SchemaCart
Pricing Playbooks Method Run free scan
Legal

Privacy Policy

How SchemaCart collects, uses, keeps, and deletes information when you use the scanner and related services.

Last updated 3 August 2026

Contact: ben@schemacart.com

On this page
  1. Who we are and scope
  2. Information we collect
  3. How we use information
  4. Scans and reports
  5. Email, cookies, and analytics
  6. Service providers and transfers
  7. Retention
  8. Security
  9. Your rights and deletion
  10. Regional and children’s information
  11. Changes and contact

1. Who we are and what this policy covers

SchemaCart is operated by Benjamin Ong, a sole trader in Hong Kong trading as SchemaCart. This policy explains how we handle personal data when you visit this website or use a free URL scan, an email-gated report, a monitoring subscription, a one-time audit, support, or related services (together, the “Services”).

Providing an email address for a scan is voluntary, but without it we cannot prepare and deliver the full requested report. The report email is a service message requested by you. It is not permission for marketing.

2. Information we collect

Information you provide

  • the email address submitted for a scan report;
  • the public URL submitted, scan status, results, score, findings, and generated report;
  • account and monitoring settings if those features are used;
  • audit instructions, materials, feedback, and deliverables for a one-time audit; and
  • messages and attachments sent in correspondence or support requests.

SchemaCart does not currently process payments and does not ask for or store card or bank details. If paid checkout is introduced, the checkout and this policy will identify the payment provider and the information involved before a payment is accepted.

Information collected automatically

SchemaCart and Cloudflare may process IP addresses, browser and device information, user agents, referring pages, timestamps, requested paths, response status, approximate network location, and security, rate-limit, error, and performance events. Full IP addresses may be processed for delivery, security, and rate limiting. Operational logs are kept under the schedule in section 7.

Information read from authorised websites

A scan reads public resources needed for the requested checks. These can include the submitted homepage, robots.txt, llms.txt, a public sitemap or product page, structured data, and technical response information. We store the submitted URL and the resulting score, findings, and report. We do not intentionally retain raw HTML, page text, response headers, screenshots, contact lists, or copies of source pages as part of a normal scan result.

Do not submit credentials, private-page URLs, payment details, sensitive personal data, or personal data about another person.

3. How and why we use information

PurposeInformation usedBasis where EU or UK law applies
Run a requested scan and prepare its reportEmail, submitted URL, scan status, results, and delivery statusTaking steps requested by you and performing our agreement with you; otherwise our limited legitimate interest in providing the requested free service
Provide monitoring, audits, accounts, support, and billing if introducedAccount, service, audit, correspondence, and transaction informationPerforming our agreement and meeting legal duties
Secure and operate the ServicesRequest metadata, rate-limit events, security logs, errors, and service activityOur legitimate interest in preventing misuse, protecting target sites and users, and maintaining a reliable service
Improve the ServicesAggregated or de-identified scan outcomes, performance information, and cookieless analyticsOur legitimate interest in understanding and improving the Services with limited privacy impact
Comply with law and resolve disputesInformation relevant to a legal request, investigation, or claimLegal duties and legitimate interests in establishing, exercising, or defending claims

We limit these uses to what is reasonably necessary. We do not use Customer Inputs or scan results to train machine-learning models. Product improvement uses only aggregated or de-identified information unless we obtain a separate permission.

4. Scans and automated reports

You may scan only a site you own, administer, manage, or have express permission to assess. The scanner makes sequential, low-volume requests to public resources—typically about six requests per scan—and identifies itself with the user agent “Mozilla/5.0 (compatible; GEO-Checker/0.1; internal audit tool)”.

The scanner accepts HTTP or HTTPS public domain names, rejects embedded credentials and IP-address targets, checks the submitted hostname for private or non-public addresses, applies request time limits, and reports robots.txt and access-control signals. It may stop or limit a scan after access blocks, rate-limit responses, repeated errors, an operator objection, or another security or legal concern. These controls do not provide permission to scan a site.

Reports are automated, point-in-time readiness measurements. They can be incomplete or wrong and can contain false positives or false negatives. A score or finding does not promise indexing, rankings, traffic, mentions or citations by an AI system, visibility, revenue, or another technical or commercial outcome. Third-party services control their own access decisions, algorithms, and outputs.

5. Email, cookies, and analytics

We use a submitted email address to prepare or deliver the report and related operational information. SchemaCart does not currently conduct cold outreach or send promotional email. If marketing is introduced, it will use a separate choice where required, keep evidence of that choice, and provide a free unsubscribe method. A minimal opt-out record may be retained while needed to honour the request and for two years after marketing ends.

