ScaFix
Privacyverklaring van ScaFix
Bijgewerkt op 30 augustus 2026
This Privacy Policy explains what information ScaFix may process when you use the app or visit scafix.app and the choices available to you.
Webapp, account, projectopslag en betalingen
Account, Pro-toegang en webprojecten
Wanneer u ingelogd de webapp gebruikt, verwerken Firebase Authentication en Cloud Firestore uw account-ID, inloggegevens, projectinhoud, maten, instellingen, webvoorraad en toegangsstatus. Uw account, betaalde toegang en ingelogde projecten met maten en instellingen worden tussen web en iOS gesynchroniseerd wanneer u hetzelfde ScaFix-account gebruikt. De webvoorraad wordt niet naar iOS gesynchroniseerd. Google verwerkt deze gegevens namens ScaFix.
Webanalyse en marketing
Google Analytics wordt pas geladen nadat u toestemming geeft voor Analyse. Het meet paginaweergaven en ScaFix-acties, zoals het starten van de demo, registratie, afrekenen en klikken naar de App Store. Voor ingelogde gebruikers kan het de ondoorzichtige Firebase-gebruikers-ID ontvangen, maar geen naam of e-mailadres. Meta Pixel wordt pas geladen na toestemming voor Marketing en meet paginaweergaven en dezelfde acties, samen met browser- en apparaatgegevens, IP-adres, pagina-URL en Meta-cookies of identificatoren. De webapp laadt geen TikTok- of Snap-pixels of advertentie-SDK's. Na marketingtoestemming worden de eerste geldige UTM-waarden en de klik-ID's fbclid, ttclid, gclid, gbraid of wbraid tijdelijk in de sessieopslag van het tabblad bewaard onder scafix.firstPartyAttribution.v1; andere parameters worden genegeerd. Bij een webaankoop worden campagnewaarden uitsluitend opgeslagen als metadata van de Stripe Checkout Session en niet gekopieerd naar het terugkerende abonnement. Intrekken van toestemming stopt nieuwe metingen; cookies van derden kunnen blijven bestaan totdat ze worden verwijderd of verlopen. Projectinhoud, maten, afbeeldingen en betaalkaartgegevens worden via deze koppeling niet naar Google Analytics of Meta verstuurd.
Meting van afgeronde aankopen
Als Marketing was toegestaan bij het starten van Stripe Checkout, kan ScaFix na een door de server bevestigde aankoop een Purchase-gebeurtenis naar Meta sturen met aankoopwaarde, valuta, een stabiele Stripe-ID, een met SHA-256 gehasht e-mailadres en eventuele Meta-ID's _fbp/_fbc. Het e-mailadres wordt niet als leesbare tekst verstuurd en de gebeurtenis wordt niet zonder deze toestemming verstuurd.
Als Analyse was toegestaan bij het starten van Stripe Checkout, kan ScaFix na een door de server bevestigde aankoop een Purchase-gebeurtenis naar Google Analytics 4 sturen met aankoopwaarde exclusief belasting, valuta, de Checkout Session-ID als transactie-ID, de ondoorzichtige Firebase-gebruikers-ID en de client- en sessiecookies van Google Analytics. Advertentiegebruik en advertentiepersonalisatie blijven geweigerd. Zonder deze toestemming wordt de gebeurtenis niet verstuurd.
Voor een ingelogde gebruiker bewaart ScaFix de huidige keuzes voor Analyse en Marketing, een willekeurige revisie en het wijzigingstijdstip in Firebase. Bij het starten van Checkout kunnen de revisie en alleen de toegestane identificatoren voor aankoopmeting — Google Analytics-client-/sessiecookies en/of Meta _fbp/_fbc — naar de metadata van de Stripe Checkout Session worden gekopieerd. Deze metadata kan op een verlaten sessie blijven staan. Ze wordt alleen gebruikt om de actuele toestemming bij ontvangst van de webhook te controleren en een bevestigde aankoop te meten; ze wordt niet naar het terugkerende abonnement gekopieerd. Elke wijziging van een keuze vernieuwt de revisie, zodat een oudere sessie geen nieuwe gebeurtenis kan toestaan. Deze meetmetadata bevat geen project- of betaalkaartgegevens.
