Last updated 31 August 2026.
| Thing | What happens |
|---|---|
| Browsing the site | No cookie, no account, no tracker. Page views are counted anonymously. |
| Your first site scan | No account needed. We store the address you scanned and the result. |
| Making an account | We receive your name, email address and avatar from Google or GitHub. Nothing else, and no password. |
| QR codes and image codes | Never uploaded. The link, the picture and any logo are read and drawn entirely inside your browser. |
| Selling your data | Never. Not to anyone, for any price. |
| Advertising | We run none, and we place no advertising or cross-site tracking cookies. |
Cash Callin is a digital studio that builds websites, e-commerce storefronts, AI integrations and small games. We are the controller of the personal data described here. You can reach us any time at hello@cashcallin.net.
Signing in with Google or GitHub gives us three things: your name, your email address and the URL of your avatar, plus the account identifier that provider uses for you. We ask for no other permission and we cannot read your contacts, files, repositories or anything else.
We never receive your password. That is the whole point of signing in this way — there is no password of yours for us to store, and none for us to lose.
We use it to keep you signed in, to attach your scan history to you, and to email you about your own account or a scan you asked for. Not for a newsletter you did not ask for.
We store the address you scanned and the result, so you can look back at it and see whether a site improved. If you asked us to email you the result, we store the email address you gave.
The scan itself is performed by Google PageSpeed Insights on the address you enter, plus our own fetch of that page to see what an AI assistant could read from it. If the address is not yours, be aware that you are asking a third party to fetch it.
The partner registration, the scan-result email and the Pulse waitlist each send us what you typed into them — usually a name and an email address. We use it to reply and, for partners, to pay you.
Our host, Cloudflare, keeps standard server logs including IP addresses, for security and abuse prevention. We use those logs to enforce the free-scan limit — the count is stored against a one-way hash of your IP address and the date, and it expires after about a day.
Page views are measured with Cloudflare Web Analytics, which sets no cookie and does not build a profile or follow you to other sites.
The QR studio and the image-code builder run entirely in your browser, on your own device. That means:
This is not a policy promise we ask you to take on trust; it is how the tool is built. You can watch it in your browser's network panel: making a code produces no requests at all.
| Cookie | What it is for | How long |
|---|---|---|
cc_sess | Keeps you signed in. Strictly necessary; set only after you choose to sign in. It is HttpOnly, so no script on the page can read it. | 30 days, or until you sign out |
That is the entire list. There are no analytics, advertising or preference cookies, which is why you are not being asked to dismiss a banner.
Two things are kept in your browser's local storage rather than a cookie: how many free scans you have used, and nothing else. Clearing your browser data clears it.
| Who | What they see | Why |
|---|---|---|
| Google / GitHub | That you signed in to Cash Callin | Only if you choose to sign in with them |
| Google PageSpeed Insights | The address you asked us to scan | It measures the page |
| Cloudflare | IP address, standard request logs | Hosting, security, anonymous page counts |
| Our form handler | What you typed into a form | So the message reaches us |
We do not sell, rent or share personal data with anyone else, and we do not use it to train anything.
For anyone in the UK or EU, under the UK GDPR and the EU GDPR:
| What | How long |
|---|---|
| Account | Until you delete it. Ask and it is gone. |
| Scan history | With your account; deleted with it |
| Free-scan counter | About 24 hours, then it expires by itself |
| Form messages | As long as we are talking, and up to two years after |
| Partner payment records | As long as tax law requires |
| Server logs | Cloudflare's own retention, currently a matter of days |
Wherever you are, you can ask us to show you what we hold, correct it, delete it, export it, or stop using it. In the UK and EU those are rights under the GDPR; in California under the CCPA; in Australia under the Privacy Act. We apply them to everybody rather than sorting people by passport.
Email hello@cashcallin.net. We will answer within 30 days, usually far sooner, and we will not ask you why.
If you are in the EU or UK and you think we have got it wrong, you may complain to your national data protection authority. We would rather you told us first.
The site and its data run on Cloudflare's network, which is worldwide. Where data leaves the UK or EEA, the transfer relies on the UK Addendum and the EU Standard Contractual Clauses in Cloudflare's terms.
This is a service for businesses. It is not directed at children, and we do not knowingly collect anything from anyone under 16. If you believe a child has made an account, tell us and we will delete it.
Sessions are held in a cookie your browser will only send back to us, over HTTPS, and which no script on the page can read. Sign-in runs through Google's or GitHub's own authorisation flow with PKCE, so an intercepted code is useless on its own. We hold no passwords and no payment card numbers.
When this changes, the date at the top changes. If a change is significant — a new kind of data, a new third party — we will say so on the site rather than edit quietly and hope nobody notices.
hello@cashcallin.net. A person answers.