Scanlane

Privacy Policy

Last updated: 31 July 2026

1. Overview

This policy explains how we process personal data in connection with our website www.scanlane.com and our software service "Scanlane" (the "Service"). We process personal data exclusively in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

The short version. We do not use analytics, advertising or tracking cookies. We do not sell personal data. Our database is hosted in Frankfurt, Germany, and our servers run in the EU. The only personal data leaving the EU is the message text sent to our AI providers so that guest questions can be answered — protected by the safeguards described in section 8.

2. Controller

Merrett Ventures GmbH
Rheinsberger Str. 58, 10115 Berlin, Germany
Represented by: Gary Merrett (Managing Director)
Email: team@scanlane.com
Telephone: +49 (0) 30 9210 4641

We have not appointed a data protection officer, as the statutory conditions under § 38 BDSG do not currently apply. You can reach us on all data protection matters at the contact details above.

3. Two different roles — please read this first

Scanlane is used by hotels. This means we act in two clearly separated roles, and which one applies determines who is responsible for your data:

a) We are the controller

For our own website, for our business customers (hotels and their staff users) and for our own business administration. Everything described in sections 4 to 7 falls into this category.

b) We are a processor on behalf of the hotel

For everything a hotel guest writes in the guest chat. Here the hotel is the controllerand decides the purposes and means of processing; we merely process this data on the hotel's documented instructions under a data processing agreement pursuant to Art. 28 GDPR.

If you are a hotel guest and wish to exercise your data protection rights or ask what is stored about you, please contact the hotel whose QR code you scanned. We will of course support that hotel in responding to you. See section 9 for details.

4. Visiting our website

Server log data

When you access our website, your browser automatically transmits technical information which is processed by our hosting provider in order to deliver the site and keep it secure: IP address, date and time of the request, the page requested, referrer URL, browser type and version, and operating system.

Purpose: delivering the website, ensuring stability and security, defending against attacks.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the secure, reliable operation of our website.
Retention: log data is stored for a maximum of 30 days and then deleted.

Cookies

We use strictly necessary cookies only. We do not use analytics, statistics, remarketing, advertising or social media cookies, and we do not use tracking pixels or fingerprinting. For that reason we do not display a cookie banner: storing strictly necessary cookies does not require consent under § 25 (2) no. 2 TDDDG.

CookiePurposeDuration
Session cookie (login)Keeps a hotel staff user signed in. Set only after a deliberate login.Until logout / end of session
Guest chat cookieLets a guest's device recognise its own conversation after scanning a QR code. Contains only a random conversation identifier — no name, no profile.30 days

Both cookies are technically necessary for the requested function, are protected against access by scripts (HttpOnly) and are transmitted over encrypted connections only.

Fonts

We use the typefaces "Fraunces" and "Outfit". These are hosted by us and delivered from our own servers; no connection to Google servers is established when you visit our website and no data is transmitted to Google.

5. Contacting us

If you contact us by email, telephone or via a contact form, we process the data you provide (such as your name, email address, telephone number and the content of your message) in order to handle your enquiry.

Legal basis: Art. 6 (1) (b) GDPR where your enquiry relates to the performance of a contract or pre-contractual measures; otherwise Art. 6 (1) (f) GDPR based on our legitimate interest in responding to enquiries addressed to us.
Retention: until your enquiry has been fully dealt with, unless statutory retention periods (see section 7) require longer storage.

6. Customer accounts and use of the Service

If your hotel uses Scanlane and you have a user account, we process the following as a controller:

  • Account data: name, email address, role (staff or administrator) and a cryptographically hashed password. We never store passwords in plain text and cannot read them.
  • Usage data: which conversations you accepted, answered or closed. This is necessary so colleagues can see who is handling a guest and to prevent two people replying to the same guest at once.
  • Customer and billing data: company name, address, VAT identification number and contract details.