De metadata van Stripe Checkout vermeldt ook welke optionele categorieën bij het starten van Checkout waren toegestaan.
Betalingen en toegang
Stripe verwerkt webabonnementen en ontvangt de factuur- en betaalgegevens die nodig zijn om de aankoop af te ronden en te beheren. ScaFix bewaart geen volledige betaalkaartnummers. Apple blijft App Store-aankopen verwerken. ScaFix verwerkt aanbieder-, klant-, abonnement- en transactie-ID's en de abonnementsstatus om beide aankooptypen aan hetzelfde ingelogde ScaFix-account te koppelen.
Uw keuzes
U kunt webprojecten en uw ScaFix-account verwijderen. Beheer actieve abonnementen bij de betaalprovider. Accountverwijdering start ook de opzegging van webabonnementen via Stripe; App Store-abonnementen moeten afzonderlijk bij Apple worden opgezegd. Accountverwijdering geeft niet automatisch recht op een terugbetaling. Aankoop- en abonnementshistorie kan zonder accountkoppeling worden bewaard wanneer dit nodig is voor boekhouding, veiligheid en wettelijke administratie. Mail naar support@scafix.app voor inzage in of verwijdering van andere servergegevens.
Betalen vóór accountaanmaak
U kunt een webabonnement starten en betalen voordat u een ScaFix-account maakt of inlogt. Voor het activeren bewaart ScaFix een noodzakelijke, willekeurige activatiesleutel in een HttpOnly-cookie en een serverrecord met Stripe-referenties, het gekozen abonnementsniveau, een afgeschermd e-mailadres en een SHA-256-hash van het e-mailadres. Het record bevat ook een hash van het netwerkadres om misbruik te voorkomen en, met uw toestemming, relevante campagne- en meetgegevens. ScaFix bewaart geen volledige betaalkaartgegevens.
In productie kunt u de aankoop binnen 30 dagen activeren. Een betaalde aankoop die niet binnen die termijn wordt geactiveerd, wordt automatisch geannuleerd en terugbetaald.
Microsoft Clarity: heatmaps en sessieopnamen
Analyse omvat ook Microsoft Clarity: klikken, scrollen en sessieopnamen op openbare pagina's, met afgeschermde inhoud.
Clarity wordt pas geladen nadat u opnieuw toestemming voor Analyse hebt gegeven met deze informatie. Formulierinhoud wordt afgeschermd; account-, project-, editor-, upload- en betaalterugkeerpagina's worden niet opgenomen. We versturen geen Firebase-gebruikers-ID's. Clarity verwerkt gebruiks- en apparaatgegevens en kan pseudonieme sessiecookies plaatsen. Advertentietoestemming voor Clarity blijft geweigerd. U kunt uw toestemming intrekken in de privacyinstellingen. De opnamen zijn geen schermvideo's van uw privétekeningen.
Vercel-analyse en prestaties
Met uw toestemming voor Analyse gebruikt ScaFix ook Vercel Web Analytics en Speed Insights. Ze verwerken anonieme, geaggregeerde paginaweergaven en technische prestatiemetingen, zoals pagina of route, verwijzer, land bij benadering, browser, apparaat, besturingssysteem, netwerktype en Core Web Vitals. Deze diensten gebruiken geen cookies en koppelen gegevens niet aan uw Firebase-gebruiker. Ze bieden geen sessieopnamen of sessieherhalingen (session replay). Web Analytics leidt een anonieme hash af van het binnenkomende verzoek en kan daarmee paginaweergaven in een kortdurende sessie groeperen en geaggregeerde statistieken zoals het bouncepercentage berekenen. De hash en sessiekoppeling worden binnen 24 uur gereset of verwijderd en worden niet gebruikt om bezoekers over dagen, websites of apps te volgen. Concrete project-ID's, projectinhoud, maten, bestandsnamen, afbeeldingen en betaalgegevens worden niet verstuurd. De verzameling stopt zodra u de toestemming voor Analyse intrekt.
