grc-scan
← Back to scanner

Privacy notice

Last updated: June 2026

grc-scan is built privacy-first: no sign-up, no account, and no email required to use it. We deliberately collect as little as possible and delete what little we do hold. This notice explains, in plain English, exactly what that means. If anything is unclear, ask us using the contact details at the bottom.

The short version

You can run our free scans without telling us who you are. For an in-depth scan you prove you own the domain (no account), pay once, get your report, and we automatically delete the scan after a few days. We don't build profiles, we don't market to you, and we never sell data.

Who we are

grc-scan is a UK-based service providing cyber-security and compliance checks for small businesses. For the data described below, we are the "data controller".

What we collect, and why

  • The domain you ask us to scan.A domain name is usually about a business, not a person. We use it only to run the scan you requested, and (for an in-depth scan) it's deleted with the rest of the scan after a few days.
  • A domain-ownership check + a private link — for an in-depth scan you prove you own the domain (a file or DNS record). We store the verification and a secret token behind your private scan link. No account, no email — the link is how you return to your report.
  • In-depth scan jobs and results — stored only so you can view and download your report, then automatically deleted after about three days.
  • Payment information— if you pay, checkout is handled by Stripe in guest mode. We don't see or store your card details and don't create a stored customer profile. Stripe keeps the transaction record because the law requires it to (tax/anti-fraud) — that part is Stripe's responsibility, not something we control.
  • Basic technical logs — like every website, our hosting providers automatically record technical data such as IP addresses to keep the service secure and running.

That's it. There's no account, no stored email, no marketing list, and no scan history kept beyond the short window above.

Our legal bases

We rely on performance of a contract (to provide the scans and reports you ask for), our legitimate interests (to keep the service secure and prevent abuse), and legal obligation where the law requires us to keep certain records.

Who we share data with

We don't sell your data. We use a small number of reputable service providers who process data on our behalf: our hosting and database providers, our payment processor (Stripe), and — for the scans themselves — public reputation services to which we send the domain or IP being scanned. Each acts under our instructions.

International transfers

Some of these providers operate outside the UK. Where that happens, the transfer is covered by an adequacy decision or an approved safeguard such as the International Data Transfer Agreement.

How long we keep it

We delete in-depth scans (the verification, the job and the results) automatically about three daysafter they complete — a daily clean-up job enforces this. Free scans aren't stored against you at all. The only longer-lived record is the payment transaction held by Stripe, which the law requires Stripe to retain.

Your rights

Under UK GDPR you can ask to access, correct, or delete your personal data, to restrict or object to certain processing, and to receive a copy of data you gave us. To exercise any of these, contact us using the details below — we'll respond within one month. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

We use only strictly-necessary cookies: a small counter that applies a fair-use limit to the free exposure check (no personal data — just a number), and, for an administrator, a sign-in cookie. We don't use advertising or third-party tracking cookies.

Contact

For any privacy question or to exercise your rights, email privacy@grc-scan.com.

We may update this notice from time to time; the date at the top shows when it last changed.