1. Scope
This policy covers the SubmitAgent website, eligibility scanner, private API, campaign application, and evidence records. Third-party directories have their own privacy practices.
2. Data we process
- Public website URLs and public product facts submitted for scanning.
- Project facts you confirm, campaign policy, and destination eligibility decisions.
- Attempt states, timestamps, route observations, and redacted evidence you choose to synchronize.
- Account, entitlement, support, and security-event data needed to operate the service.
3. Credentials and local sessions
Directory passwords, authenticated Chrome sessions, project inbox contents, payment instruments, and identity documents are not intended to be stored by the SubmitAgent backend. They remain in the customer-controlled browser and email environment.
4. Scan privacy
The scanner should fetch only public pages needed for the requested assessment. Private result URLs must be non-guessable and excluded from search indexing. Production retention and deletion behavior will be displayed beside the scanner before launch.
5. Evidence
Evidence can contain public URLs, route facts, timestamps, and redacted screenshots. Customers should not upload secrets or unrelated personal information. Sensitive values must be removed before synchronization.
6. Service providers and directories
Infrastructure providers may process limited service data on our behalf. When a customer authorizes a submission, the destination receives the profile facts entered into its form under the terms published by that destination.
7. Retention and deletion
Production retention periods, export behavior, and deletion timelines must be finalized before public billing. Until then, the application is an internal validation product and should not be used for unrelated personal data.
8. Contact
For access, correction, deletion, or privacy questions, email kenkenysy@gmail.com. Do not include account passwords or verification codes.