Aanvullende voorwaarden voor iPhone en diensten (Engelse brontekst)
Data controller
Ole Emil Frikstad Urstad (ScaFix). Contact: support@scafix.app.
Owner-only operational notifications and App Store events
Only the verified ScaFix owner account can choose to enable private push notifications about new account registrations, trials, purchases and trial conversions. Regular users are not registered for these notifications and are not shown this notification-permission request.
When the owner enables notifications, ScaFix and Firebase Cloud Messaging process a Firebase Installation ID (FID), its association with the device’s Apple Push Notification service (APNs) token, and related registration data to route and deliver the notifications. Turning the feature off removes the device from ScaFix’s recipient list and unregisters it from FCM.
For a purchase made from a Firebase-authenticated app session, ScaFix may issue a stable, randomly generated appAccountToken, link it on the server to the Firebase user ID (UID), and pass the token to StoreKit. This lets ScaFix associate relevant purchase and subscription events with the account. The token is not a payment credential and contains no payment information.
ScaFix receives and verifies signed App Store Server Notifications v2 from Apple and processes relevant purchase and subscription event data, such as notification and event type, transaction and original-transaction identifiers, product identifier, environment, signed date and appAccountToken. This processing is used to detect events including a new subscription, a free trial and its paid conversion, prevent duplicate handling, and create an owner alert where applicable. Apple handles the payment.
The push-notification text states only the type of operational event. It does not contain the customer’s name, email address, Firebase UID, appAccountToken, transaction identifiers, payment or card details, receipt contents, project content, measurements or images. These operational-notification data are not used for advertising.
What we collect
1) Account and sign-in
If you choose to sign in, ScaFix uses Firebase Authentication for Apple, Google and email sign-in. This may include a user ID, email, display name and sign-in method. For Google sign-in, Google Sign-In may also process an account identifier, name, email and technical sign-in data.
2) Usage analytics
Usage analytics is on by default. Firebase Analytics receives app opens, session and lifecycle data, number of projects, scaffold systems used, and other feature usage.
Firebase Analytics may also receive purchase and subscription events, such as product ID and status, but never payment-card information.
When both optional usage analytics and ad measurement are enabled, Firebase Analytics purchase and subscription events may be linked to or imported into Google Ads for attribution, conversion measurement and ad optimization. Payment-card data, Firebase Authentication/Firestore account data and project content are not transferred to Google Ads.
Usage analytics can be turned off at any time in Settings → Privacy. This does not affect app functionality.
Advertising measurement and tracking
ScaFix processes information to provide the app and uses Firebase for usage analytics that can be turned off in Settings. On first use, Apple’s ATT prompt is the only advertising-measurement choice. Meta and TikTok start direct tracking only when you choose Allow. AppsFlyer can use Apple’s privacy-preserving measurement without IDFA/IDFV only if you later enable advertising measurement in Settings. Snapchat is measured only through AppsFlyer; the app has no direct Snap SDK.
When advertising measurement remains enabled in ScaFix and ATT permission is granted, Meta Platforms Ireland Limited, TikTok Technology Limited and AppsFlyer Ltd. may receive install, app-open, session or retention data, technical app and device information, an approximate IP-based location, installation ID/IDFV and IDFA.
When ad measurement is active, one purchase event may be sent to AppsFlyer for each eligible, verified, paid production charge — initial purchase or renewal — with product ID, actual price, currency, quantity and StoreKit transaction/order ID. Payment-card data, receipt contents and bank details are never shared. AppsFlyer may forward configured postbacks to Meta, TikTok and Snap. Meta and TikTok receive no purchase events directly from the app, and the app has no direct Snap SDK.
If ATT is denied or restricted, direct tracking and IDFA/IDFV are off. AppsFlyer’s privacy-preserving SKAdNetwork/AdAttributionKit can be used only if you later enable advertising measurement in Settings; no device-level data is then shared with advertising partners.
