storage keys
11h ago Last checked
scavo.ai Observed domain
Linked self-check + runtime defaults Evidence source
Linked self-check active scavo.ai
What the policy says vs what the site last did What the formal policy says, next to the latest linked technical observation. Verified by scheduled scan — not hand-written
Signal What we say What the scanner found
Consent choices Optional analytics should stay off until visitors can clearly accept, reject, or reopen cookie choices. Observed consent interface baseline passed. For this scan context, a consent surface plus reject/manage controls were detected.
Privacy disclosures The policy should clearly explain tracking, cookie categories, and how people can manage those choices later. Policy disclosures detected. Privacy and cookie disclosure surfaces were detected for the scanned scope.
California / GPC rights Where California sale or sharing rights apply, people should have a clear opt-out path and GPC handling should be explained. California opt-out signals detected. California rights links, privacy-signal disclosure text, and live GPC runtime controls were detected.
Policy ↔ runtime alignment Privacy wording and live site behavior should not drift apart on key consent and disclosure controls. Disclosure and runtime signals are broadly aligned. No major disclosure/runtime contradictions were detected in this scan scope.
Current data-handling defaults These are runtime defaults in the product today, separate from the legal wording below.
Optional analytics stays off until consent Interaction analytics is gated behind the cookie choice and does not start by default.
Cookie controls stay reachable after first visit Visitors can reopen cookie settings using the persistent footer control.
Analytics stores only coarse technical dimensions We keep high-level path, country, device, browser, and event outcome data rather than page content.
Sensitive payloads are blocked from analytics Tool inputs, page HTML, passwords, tokens, and cookie values are excluded from analytics metadata.
Baseline retention windows Operational data stays for different lengths depending on what it is needed for.
365 days Scan history Score history and scan-level summaries
180 days Raw analytics Event-level product analytics retention
90 days Email and webhook logs Operational delivery evidence
7 days Demo results Short-lived demo scan storage
What analytics collects vs blocks
Stores

Page path · Coarse country · Device type · Browser family · Consent state · Journey or tool outcome

Never collected

Full form field values · Passwords, tokens, and cookie values · Page HTML or page content · Raw tool inputs and fetched payloads · Full referrers or unbounded URLs

Machine-readable scanner identity How Scavo identifies itself when a user asks us to scan a site.
User-Agent ScavoBot/1.0 (+https://scavo.ai/legal/privacy#automated-scanning-identity; mailto:[email protected])
From header [email protected]
Scanner info URL https://scavo.ai/legal/privacy
Signature-Agent https://scavo.ai/.well-known/http-message-signatures-directory#scavobot-v1
Key directory https://scavo.ai/.well-known/http-message-signatures-directory
Key id TRvc62U4tBmDHfhzl1-3VuPXmbz6gAZJ-mT7zNPysgM

Formal privacy policy text starts immediately below this snapshot.

Formal policy document. The live transparency snapshot above is an operational companion, not a replacement for the legal wording below.

1. Information We Collect

When you use Scavo, we collect the following information:

  • Account Information: Name, email address, and password when you create an account
  • Website Data: URLs you submit for scanning, final/resolved URLs, response headers, page metadata, technical signals, visible-page evidence, and scan screenshots or thumbnails captured during scans
  • Payment Information: Processed securely through Stripe (we don't store your card details)
  • Contact Requests: Name, email, company, website, and message details you submit via our contact form
  • Demo and Free Tool Data: Domains, URLs, robots.txt inputs, validation outcomes, and contact details you choose to submit through public demo or tool flows
  • Business Outreach Research: Public business names, website URLs, corporate status, public source URLs, relevant business contact names or addresses, review notes, one-off scan results, delivery status, opt-out status, and limited engagement events
  • Usage Data: How you interact with the service, including page views, journey steps, CTA clicks, and tool interaction events (when optional analytics is enabled)
  • Technical Data: IP address, browser type, coarse device/browser family, consent state, and cookies

2. How We Use Your Information

We use your information to:

