1. Introduction
Scatterlink Corp. ("Scatterlink", "we", "us", "our") provides cloud‑based inventory‑management software and companion mobile applications distributed through the Apple App Store and Google Play.
This Privacy Policy explains what data we collect, why we collect it, how we use it, and the choices you have. It applies to:
- Scatterlink and any site that links to this notice;
- the Scatterlink Mobile App for Android and iOS; and
- any related sales, support or marketing activities.
If you do not agree with our practices, please do not use our Services. Questions can be sent to info@scatterlink.com or to the postal address in Section 16.
2. Summary of Key Points
- Personal data collected: contact details, login credentials, precise or coarse device location, camera images (e.g., barcode/RFID pics), time‑stamps, device identifiers, and company inventory records created or viewed through the app.
- Sensitive data: we do not intentionally collect special‑category data (race, health, etc.).
- Purpose & legal basis: operate the Services, secure user accounts, provide location‑aware functionality, comply with law, and develop new features. Processing is based on contract necessity, legitimate interests, consent (for optional features), and legal obligations.
- Sharing: only with trusted service providers (cloud hosting, authentication, crash‑analytics), your employer (if they are our customer), and as required by law. We never sell personal data.
- International transfers: data may be stored in Canada or the United States; we use recognised safeguards such as Standard Contractual Clauses for EEA/UK data.
- Your rights: depending on where you live (e.g., Canada, EEA/UK, California) you may access, correct, delete, or port your data and object to certain processing.
- Security: industry‑standard organisational and technical safeguards, but no system is 100 % secure.
For full details, please read the entire policy.
3. Information We Collect
We collect data directly, automatically, and from third‑party integrations (e.g., Azure AD, SAP, Zebra SDK).
| Category |
Examples |
Source |
| Account & Contact Data |
name, work e-mail, phone, role |
You / employer |
| Authentication Data |
hashed password, OAuth or SSO tokens, user ID |
You / SSO provider |
| Device & Usage Data |
IP address, OS version, app version, crash logs, mobile carrier |
Automated |
| Location Data |
GPS coordinates (foreground), network location (background, if enabled) |
Device sensors (permission-based) |
| Camera |
To scan RFID / Barcodes or capture photos / videos that you choose to attach to an inventory record within the app. |
Device camera (permission-based) |
| Operational Data |
Inventory IDs, quantities, asset history, annotations |
You / employer |
| Log Data & Time-Stamps |
server logs, transaction time, last-seen |
Automated |
Mobile permissions – The first time a feature requires Location, Camera, Files or Bluetooth, the OS will prompt you. You may decline or later withdraw permission in your device settings. Some functions (e.g., location‑based asset search) will not work without the relevant permission.
4. How We Use Your Information
| Purpose |
Typical Activity |
Legal Basis* |
| Service delivery |
authenticate you, sync inventory to your phone, show asset location on a map |
Contract |
| Safety & Security |
detect fraud, audit user actions, secure accounts |
Legitimate interest |
| Product Improvement |
error analytics, usage statistics, new‑feature telemetry |
Legitimate interest / consent (where required) |
| Communications |
transactional e‑mails, app notifications, training materials |
Contract / legitimate interest |
| Compliance |
respond to lawful requests, tax & accounting |
Legal obligation |
| Marketing (optional) |
newsletters, event invites |
Consent (opt‑in) |
*Definitions follow PIPEDA (Canada), GDPR (EEA/UK), and applicable US state privacy statutes.
5. Sharing and Disclosure
We only share personal information under these circumstances:
- Service Providers. Cloud hosting (AWS Canada/US), authentication, analytics, customer‑support platforms. Contracts require them to: act only on our instructions, protect the data, and delete it when no longer needed.
- Customer Organisation. If your access is provided by an employer or other business client, authorised administrators can view activity logs and inventory records you create.
- Legal/Regulatory. Courts, law‑enforcement, or regulators when we must comply with the law.
- Business Transfers. Mergers, acquisitions, or asset sales (with appropriate confidentiality safeguards).
We do not sell or rent personal information.
6. International Transfers
Primary servers are in Canada Central. Backup and redundancy services operate in the United States. Where data originates from the EEA, UK or Switzerland we rely on:
- European Commission or UK ICO Standard Contractual Clauses; and
- Technical measures such as encryption in transit and at rest.
7. Cookies & Tracking Technologies
The web dashboard uses cookies and local storage for session management and analytics. You may block non‑essential cookies via the banner or browser settings. For analytics we use Google Analytics with IP anonymisation. Opt‑out tools are available at Google Analytics Opt-out Browser Add-on Download Page.
8. Data Retention
- Account data – kept while your organisation has an active subscription plus 12 months.
- Inventory records – retained at the discretion of the customer administrator or as required by law.
- Logs & backups – rotated every 90 days and archived for up to 2 years for security and audit. After retention ends we delete or anonymise data.
9. Security Measures
- Encryption in transit (TLS 1.2+) and at rest (AES‑256).
- Device‑level storage uses the operating systemʼs protected app sandbox; sensitive files are encrypted.
- Role‑based access control; MFA available.
- Annual penetration tests and SOC 2 Type II controls.
Despite these precautions, no system can guarantee absolute security.
10. Your Rights and Choices
Depending on your jurisdiction you may have the right to:
- Access and obtain a copy of your data;
- Correct inaccurate data;
- Erase data or restrict processing;
- Port data to another provider;
- Object to certain processing (including direct marketing);
- Lodge a complaint with a supervisory authority.
To exercise any right, e‑mail info@scatterlink.com . We will respond within one month (30 days for Canada/PIPEDA) or sooner where required.
11. California & US State‑Specific Disclosures
Scatterlink is a "service provider" under the California Consumer Privacy Act (CCPA/CPRA). We:
- do not sell or share personal information for cross‑context behavioural advertising;
- honour Global Privacy Control (GPC) signals;
- disclose the categories of personal information collected, sources, purposes, and third‑party disclosures in Sections 3–5.
Similar rights apply under Colorado, Connecticut, Utah and Virginia laws.
12. Do‑Not‑Track Signals
Our Services do not currently respond to browser "Do‑Not‑Track" settings.
13. Childrenʼs Privacy
The Services are not directed to children under 16 and we do not knowingly collect data from them. If you believe a child has provided us personal information, please contact us and we will delete it promptly.
14. Bring‑Your‑Own‑Device (BYOD) Notice
Because inventory data resides on your personally‑owned handset:
- Your employer may adopt mobile device‑management (MDM) or remote‑wipe policies.
- You are responsible for keeping your deviceʼs OS up to date, using a strong passcode, and not sharing your unlock credentials.
- Scatterlink provides client‑side encryption and sandboxing but is not liable for data loss resulting from a compromised device.
15. Changes to This Policy
We may update this notice from time to time. The "Last updated" date at the top changes whenever we publish a material revision. If changes materially affect your rights, we will give 30 daysʼ advance in‑app or e‑mail notice and, where required, ask for renewed consent.
16. Contact Us
Email: info@scatterlink.com