TikTok Enhanced Data Postback and automatic purchase tracking are disabled. We never send project content, measurements, scans, images, names, email addresses or phone numbers to the advertising partners. Apple may send privacy-preserving SKAdNetwork/AdAttributionKit postback copies to AppsFlyer. These Apple postbacks do not contain IDFA or contact information.
5) Meta ad measurement and tracking
Meta SDK tracking applies only to an App Store version of ScaFix that includes the SDK. No Meta SDK tracking occurs before such a version has been published and installed. When a version containing the SDK is used, tracking starts and continues only while you grant permission through Apple’s App Tracking Transparency (ATT) prompt and advertising measurement remains enabled in ScaFix under Settings → Privacy.
- Meta may receive information about installs and app activations, device and app identifiers (including IDFA where available), IP address, and technical app and device data.
- Meta may also receive SDK-generated session and lifecycle data, including activation and deactivation, session duration, time between sessions, and interruptions when the app moves between foreground and background.
- Meta may use the information for attribution, reporting and ad improvement, and link it with data from other apps, websites or services.
- Automatic logging of other app events is disabled. Meta’s activation measurement nevertheless records the activation and deactivation events and session data described above. Projects, measurements, images, names and email addresses are not sent to Meta through this integration.
ScaFix works without this permission. You can change your choice later in iOS Settings for ScaFix.
What data is not used for
- No third-party ads are shown in the app
- No sale of project or usage data
Projects, PDF import, camera and account logo
Drafts you create while signed out are stored only locally in that browser or on the device. When you are signed in, projects, wall measurements, project settings and your account logo are stored and synchronized through Firebase Cloud Firestore and Cloud Storage so the content is available on the web and iPhone. The imported source PDF itself is processed in memory and is not uploaded; derived project geometry that you save in the project may be synchronized like other project data. Camera, photo and LiDAR access is used only when you start a feature that requires it. An uploaded account logo is stored in the cloud until you replace it or delete the account.
Sharing and processors
Firebase (Google Ireland Limited), including Cloud Firestore and Cloud Storage, processes account data, synchronized projects, wall measurements, project settings and account logos, as well as server-verified subscription and transaction data, operational notifications, optional usage analytics, and technical security/SDK data on our behalf. Apple processes purchases, App Store Server Notifications, APNs delivery and App Attest certifications.
For security, Firebase App Check uses Apple App Attest. Firebase processes cryptographic attestation and assertion objects, short-lived App Check tokens, and basic app and technical information to verify that requests come from an authentic ScaFix installation and protect Firebase and ScaFix backend services against abuse. On signed-in backend requests, the App Check token is sent with the Firebase authentication token. ScaFix does not store App Check tokens or attestation material in its own application database, and these data are not used for advertising.
AppsFlyer Ltd. may process privacy-preserving Apple measurement data when advertising measurement is enabled and device data when both advertising measurement remains enabled in ScaFix and ATT is allowed. Meta Platforms Ireland Limited and TikTok Technology Limited process direct advertising-measurement data only under the same two conditions. Snap Inc. may receive campaign postbacks through AppsFlyer; the app contains no Snap SDK.
Firebase usage analytics, project content and ScaFix account data are not shared with Meta, TikTok, AppsFlyer or Snap.
Apple, Google and the advertising-measurement providers may process data outside the EEA under valid transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs) where applicable.
Your choices and deletion
You can change analytics consent under Settings → Privacy. Advertising measurement can be turned off in ScaFix under Settings → Privacy; in an app version that includes the Meta SDK, Meta tracking can also be declined in Apple’s prompt and changed later in iOS Settings for ScaFix. You can delete your sign-in account directly in the app under Settings → Account → Delete Account. Local app data, synchronized cloud projects, project settings and account-logo/branding data are then deleted. Contact support@scafix.app to request access to or deletion of any other server records associated with you.
Changes
For material changes, we will update the date at the top of this page.
