Privacy Policy

Version 4 · Last updated July 23, 2026


Effective date: May 3, 2026

This version (v2) consolidates the previously standalone Cookies Policy into the Privacy Policy. Section 13 below incorporates the substance of the prior Cookies Policy; references to the standalone Cookies Policy should be read as references to that section of this Policy.

This Privacy Policy explains how KERNO, Inc., doing business as Scan Simple ("Scan Simple", "we", "us", "our"), collects, uses, shares, and protects information when you use the Scan Simple platform at scansimple.app, the mobile-scanner web app, the desktop print agent, and the Enterprise API (collectively, the "Service").

This Policy is incorporated into our Terms of Use. By using the Service you agree to the practices described here.

1. Information we collect

1.1 Information you provide

  • Account information: name, email, password (stored hashed), phone, store/company name, role (admin or operator).
  • Billing information: billing contact name and email, billing company, billing address, the last four digits and brand of your payment card, and the Stripe customer ID. Full card numbers and CVCs are entered directly into Stripe's hosted forms; Scan Simple never sees or stores them.
  • Subscription details: selected plan, tier, workstation count, mobile add-on status, coupons applied, effective and renewal dates.
  • Operational data: SKUs, scan history, printed labels, label-layout templates, printer configuration, team-member invitations, and feature suggestions.
  • Support and feedback: the contents of emails, contact-form messages, cancellation feedback, and roadmap comments you submit.
  • Policy acceptance records: the date, time, IP address, user agent, full name, and electronic signature (drawn or typed) you provide when accepting these documents, plus a snapshot of the document version you agreed to. We retain this for the life of your account and for as long as required by law afterward.

1.2 Information collected automatically

  • Device and usage data: IP address, browser type, operating system, referring/exit pages, pages visited, click events, and timestamps.
  • Workstation identifier: a per-browser cookie ("ss_workstation") that identifies the device for workstation-licensing purposes.
  • Cookies and similar technologies: see Section 13 below for the full description of the cookies we use, why we use them, and how to control them.
  • Error and performance data: via Sentry, including stack traces, request URL, and request id, scrubbed of credentials before transmission.

1.3 Information from third parties

We receive payment-related events (charges, renewals, refunds, disputes) from Stripe via webhooks, email-delivery events (deliveries, bounces, complaints) from Postmark, and limited identity data when you accept a team invitation that was addressed to your email.

2. How we use information

  • To create and operate your account and authenticate your workstations.
  • To process payments, send invoices and receipts, manage renewals, and handle pauses, cancellations, and refunds.
  • To deliver, maintain, secure, and improve the Service, including diagnostic logs, performance monitoring, and rate- limit enforcement.
  • To communicate with you about your account, security events, billing, support requests, scheduled maintenance, and changes to these documents. You may not opt out of essential service emails while you have an active account.
  • To send product updates, tips, and marketing where you have consented; you may unsubscribe from marketing email at any time.
  • To detect, investigate, and prevent fraud, abuse, and violations of our Terms.
  • To comply with legal obligations, respond to lawful requests, and enforce our agreements.
  • To compute aggregated, de-identified analytics about Service usage; aggregated data does not identify you.

3. Pricing and billing data

Pricing tiers, the active price ID for each plan, and your subscription status are held in our database. Card details themselves live with Stripe; we store only the customer/subscription identifiers and a tokenized last-four-and-brand summary for display in the billing UI. We use this information to render invoices, attempt failed-payment retries, send card-expiry reminders, and notify you about price changes.

4. How we share information

We do not sell or rent personal information. We share information only as described below:

  • Service providers / processors: Stripe (payments), Postmark (transactional email), Sentry (error monitoring), our cloud-hosting and content-delivery providers, and other vendors that operate under written confidentiality and data-protection obligations and only process data on our behalf.
  • Within your team: data you submit is visible to other authorized members of your company account, subject to the role you assign them.
  • Legal and safety: when required to comply with law, lawful requests, or to protect rights, property, or safety.
  • Business transfers: as part of a merger, acquisition, financing, or sale of all or part of our business, in which case we will require the recipient to honor this Policy or notify you of any material changes.
  • With your consent: for any purpose disclosed at the time of collection.

5. Data retention

We retain account and operational data for as long as your account is active. After cancellation we keep data for at least thirty (30) days for restoration purposes and then delete or anonymize it, unless a longer period is required by law (e.g. tax, accounting, or fraud-prevention obligations) or to enforce our agreements. Policy-acceptance records and audit logs are retained for the life of your account plus the period required by applicable law.

