Privacy policy
Effective 2026-08-09
This policy explains what Sextant collects when you use this site, why, and what rights you have over it. It applies to sextantscan.com and the scan reports it produces.
Who we are
Sextant is a trading name of Adcock Stanton Limited, a company registered in England and Wales, company number 14869761. Registered office: 72 Stoneyfields Lane, Edgware, Middlesex, HA8 9SW. We are registered with the UK Information Commissioner's Office, registration number ZB644996.
For the purposes of UK GDPR, Adcock Stanton Limited is the data controller for the personal data described below. Contact us at hello@sextantscan.com for anything in this policy, including exercising your rights.
What we collect, and why
Store URLs and scan reports. When you submit a URL to be scanned, we store that URL and the resulting report, which includes the pages we fetched and the structured data we found on them. This is processed under legitimate interest: it is the service you asked for, and there is no way to run a scan without recording what it found.
A salted hash of your IP address, for rate limiting. We do not store your IP address. We compute a cryptographic hash of it, combined with a private salt, and store only that hash together with a date and a count. This lets us enforce a daily limit on anonymous scans without keeping a record of individual addresses. This is processed under legitimate interest: preventing abuse of a free, unauthenticated service.
Email address and message, if you contact us. If you submit the fix enquiry form, we store the email address, the store URL if you gave one, and your message, so we can reply and, if you go ahead, deliver the work. This is processed under legitimate interest and, once you engage us, to take steps towards a contract.
Booking and setup details, if you buy Done for you. Paying for the flat price implementation collects your email and the store URL through Stripe's checkout, which is how we deliver the work you paid for. After payment, a setup form (linked from the confirmation email and reachable at any time from a private link scoped to your order) asks for your name, business name, role, phone number if you give one, and how you would prefer to be contacted; your store's platform, approximate size, and whether it is a standard or a custom/headless build; and how you intend to grant us access, for example a Shopify collaborator request code, a WordPress admin URL, or a repository URL. We do not ask for, and this form does not accept, a password, an API key, or any other credential; access is always requested directly on the platform's own terms. This is processed to perform the contract you entered into by paying for the work, and we keep it for as long as we might need to refer back to how access was granted, or until you ask us to delete it.
Email address, if you ask for a report by email. On a report page you can ask us to email you the report link, and optionally to rescan the store 30 days later and email you what changed. If you do, we store your email address, which scan it relates to, the store's domain, and whether you asked for the rescan. This is processed on the basis of your consent: the emails exist because you asked for them, on the page they are about, and we send nothing else to that address. Every one of these emails carries a one-click unsubscribe link. Unsubscribing takes effect immediately, cancels any scheduled rescan email, and needs no login and no confirmation step. We check the unsubscribe state before every send.
Your email address, if you sign in. You can create an account to subscribe and to keep a history of your scans. An account is identified by your email address, and that is the whole of it: there is no password to choose, and we do not ask for your name, your address or your phone number. We sign you in by emailing you a single-use link rather than asking you to invent another password. Each link is stored as a hash alongside the email address it was sent to, expires shortly after we issue it, and is marked spent the moment it is used, so a link found in an old inbox later is worth nothing. This is processed to provide the account you asked for and, once you subscribe, to perform the contract between us.
Subscription records, if you subscribe. Payment is handled by Stripe and we never see or store your card details. What we store against your account is the customer and subscription identifiers Stripe gives us, which plan you are on, whether it is active, when the current period ends and whether it has been cancelled. That is the minimum needed to know what your account is entitled to and to answer a question about your own billing. We also record which Stripe notifications we have already processed, so that one delivered twice cannot be counted twice.
Which domains you monitor, if you subscribe to Monitor or Fix. We keep the list of domains attached to your account: your own store, and any competitor domain you choose to track alongside it, each marked as one or the other. Monitoring a competitor's domain runs the same public scan as any other; it does not access anything private on it. This is processed to provide the monitoring you subscribed to.
Your store's product catalogue, if you subscribe to Fix. Name, price, availability, images and description for every product, fetched from your store's platform so the files below can be generated from real data rather than a sample. This is processed to provide the service you subscribed to.
The files we generate for AI agents, if you subscribe to Fix. Fix writes four files meant to be read by AI shopping agents directly from your own domain: llms.txt, llms-full.txt, agents.md and a UCP manifest. They carry your product catalogue from above, and business details you give us for this purpose specifically: your store name, a short business description, a contact email, your legal entity name if you have one, and a summary of your returns and shipping terms. All of it - including the contact email and the legal entity name - is written into the files themselves. This is processed to provide the service you subscribed to, on the understanding that these are exactly the details you want an AI agent reading your store to see.