  • Provide and improve our website scanning and monitoring services
  • Send you scan reports and alerts about your website's health
  • Process your payments and manage your subscription
  • Communicate with you about service updates and support
  • Respond to contact inquiries, plan questions, and technical support requests
  • Prevent fraud and ensure the security of our service
  • Analyze usage patterns to improve our product
  • Generate automated technical and compliance signals about scanned websites
  • Generate prioritized fix guidance based on observed scan evidence
  • Prepare and send a manually reviewed, relevant one-off website report to an eligible corporate business contact

3. Legal Bases for Processing

Depending on the context, we process personal data under one or more of these legal bases:

  • Contract: to create accounts, run scans, provide dashboards, process subscriptions, and deliver monitoring reports
  • Legitimate interests: to secure the Service, prevent abuse, improve product reliability, maintain operational logs, understand aggregate product usage, and conduct carefully targeted corporate business outreach where our interests do not override your rights
  • Consent: for optional public-page analytics, optional browser storage, and any consent-based communication or tracking flow
  • Legal obligation: where we need to retain or disclose information for tax, accounting, regulatory, security, or lawful request reasons

4. Business Outreach and One-Off Website Reviews

Scavo may research an individual corporate business, run a one-off scan of its public website, and send a relevant report to a business contact. This workflow is reviewed by a person before sending. It is not used for broad, indiscriminate mailing or autonomous AI sending.

For cold business outreach, our internal send gate is limited to contacts we have verified as connected with a limited company, limited liability partnership, or public body. Sole traders, unincorporated partnerships, and unknown business types cannot pass that gate without another appropriate communication basis.

  • Sources: public company websites, contact pages, company registers, professional directories, and other public business information
  • Review: we record the source, business type, why the contact is relevant, the lawful basis, and the wording used
  • Report: the linked page contains evidence from one public website scan and clearly separates that snapshot from uptime or recurring monitoring that has not taken place
  • Engagement: token links can record the destination opened, whether the user agent resembles an automated email-security scanner, and whether the report remained visibly open for about ten seconds. We do not use an email open pixel or store a raw visitor IP in the outreach event
  • Choice: every outreach email identifies Scavo, provides a direct reply route, and includes a one-step opt-out. Opted-out addresses are added to a suppression list so we do not contact them again through this workflow

You can object at any time using the link in the email or by contacting [email protected]. You can also ask where we found the business contact details, request correction or deletion, or exercise the rights described below.

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your information with:

  • Service Providers: Stripe for payment processing, Postmark for app-generated email delivery (permission-based and transactional), a separate suitable outreach delivery provider if that workflow is enabled, Cloudflare for DNS, security, caching, and edge services where used, hosting/database/cache providers, and other processors that help us operate support, logging, reliability, and security workflows
  • Legal Requirements: When required by law or to protect our rights and safety
  • Business Transfers: In the event of a merger, acquisition, or sale of assets

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (HTTPS/SSL)
  • Secure password hashing
  • Regular security audits and updates
  • Access controls and authentication measures

However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

7. Your Rights and Privacy Choices

If you are in the UK, European Economic Area, or another jurisdiction with similar privacy rights, you may have the right to:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to our processing of your data
  • Right to Withdraw Consent: Withdraw consent at any time
  • Rights Relating to Automated Decision-Making: Ask us to review any concern about automation that affects you

We do not sell personal data, and optional analytics on our public pages stays off unless you explicitly accept it. If your browser sends a privacy preference signal such as Global Privacy Control (GPC), our public pages still begin in that no-optional-analytics state; strictly necessary storage remains unaffected.

If you are in California and want to exercise an access, deletion, or opt-out style request, or want us to review a specific privacy concern, contact us at [email protected] and we will handle the request through the appropriate process.

If you are unhappy with how we handle a privacy request, please contact us first so we can investigate. You can also raise a complaint with the UK Information Commissioner's Office (ICO) or your local data protection authority.

For the live public-page control path, see Your Privacy Choices below.