6. Security

We use TLS in transit, encryption at rest for backups, hashed passwords (bcrypt), scoped API keys (with one-time plaintext display), per-key rate limiting, audit logging of sensitive admin actions, and least-privilege access controls. No system is perfectly secure. If you believe your account or an API key has been compromised, contact us immediately.

7. Your rights and choices

Depending on where you live you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to processing or withdraw consent. To exercise these rights, email support@scansimple.app from the address on your account. We may need to verify your identity before acting on a request. If you are an end user of one of our customers, please contact that customer first.

You can update most account information directly from the profile and billing tabs. You can request deletion of your account; some records (e.g., invoices, audit logs, policy acceptances) may be retained as described above.

8. International transfers

Scan Simple is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where we or our service providers operate. By using the Service you consent to that transfer.

9. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

10. California, Virginia, and other state privacy rights

Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have specific rights to know, access, delete, correct, port, and (in some states) opt out of "sale" or "sharing" of personal information and targeted advertising. We do not "sell" personal information for monetary value and we do not engage in cross-context behavioral advertising in the customer portal. To exercise a state-law right, contact us using the address below.

11. Changes to this Policy

We may update this Policy from time to time. The "Effective date" at the top reflects the latest revision. For material changes we will email the address on your account and require acceptance on next login. The current version is always available at /privacy-policy and prior versions you have accepted are available from the Policy Details block on your billing tab.

12. Supersedence

This v2 supersedes and replaces the previously standalone Cookies Policy (last updated September 5, 2022). That document is no longer maintained as a separate page; the current, authoritative version of its substance is Section 13 below.

13. Cookies and similar technologies

13.1 What cookies are

"Cookies" are small files placed on your computer, mobile device, or other device by a website, containing details of your browsing history on that website among other uses. Cookies do not typically contain information that personally identifies a user, but personal information that we store about you may be linked to information stored in and obtained from cookies. We do not store sensitive personal information (such as mailing addresses or account passwords) in the cookies we use.

13.2 Persistent vs. session cookies

Cookies can be "Persistent" or "Session" cookies. Persistent cookies remain on your device when you go offline; session cookies are deleted as soon as you close your web browser. We use both, for the purposes described below.

13.3 Categories of cookies we use

  • Necessary / Essential cookies. Type: Session. Administered by: Us.

    These cookies are essential to provide you with services available through the Service and to enable you to use some of its features. They help authenticate users and prevent fraudulent use of user accounts. Without these cookies the services you have asked for cannot be provided, and we use them only to provide those services. The session cookie used for portal authentication and the workstation identifier cookie ("ss_workstation") fall in this category.

  • Functionality cookies. Type: Persistent. Administered by: Us.

    These cookies allow us to remember choices you make when you use the Service, such as remembering your login details or language preference, so you do not have to re-enter your preferences every time you visit.

  • Tracking and performance cookies. Type: Persistent. Administered by: Third parties.

    These cookies are used to track information about traffic to the Service and how users use it. The information gathered via these cookies may directly or indirectly identify you as an individual visitor, because the information collected is typically linked to a pseudonymous identifier associated with the device you use. We may also use these cookies to test new pages, features, or functionality to see how users react.

  • Targeting and advertising cookies. Type: Persistent. Administered by: Third parties.

    These cookies track your browsing habits to enable us to show advertising more likely to be of interest to you. They use information about your browsing history to group you with other users with similar interests; based on that information, and with our permission, third-party advertisers may place cookies that show adverts we think will be relevant to you on third-party websites. We do not run third-party advertising trackers in the customer portal itself.

13.4 Your choices regarding cookies

If you prefer to avoid the use of cookies on the Service, first disable the use of cookies in your browser and then delete the cookies saved in your browser associated with this site. You may use this option to prevent the use of cookies at any time.

If you do not accept our cookies, you may experience some inconvenience using the Service and some features may not function properly.

To delete cookies or instruct your web browser to delete or refuse cookies, see the help pages for your browser. Examples:

For any other browser, please consult your browser's official documentation.

14. Contact

KERNO, Inc. d/b/a Scan Simple
158 Front Royal Pike, Suite 300A
Winchester, VA 22602
Email: support@scansimple.app
Phone: +1 (540) 328-0424