1. Who we are and what this policy covers
SchemaCart is operated by Benjamin Ong, a sole trader in Hong Kong trading as SchemaCart. This policy explains how we handle personal data when you visit this website or use a free URL scan, an email-gated report, a monitoring subscription, a one-time audit, support, or related services (together, the “Services”).
Providing an email address for a scan is voluntary, but without it we cannot prepare and deliver the full requested report. The report email is a service message requested by you. It is not permission for marketing.
2. Information we collect
Information you provide
- the email address submitted for a scan report;
- the public URL submitted, scan status, results, score, findings, and generated report;
- account and monitoring settings if those features are used;
- audit instructions, materials, feedback, and deliverables for a one-time audit; and
- messages and attachments sent in correspondence or support requests.
SchemaCart does not currently process payments and does not ask for or store card or bank details. If paid checkout is introduced, the checkout and this policy will identify the payment provider and the information involved before a payment is accepted.
Information collected automatically
SchemaCart and Cloudflare may process IP addresses, browser and device information, user agents, referring pages, timestamps, requested paths, response status, approximate network location, and security, rate-limit, error, and performance events. Full IP addresses may be processed for delivery, security, and rate limiting. Operational logs are kept under the schedule in section 7.
Information read from authorised websites
A scan reads public resources needed for the requested checks. These can include the submitted homepage, robots.txt, llms.txt, a public sitemap or product page, structured data, and technical response information. We store the submitted URL and the resulting score, findings, and report. We do not intentionally retain raw HTML, page text, response headers, screenshots, contact lists, or copies of source pages as part of a normal scan result.
Do not submit credentials, private-page URLs, payment details, sensitive personal data, or personal data about another person.
3. How and why we use information
| Purpose | Information used | Basis where EU or UK law applies |
|---|---|---|
| Run a requested scan and prepare its report | Email, submitted URL, scan status, results, and delivery status | Taking steps requested by you and performing our agreement with you; otherwise our limited legitimate interest in providing the requested free service |
| Provide monitoring, audits, accounts, support, and billing if introduced | Account, service, audit, correspondence, and transaction information | Performing our agreement and meeting legal duties |
| Secure and operate the Services | Request metadata, rate-limit events, security logs, errors, and service activity | Our legitimate interest in preventing misuse, protecting target sites and users, and maintaining a reliable service |
| Improve the Services | Aggregated or de-identified scan outcomes, performance information, and cookieless analytics | Our legitimate interest in understanding and improving the Services with limited privacy impact |
| Comply with law and resolve disputes | Information relevant to a legal request, investigation, or claim | Legal duties and legitimate interests in establishing, exercising, or defending claims |
We limit these uses to what is reasonably necessary. We do not use Customer Inputs or scan results to train machine-learning models. Product improvement uses only aggregated or de-identified information unless we obtain a separate permission.
4. Scans and automated reports
You may scan only a site you own, administer, manage, or have express permission to assess. The scanner makes sequential, low-volume requests to public resources—typically about six requests per scan—and identifies itself with the user agent “Mozilla/5.0 (compatible; GEO-Checker/0.1; internal audit tool)”.
The scanner accepts HTTP or HTTPS public domain names, rejects embedded credentials and IP-address targets, checks the submitted hostname for private or non-public addresses, applies request time limits, and reports robots.txt and access-control signals. It may stop or limit a scan after access blocks, rate-limit responses, repeated errors, an operator objection, or another security or legal concern. These controls do not provide permission to scan a site.
Reports are automated, point-in-time readiness measurements. They can be incomplete or wrong and can contain false positives or false negatives. A score or finding does not promise indexing, rankings, traffic, mentions or citations by an AI system, visibility, revenue, or another technical or commercial outcome. Third-party services control their own access decisions, algorithms, and outputs.
