This Privacy Policy explains how ZHOST Consulting Private Limited ("we", "ZScanner") collects, uses, and protects your personal information when you use zscanner.bithost.in and the ZScanner desktop application.
1. Information We Collect
- Email address — when you sign in via OTP to purchase a license or manage your account.
- Name, company, phone — optionally provided in your profile.
- Payment information — processed directly by Razorpay. We do not store card numbers or UPI IDs.
- Scan telemetry — license hash, scan timestamps, target domain, finding counts by severity. No vulnerability details, payloads, or report content.
- Server logs — IP addresses, browser type, pages accessed. Retained 30 days.
2. How We Use Your Information
We use your information to: deliver license keys and account communications, process and track payments, verify license validity, detect fraudulent use, improve the scanner based on aggregate telemetry, and send renewal reminders.
3. Data Sharing
We do not sell your personal data. We share data only with Razorpay (payment processor) and our email provider. Both operate under Data Processing Agreements.
4. Data Retention
Account data is retained while active and for 2 years after last login. Order and license records are retained for 7 years. Telemetry is retained for 12 months. Email support@bithost.in to request deletion.
5. Security
We use TLS (HTTPS) for all data in transit. License keys are HMAC-SHA256 signed. Authentication is via one-time codes — no passwords stored. Payment data is handled by Razorpay's PCI DSS Level 1 infrastructure.
6. Cookies
We use only a session cookie to keep you signed in. No advertising or third-party tracking cookies.
7. Your Rights
You have the right to access, correct, or delete your personal data. Email support@bithost.in. We respond within 30 days.
8. Contact
Data Controller: ZHOST Consulting Private Limited. Email: support@bithost.in.