Legal basis: Art. 6 (1) (b) GDPR (performance of the contract with your employer and provision of your user account), and Art. 6 (1) (c) GDPR for statutory retention obligations relating to accounting data.

7. Retention periods

  • Server log data: maximum 30 days.
  • Account data: for the duration of the contract; deleted within 90 days of the contract ending, unless statutory retention obligations apply.
  • Guest conversations: determined by the hotel as controller; deleted at the latest within 90 days of the contract with that hotel ending.
  • Accounting records, invoices and commercial correspondence: 6 or 10 years pursuant to § 257 HGB and § 147 AO.

8. Service providers and recipients

We use carefully selected service providers who process personal data on our behalf as processors under Art. 28 GDPR. We have concluded data processing agreements with each of them. Where a provider processes data outside the EU/EEA, the transfer is safeguarded by the EU Standard Contractual Clauses and, where applicable, by the provider's certification under the EU–US Data Privacy Framework.

ProviderPurposeLocation of processing
Vercel Inc.Hosting and delivery of the website and applicationServers in Frankfurt, Germany (company based in the USA)
Neon Inc.Database hosting (all content and conversation data)Frankfurt, Germany
Anthropic PBCThe AI concierge: generating answers, translations and summariesUSA
Voyage AI (MongoDB Inc.)Converting document and website text into a searchable form (semantic search)USA
Resend Inc.Sending notification emails to hotel receptionUSA

Please note in relation to the AI providers: the text of a guest message and the relevant hotel information are transmitted in order to generate an answer. According to their terms, our AI providers do not use this data to train their models. We deliberately do not ask guests for names, email addresses or telephone numbers — but content that a guest chooses to write in the chat is naturally transmitted along with the message.

Beyond this, we do not pass personal data to third parties unless we are legally obliged to do so, or it is necessary to establish, exercise or defend legal claims.

9. Guest chat — information for hotel guests

Scanning a QR code opens a chat. Please note the following:

  • No registration. You are not asked for a name, email address, telephone number or any other identifying information, and you do not need an account or an app.
  • What is stored:the content of your conversation, the language detected, and which QR code you scanned (i.e. your room number or a location such as "lobby").
  • Who is responsible: the hotel operating the QR code, as controller. We act solely as its processor.
  • Your rights: please address requests for access, erasure or objection to that hotel. If you contact us instead, we will forward your request to the hotel without undue delay.
  • Please do not enter sensitive information such as payment card details, passwords, health data or identity document numbers into the chat. It is not needed to answer your questions.

10. Data security

  • All connections are encrypted in transit using TLS.
  • Passwords are stored only as salted cryptographic hashes and cannot be recovered by us.
  • Each hotel's data is strictly separated from every other hotel's at database level.
  • Internal information — such as reasons for escalation, internal AI summaries and staff identifiers — is technically prevented from ever reaching the guest chat.
  • Access to production data is limited to the persons who need it in order to operate the Service.

11. Your rights

You have the following rights in relation to your personal data:

  • Access (Art. 15 GDPR) — what data we hold about you.
  • Rectification (Art. 16 GDPR) — correction of inaccurate data.
  • Erasure (Art. 17 GDPR) — deletion, subject to statutory retention obligations.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — receipt of your data in a machine-readable format.
  • Objection (Art. 21 GDPR) — you may object at any time to processing based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation.
  • Withdrawal of consent (Art. 7 (3) GDPR) — with effect for the future, where processing is based on consent.

To exercise these rights, contact us at team@scanlane.com.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
www.datenschutz-berlin.de

12. Obligation to provide data, automated decision-making

You are not under any legal or contractual obligation to provide personal data. However, without the data required for a user account we cannot provide you with access to the Service.

Automated decision-making: our AI concierge generates answers to guest questions automatically. It does not make any decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR. A member of hotel staff can take over any conversation at any time, and any guest can ask to speak to a person.

13. Changes to this policy

We may amend this policy to reflect changes in the law or in our Service. The version published on this page applies. The date of the most recent update is shown at the top.