Your Privacy Choices

  • Optional cookies stay off unless you allow them: public-page analytics and other optional storage stay disabled until you choose Accept optional.
  • You can change your choice any time: use the persistent Cookie Settings control in the footer to reject, withdraw, or review optional-cookie choices.
  • We honor Global Privacy Control on public pages: when a supported browser sends GPC, we treat that as a request to keep optional cookies and optional analytics off.
  • We do not sell or share personal data for cross-context behavioral advertising on our public pages. If that ever changes for a specific flow, we will add a clearer opt-out path and explain it here.

8. Cookies, Local Storage, and Tracking

We use essential cookies and related browser storage for core site operation. Optional storage and access technologies, including analytics cookies, local storage, tracking pixels, scripts, or tags, are only used after you choose Accept optional in the cookie banner.

You can change or withdraw optional-cookie consent at any time using the Cookie Settings link in our footer. If you reject optional cookies, we clear optional first-party cookies and optional local-storage keys that power analytics, preference memory, and prompt suppression.

Our optional analytics is privacy-limited: we track page visits, coarse country (via edge headers), coarse device/browser family, and aggregate tool usage outcomes. We do not record keystrokes, form field values, page content, or full tool-input payloads.

A token-scoped outreach report can send the limited engagement events described in Business Outreach and One-Off Website Reviews. That report signal does not set an analytics cookie, write browser storage, use an open pixel, or supply data to third-party advertising.

For example, tool telemetry can include a tool slug, action type, and success/failure outcome, but not the submitted domain content or fetched robots.txt body.

Essential

Needed for security, routing, and core platform behavior.

  • scavo_session (Scavo) : Maintains secure authenticated session state and CSRF/session continuity. Duration: Up to session timeout or browser close.
  • scavo_remember (Scavo) : Keeps you signed in on a trusted device when you explicitly choose remember me. Duration: 7 days.
  • scavo_cookie_consent (Scavo) : Stores your cookie preference (accept/reject) and consent version timestamp. Duration: 180 days (configurable).

Preferences

Stores choices such as currency display for faster repeat visits.

  • scavo_currency (Scavo) : Remembers your preferred currency across pages and sessions. Duration: 1 year.

Engagement

Helps us avoid repeating prompts and improve high-intent journeys.

  • scavo_exit_shown (Scavo) : Prevents repeatedly showing the same exit-intent prompt. Duration: 7 days.

Analytics

Measures useful interactions so we can improve product decisions.

  • scavo_analytics_id (Scavo) : Anonymous visit/session identifier for pageview, funnel, and country/device analytics. Duration: 30-minute rolling inactivity window.

When optional features are enabled, we may also write local-storage keys in your browser: scavo_currency , scavo_analytics_sid .

This list covers first-party cookies set directly by Scavo. We link to external social pages such as LinkedIn, Facebook, Instagram, and X, but we do not load social-network widgets by default. If you open an external service, that service controls its own cookies and browser storage.

9. Data Retention

We use retention windows that vary by data type and operational need. Current baseline windows include:

  • Scan history and detail: up to 365 and 365 days
  • Scan screenshots: typically up to 45 days, unless removed earlier by retention cleanup or account/site deletion
  • Analytics: raw events up to 180 days and session rollups up to 120 days
  • Email/webhook operational logs: typically up to 90 / 90 days
  • Demo scan results: up to 7 days
  • One-off outreach reports: up to 30 days
  • Outreach prospect research and events: removed after 180 days without activity; a minimal suppression record may be retained for as long as needed to honour an opt-out
  • Contact inquiries, demo leads, and support messages: stored in our support/admin systems for follow-up and abuse prevention, then removed when no longer needed
  • Post-cancellation account records: up to 90 days where needed for service operations

When you delete your account, we remove account-linked monitoring, scan, analytics, settings, and website data from our primary application systems. Some transaction or provider-side records may still be retained by payment processors, email processors, or where required by law.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction when our processors, infrastructure, support, payment, or email providers operate internationally. Where required, we rely on appropriate safeguards such as adequacy decisions, the UK International Data Transfer Agreement/Addendum, Standard Contractual Clauses, or processor-specific transfer terms.

11. Automated Decision-Making and AI-Assisted Outputs

Scavo uses automated checks and scoring to produce technical findings, priorities, and suggested next steps. These outputs are advisory product signals. We do not use solely automated processing to make legal or similarly significant decisions about individuals.

