Privacy notice

Privacy

This service collects very little, because it is built not to need much. There is no upload channel of any kind, and nothing you write is used to train a model.

Effective date 2026-09-10

Who is responsible

The company named on the legal information page is the data controller for personal data handled through scotchbon.shop. You can reach us at support@scotchbon.shop.

This notice is written under the UK General Data Protection Regulation and the Data Protection Act 2018.

What we never receive

This service accepts no uploads. There is no audio upload and no image upload, anywhere, on any plan, and no code path that would accept one.

That is a deliberate design decision rather than a missing feature: the decisive information is where the record has turned to when the noise happens, and a recording carries no such reference — while an upload would send everything else in your room along with it.

What we collect

  • Account data — your email address, a hashed password, and a display name if you give one.
  • What you describe — the text you type about when a noise happens, and the resulting reading.
  • Subscription data — which plan you are on, the dates of your charges, and the two cancellation-right acknowledgements you gave at checkout.
  • Technical data — IP address, browser and device type, and server logs, kept to keep the service running and safe.

Card details are entered on the systems of an external payment provider and never reach our servers. We can see that a payment succeeded and the last four digits of the card; we cannot see the full number.

Why we handle it, and on what basis

  • To provide the service you asked for — performance of our contract with you.
  • To take payment and keep billing records — performance of contract, and a legal obligation for tax records.
  • To keep the service working and prevent abuse — our legitimate interests in running a service that is not abused.
  • To answer you when you write to us — performance of contract, or our legitimate interest in dealing with enquiries.
  • To send the renewal reminders and confirmations described in the terms — a legal obligation and performance of contract. These are never marketing emails.

We do not sell personal data, and we do not share it for advertising.

Model training

What you write is not used to train any model, ours or anyone else’s. It is used to answer you, and for nothing else.

We may look at aggregate, non-identifying figures — how often a timing pattern is matched, error rates, how long a page takes to load — to improve the service. Those figures contain nothing that identifies you or reproduces what you wrote.

How long we keep it

  • Account data — until you delete your account, then removed within 30 days.
  • What you described and the resulting reading — 30 days, unless you are on a plan that keeps your readings and you have chosen to save them. You can delete any of them at any time.
  • Billing records — 7 years, because tax law requires it.
  • Server logs — 90 days.

Your rights

Under UK GDPR you have the right to ask for a copy of your data, to have it corrected, to have it deleted, to have it sent to you in a portable form, to restrict or object to how we use it, and to withdraw consent where we relied on it.

Write to support@scotchbon.shop and we will respond within one month.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk or by telephone on their helpline. You do not have to raise it with us first, though we would like the chance to put it right.

If you are in California, you also have the rights the CCPA gives you, including the right to know what is collected, to have it deleted, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined there, and we honour Global Privacy Control signals.

Sending data outside the UK

Some of the services we rely on to host and run this site operate outside the United Kingdom. Where personal data is transferred out of the UK, we rely on either the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

Keeping it safe

The site is served over HTTPS throughout. Passwords are stored hashed, never in readable form. Access to production data is limited to the people who need it to run the service. If a breach ever put your rights at risk, we would tell the ICO within 72 hours and tell you without undue delay.

Children

This service is not intended for children under 13. Someone aged 13 to 17 may use the free plan with a guardian’s agreement but may not subscribe.

Cookies

Only the cookies the service needs in order to work are set without asking. Everything else waits for your choice. See the cookie notice.

Changes to this notice

If we change this notice in a way that materially affects you, we will tell registered users by email at least 14 days beforehand.