5. Email, cookies, and analytics
We use a submitted email address to prepare or deliver the report and related operational information. SchemaCart does not currently conduct cold outreach or send promotional email. If marketing is introduced, it will use a separate choice where required, keep evidence of that choice, and provide a free unsubscribe method. A minimal opt-out record may be retained while needed to honour the request and for two years after marketing ends.
Cloudflare Web Analytics is used in its cookieless configuration for basic traffic measurement. It does not set analytics cookies or use local storage. SchemaCart does not currently use advertising pixels, cross-site behavioural advertising, session replay, or non-essential cookies. Essential storage may be introduced for account security; if so, this policy will be updated before use.
Because we do not use cross-site behavioural advertising, the site does not change its operation in response to a browser “Do Not Track” signal. Our service providers process information only to provide their services to us and are not authorised to track users for their own advertising.
7. How long we keep information
| Category | Retention |
|---|---|
| Submitted email, URL, scan results, and generated reports | 24 months from the scan or until a verified deletion request, whichever comes first |
| Account and monitoring information | While active, then 24 months after closure or until a verified deletion request, whichever comes first |
| Security, access, rate-limit, error, and abuse logs | 90 days, unless needed longer for an active incident, legal claim, or legal duty |
| Support and Google Workspace correspondence | 24 months after the last substantive exchange, unless needed for an active service or legal matter |
| Resend delivery records held by SchemaCart | 90 days; provider-held records follow the provider’s schedule and may be included in a deletion request where available |
| Audit working files and deliverables | 24 months after final delivery or until a verified deletion request, whichever comes first, subject to legal records |
| Invoices and required transaction or tax records, if paid services begin | At least seven years, or longer where law or an active legal matter requires |
| Backups | Expire within 90 days; deleted data restored from a backup is deleted again before ordinary use resumes |
A limited legal or security hold may override these periods only while necessary. Information is then deleted or anonymised when the reason for the hold ends.
8. Security
We use safeguards appropriate to the service, including encrypted connections, provider encryption for stored service data, access limited to the operator and necessary providers, environment-based credential management, rate limits, sequential scanning, request time limits, a descriptive scanner identity, SSRF controls, backups, and provider security controls. No internet service is completely secure.
9. Your rights and deletion
Depending on your location and applicable law, you may ask for access to, correction of, a copy of, restriction of, or deletion of personal data. You may also object to certain uses, withdraw consent where processing relies on consent, and complain to a relevant privacy regulator.
To make a request, email ben@schemacart.com. Benjamin Ong handles privacy requests. We may verify your identity and authority before acting. Existing deletion tooling can remove the submitted email, stored scan inputs, scan results, and generated reports. A request does not automatically remove short-lived security logs, provider delivery records, correspondence, backups awaiting expiry, or records that must be kept for legal reasons; we will identify any exception in our response.
For Hong Kong access or correction requests, use the same contact. Providing data is voluntary, and we use and disclose it only for the purposes and recipient classes stated here. We will not use personal data for direct marketing without the notices and consent required by Hong Kong law. You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
10. Regional information and children
SchemaCart is a small Hong Kong sole-trader operation and, based on its current scale and practices, does not treat itself as meeting the business thresholds of the California Consumer Privacy Act. We do not sell personal data or share it for cross-context behavioural advertising. If that law applies to a request despite this assessment, we will honour the rights it requires.
The Services are intended for website owners, operators, merchants, and professionals, not children. You must be at least 18, or the age of legal majority where you live if higher, to use the Services. We do not knowingly collect data from children and do not use age-assurance or parental-consent processing. Contact us if you believe a child supplied data so we can investigate and delete it where appropriate.
11. Changes and contact
We may update this policy when the Services, providers, or legal requirements change. We will post the revised policy with a new date. For a material change affecting an account or active subscription, we will also give reasonable notice through the Service or by email and obtain consent where required.
Questions, requests, and complaints may be sent to Benjamin Ong / SchemaCart at ben@schemacart.com. We will try to resolve a concern directly. You may also contact the privacy authority where you live.