If a scan result or account automation appears wrong, contact us and we can review the underlying evidence.

12. Children's Privacy

Scavo is not intended for users under 18 years of age. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or through our service. Continued use after changes constitutes acceptance.

14. Automated Compliance Signals

Scavo provides automated technical compliance signals across selected frameworks, does not cover every legal obligation or jurisdiction, and does not provide legal advice. Compliance-related outputs are automated technical indicators based on observed website behavior, not a comprehensive legal audit.

Our checks cover a broad set of practical requirements and common frameworks, but they do not cover every obligation in every jurisdiction. You should validate high-impact decisions with qualified legal counsel.

15. Automated Scanning Identity

Scavo performs technical scans for URLs submitted by users and individually researched one-off outreach prospects. We do not run broad internet crawling.

For transparency, scanner requests identify as:

  • User-Agent: ScavoBot/1.0 (+https://scavo.ai/legal/privacy#automated-scanning-identity; mailto:[email protected])
  • From header: [email protected]
  • Scanner info: https://scavo.ai/legal/privacy
  • Web Bot Auth Signature-Agent: https://scavo.ai/.well-known/http-message-signatures-directory#scavobot-v1
  • Web Bot Auth key directory: https://scavo.ai/.well-known/http-message-signatures-directory
  • Web Bot Auth key id: TRvc62U4tBmDHfhzl1-3VuPXmbz6gAZJ-mT7zNPysgM

If you want us to stop scanning your site, contact [email protected] with your domain and request details.

16. Contact Us

If you have questions about this privacy policy or wish to exercise your rights, contact us:

  • Email: [email protected]
  • Contact page: https://scavo.ai/contact

Start monitoring your site today.

One service covers uptime monitoring, security, SEO, performance, and AI visibility.

Run free scan Start free trial
scavo

A dependable weekly view of your website, with urgent problems raised sooner.

Ask Alex a question

Product

  • Features
  • Pricing
  • Free scan
  • Free tools

Resources

  • Blog
  • Help guides
  • Changelog
  • Service status
  • Latest updates RSS

Company

  • About
  • Contact
  • Privacy
  • Terms

© 2026 Scavo

Scavo service status Cookie settings

Your cookie choices

Essential cookies keep Scavo secure. Optional cookies remember your currency and show us which pages are useful.

Current choice: Decision needed

Essential

Needed for security, routing, and core platform behavior.

  • scavo_session Scavo

    Maintains secure authenticated session state and CSRF/session continuity.

    Duration: Up to session timeout or browser close.

  • scavo_remember Scavo

    Keeps you signed in on a trusted device when you explicitly choose remember me.

    Duration: 7 days.

  • scavo_cookie_consent Scavo

    Stores your cookie preference (accept/reject) and consent version timestamp.

    Duration: 180 days (configurable).

Preferences

Stores choices such as currency display for faster repeat visits.

  • scavo_currency Scavo

    Remembers your preferred currency across pages and sessions.

    Duration: 1 year.

Engagement

Helps us avoid repeating prompts and improve high-intent journeys.

  • scavo_exit_shown Scavo

    Prevents repeatedly showing the same exit-intent prompt.

    Duration: 7 days.

Analytics

Measures useful interactions so we can improve product decisions.

  • scavo_analytics_id Scavo

    Anonymous visit/session identifier for pageview, funnel, and country/device analytics.

    Duration: 30-minute rolling inactivity window.

Optional browser storage

These local-storage keys support optional features only after you allow them.

  • scavo_currency Scavo

    Browser-side storage for optional preference memory or privacy-limited analytics state.

    Duration: Until cleared, changed, or the feature no longer needs it.

  • scavo_analytics_sid Scavo

    Browser-side storage for optional preference memory or privacy-limited analytics state.

    Duration: Until cleared, changed, or the feature no longer needs it.

This panel covers first-party cookies and optional browser storage used directly by Scavo. We do not load social-network widgets by default; if you open an external link, that service controls its own cookies and browser storage. See Privacy Policy.