Once generated, the files are served at a public URL: not password protected, not linked from anywhere on sextantscan.com and not indexed by search engines, but reachable by anyone who has the link, because the whole point is that an AI agent can fetch them directly rather than asking you first. If your subscription lapses, they stop being served immediately - the URL answers not found from that point, exactly as it did before you subscribed - and the underlying data is deleted 30 days after cancellation with the rest of your scan history.
A record of every email we send you. Who it went to, which template it was, and whether it sent successfully, for every report, account notice and order update. This is processed under legitimate interest, to know what we have already told you and to diagnose a delivery problem if you say something did not arrive.
Contact details we find published on a business's own site, before we have written to them. Separately from everything above, we sometimes build a list of stores to introduce Sextant to by email: the domain, a contact email address published on that business's own site and nowhere else, and what we can determine about the jurisdiction and legal form of the business behind it - a registered company number, where we can find one, because the basis that lets us write to a corporate subscriber this way does not extend to a sole trader, who the law treats as an individual. No address on this list is written to until a person has confirmed the jurisdiction and the corporate status and recorded, in three separate parts, why writing to this specific business is justified. Every message would carry a one-click unsubscribe, honoured immediately and permanently. This is processed under legitimate interest: a single, narrow, one-time introduction to a business account, about work we already have evidence for on their own public store, not an ongoing relationship.
A permanent record of addresses that must not be contacted again. If an address unsubscribes from outreach, bounces permanently or complains, we keep it - and every other address at the same domain - on a list we check before any outreach send. This one has no expiry by design: the reason it exists is to make sure nobody at that company is written to again, and a record that expired would defeat that.
We do not ask for or knowingly collect any other personal data. We do not require an account, a name, or payment details to run a scan.
What a scan actually does
A scan fetches only pages that are already public on the store you submit: its homepage, robots.txt, sitemap, a handful of product pages, and a small number of policy pages, using a normal unauthenticated request that identifies itself as SextantBot. It does not log in, does not use cookies to access anything, and does not touch any page that requires authentication.
A Fix subscriber's scan goes further. Alongside the same checks, we fetch the whole product catalogue from the store's platform rather than a sample, using the store's own products API or, when that is not available, a sitemap walk. For a headless store this can mean calling a separate backend host the merchant has told us to use instead of the storefront domain; before we call it, we check that it does not resolve to a private or internal address, the same as with any other host we are told to fetch from. This is still a normal, unauthenticated, read-only request, and it is what the discovery files described below are built from.
Report pages are public by design and shareable by their link: anyone who has the URL of a report can view it, in the same way anyone who has the URL of a public document can view it. We do not search-index individual reports, but we do not restrict access to them by login either. If you would rather a report of your store were not shared further, contact us and we will remove it.
What we do not do
We do not run advertising trackers of any kind. We do not sell, rent or otherwise share your data with third parties for their own marketing. We use no third party analytics and no tracking cookies, and we embed no third party content: there is no analytics script, tag manager, advertising pixel, social widget or embedded video on any page of this site. The only third party network requests this site makes are to fetch the store you ask us to scan (which is the point of the service) and, at build time on our own servers, to load our own typeface; neither involves your browser sending anything to a third party on your behalf.
Cookies and storage
Browsing this site sets nothing on your device. No cookies, no local storage, no session storage, no other client side storage of any kind. That is true of every public page, including the homepage, the pricing pages and any report you open by its link.
Signing in sets exactly one cookie, named sextant_session. It is set when
you follow a sign-in link from your email, and cleared when you sign out. It
does one job: keeping you signed in, so that every page does not forget who
you are. Under the Privacy and Electronic Communications Regulations that
makes it a strictly necessary cookie for a service you explicitly asked for,
which is why this site shows no cookie banner. There is nothing here for you
to consent to, because we set nothing that consent would apply to.
That cookie contains an opaque random secret and nothing else. It is not an identifier: it carries no account number, no email address and no profile data of any kind, and nothing can be inferred from its value. No script can read it, on this site or any other, because it is set HttpOnly. We do not store the secret itself either - our database holds only a hash of it, so what sits in your browser cannot be reconstructed from anything we hold. It is restricted to this site, sent only over an encrypted connection, and expires 30 days after it is issued.
Paying for anything sends you to Stripe's own checkout, on Stripe's domain. Any cookie Stripe sets there is set by Stripe, on their site, under their privacy policy, and not by us on ours.