Cloudflare Web Analytics is used in its cookieless configuration for basic traffic measurement. It does not set analytics cookies or use local storage. SchemaCart does not currently use advertising pixels, cross-site behavioural advertising, session replay, or non-essential cookies. Essential storage may be introduced for account security; if so, this policy will be updated before use.

Because we do not use cross-site behavioural advertising, the site does not change its operation in response to a browser “Do Not Track” signal. Our service providers process information only to provide their services to us and are not authorised to track users for their own advertising.

6. Service providers, disclosures, and international transfers

We disclose personal data only as needed to provide and secure the Services, comply with law, protect rights, or complete a business transaction. Current service providers are:

RecipientPurpose and information
CloudflareHosting, website delivery, network security, D1 database storage, operational logs, and cookieless Web Analytics. This can involve request metadata, IP addresses, submitted emails, scan results, and reports.
ResendTransactional report email, involving the recipient email, report content or link, and delivery metadata.
Google WorkspaceBusiness and support correspondence, involving contact details, message content, and attachments.
Professional advisers and authoritiesLegal, accounting, security, compliance, dispute, and lawful government matters, limited to relevant information.

There is no payment processor or separate production monitoring, advertising, session-replay, customer-support, or authentication vendor at present. We will update this list before adding a provider that materially changes how personal data is handled.

We do not sell personal data or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months.

SchemaCart operates from Hong Kong. Providers may process information in Hong Kong and other places where they operate. Where transfer rules apply, we rely on the provider’s contractual and organisational safeguards and use additional transfer terms when required. Contact us for information relevant to your data.

7. How long we keep information

CategoryRetention
Submitted email, URL, scan results, and generated reports24 months from the scan or until a verified deletion request, whichever comes first
Account and monitoring informationWhile active, then 24 months after closure or until a verified deletion request, whichever comes first
Security, access, rate-limit, error, and abuse logs90 days, unless needed longer for an active incident, legal claim, or legal duty
Support and Google Workspace correspondence24 months after the last substantive exchange, unless needed for an active service or legal matter
Resend delivery records held by SchemaCart90 days; provider-held records follow the provider’s schedule and may be included in a deletion request where available
Audit working files and deliverables24 months after final delivery or until a verified deletion request, whichever comes first, subject to legal records
Invoices and required transaction or tax records, if paid services beginAt least seven years, or longer where law or an active legal matter requires
BackupsExpire within 90 days; deleted data restored from a backup is deleted again before ordinary use resumes

A limited legal or security hold may override these periods only while necessary. Information is then deleted or anonymised when the reason for the hold ends.

8. Security

We use safeguards appropriate to the service, including encrypted connections, provider encryption for stored service data, access limited to the operator and necessary providers, environment-based credential management, rate limits, sequential scanning, request time limits, a descriptive scanner identity, SSRF controls, backups, and provider security controls. No internet service is completely secure.

9. Your rights and deletion

Depending on your location and applicable law, you may ask for access to, correction of, a copy of, restriction of, or deletion of personal data. You may also object to certain uses, withdraw consent where processing relies on consent, and complain to a relevant privacy regulator.

To make a request, email ben@schemacart.com. Benjamin Ong handles privacy requests. We may verify your identity and authority before acting. Existing deletion tooling can remove the submitted email, stored scan inputs, scan results, and generated reports. A request does not automatically remove short-lived security logs, provider delivery records, correspondence, backups awaiting expiry, or records that must be kept for legal reasons; we will identify any exception in our response.

For Hong Kong access or correction requests, use the same contact. Providing data is voluntary, and we use and disclose it only for the purposes and recipient classes stated here. We will not use personal data for direct marketing without the notices and consent required by Hong Kong law. You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.

10. Regional information and children

SchemaCart is a small Hong Kong sole-trader operation and, based on its current scale and practices, does not treat itself as meeting the business thresholds of the California Consumer Privacy Act. We do not sell personal data or share it for cross-context behavioural advertising. If that law applies to a request despite this assessment, we will honour the rights it requires.

The Services are intended for website owners, operators, merchants, and professionals, not children. You must be at least 18, or the age of legal majority where you live if higher, to use the Services. We do not knowingly collect data from children and do not use age-assurance or parental-consent processing. Contact us if you believe a child supplied data so we can investigate and delete it where appropriate.

11. Changes and contact

We may update this policy when the Services, providers, or legal requirements change. We will post the revised policy with a new date. For a material change affecting an account or active subscription, we will also give reasonable notice through the Service or by email and obtain consent where required.

Questions, requests, and complaints may be sent to Benjamin Ong / SchemaCart at ben@schemacart.com. We will try to resolve a concern directly. You may also contact the privacy authority where you live.

SchemaCart
PricingPlaybooksMethodTermsPrivacy
© 2026 SchemaCart. Baseline, fix, re-measure, evidence.