Where your data lives
The database is hosted by Neon in their EU (Frankfurt) region. The site itself is hosted by Vercel. Email is sent through Resend, which holds the address a message went to and the message itself for 30 days before deleting them. All three are data processors acting on our instructions; none has an independent right to use your data.
How long we keep it
A free scan you ran without an account is anonymised 90 days after it completes: the score and grade stay, everything that names your store or quotes its pages is removed. Two things can keep a scan out of that for longer: a report you asked to be emailed to you, and one linked from a Done for you booking, in both cases because you have an ongoing reason to refer back to the original. The Done for you one holds for as long as the order record itself does, 6 years (see below).
The emailed one holds only for as long as that record does, and no longer: it is a separate record with its own clock, and it is anonymised 90 days after the last thing that happened on it - the date of the rescan reminder if you opted into one, or the date you asked for the report if you did not. We measure it on the free scan's own window rather than a longer one, because the only reason the scan is being kept past that window at all is this record, and there is no reason to hold it open for longer than the scan it is protecting.
A report currently embedded as a badge on your own site is different: it stays excluded only while the badge is actually being loaded. A badge resolves by this report's id forever, so the URL alone cannot say whether it is a live embed or one nobody has looked at since - what we track instead is recency of use. Every time a badge loads we record that, and the scan behind it stays out of anonymisation only while it has been loaded within the last 30 days: long enough that a quiet spell on a low-traffic store does not cost you the badge, short enough that a single click, crawl or link preview loading the URL once no longer excludes a report forever, which is what used to happen. We cannot tell a genuine embed from an automated visitor that revisits on a schedule of its own; recency of access is the only signal this gives us.
A Monitor or Fix subscriber's scan history, along with the catalogue and the files we generate, is kept for as long as the subscription is active and for 30 days after it ends, then deleted; the record that a domain was once monitored is not part of that and is not deleted, since a domain name on its own names a business, not you. Access details from a Done for you booking (collaborator codes, admin URLs, repository links) are deleted 30 days after we hand the work back; the order record itself is kept for 6 years as a financial and compliance record, as is our record of every transactional email - a report delivery, an enquiry confirmation - for the same reason.
Our record of an outreach email is not. Unsolicited mail to someone who never became a customer is not a financial record, and there is no reason to hold the address for that long: after 2 years the address and subject are removed and what remains is the fact that a message of that kind was sent on that date, which is what we need to be able to account for having sent it. A rehearsal that was never actually sent keeps no address at all - only the domain, discarded after 14 days along with the contact record it was rehearsed against.
A business contact we have found is deleted 14 days after we found it, whether or not it has been reviewed or written to by then. A contact nobody has acted on in two weeks is not a live prospect; if we still want to reach that business later, we look it up again rather than holding a stale row. An address that has opted out of outreach is different and is never time-limited - it stays on our suppression list indefinitely, and that stays true even if the business is looked up again after its contact record is gone, because that is the entire purpose of keeping it.
An enquiry you send us through a contact or quote form is anonymised 12 months after you send it: your address and your message are removed, and what remains is that an enquiry was received on that date about that store. We keep that much because it is the only honest picture we have of what people ask us for, and none of it needs your name on it. If the enquiry turned into paid work, the order record is the one that matters and is kept for 6 years as described above - the enquiry is not kept longer just because it led somewhere.
A message you send us through the contact form is not stored in our database at all. It is emailed to us and it reaches our inbox and our email provider, and nowhere else - Resend holds the message and your address for 30 days as described above, and we hold no copy of either in a table. What we do keep is the automatic acknowledgement we sent you, as the record that your message arrived and was answered; your address is removed from that 12 months after we send it, leaving only the fact that a message was acknowledged on that date.
Anything else is kept until you ask us to delete it. To ask for deletion at any time, email hello@sextantscan.com with the report link or the email address you used.
If we have emailed you in the last 30 days, deleting our own record is not the whole job: our email provider holds its own copy for that period. We ask them to delete it too, rather than leaving you to.
Your rights
Under UK GDPR you have the right to:
- know what personal data we hold about you and why
- have inaccurate data corrected
- ask us to delete your data
- ask us to restrict or object to our processing of it
- receive a copy of it in a portable format
To exercise any of these, email hello@sextantscan.com. We will respond within one month.
If you want to complain about how we have handled your data, rather than ask us to do something with it, use the complaint form. It acknowledges itself immediately, so you have a record that it arrived, and it needs no account.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113. We would appreciate the chance to put things right first, but you do not need our permission to complain.
Changes to this policy
If this policy changes materially, we will update the date below and, where the change affects how we handle data you have already given us, tell you directly.
Effective date: 2 August 2026.