PCI Scan
  • Scan
  • Assessment
  • Services
  • Contact
0
Home Terms & Privacy
Last updated 16 August 2026

Terms & Privacy

A plain-language explanation of the rules for using pciscan.org, the limits of our security checks, and how we handle your information.

Free scanA readiness pre-check, not an official ASV scan or PCI certification.
PermissionOnly scan a target you own or are expressly authorised to test.
PaymentsStripe handles card details; PCIScan does not receive your card number or CVV.
PrivacyNo signup is required for a free scan, and we do not sell personal information.
On this page

Terms of use

  1. 1 About us
  2. 2 Scope & acceptance
  3. 3 Use of the scanner
  4. 4 Paid services
  5. 5 Refunds
  6. 6 Intellectual property
  7. 7 Disclaimers & liability

Privacy policy

  1. 8 Privacy policy
  2. 9 Information we collect & use
  3. 10 Cookies & local storage
  4. 11 Service providers & overseas processing
  5. 12 Security & retention
  6. 13 Access, correction & complaints
  7. 14 Governing law
  8. 15 Changes to these terms

Get in touch

  1. • Contact
Terms of use

1 About us

PCIScan.org is operated by Pool.com.au Pty Ltd (ACN 615 426 929), an Australian proprietary limited company. References in these terms to "we", "us" or "our" mean Pool.com.au Pty Ltd. References to "you" or "your" mean the person or entity using the website or our services.

2 Scope & acceptance

By accessing pciscan.org, running a scan, submitting information, using the Windows app, completing an assessment, or purchasing a service, you agree to these Terms & Privacy. If you are acting for a business, you confirm that you have authority to accept them for that business.

If you do not accept these terms, do not use the scanner or submit information through the site. Service-specific descriptions shown at the time of purchase also form part of your agreement with us. If they conflict with this page, the service-specific terms apply to that service.

3 Use of the scanner

The free PCI Quick Check is an automated, externally visible readiness pre-scan. It is designed to identify common problems before you purchase a full scan, but it is not an official Approved Scanning Vendor (ASV) scan, penetration test, PCI assessment, certification or attestation of compliance.

A PASS means that this limited scan did not confirm a failing result among its checks at the time it ran. It does not guarantee that another scanner, an ASV, your acquiring bank or a PCI assessor will reach the same result. Warnings still require review, and results may contain false positives or false negatives.

The scanner connects to publicly reachable services and may send unusual but non-destructive test requests, including HTTP payloads, TLS handshakes, DNS queries, port connections and protocol probes. These requests may appear in server, firewall, intrusion-detection or hosting-provider logs and may trigger automated alerts.

Acceptable use

  • You may only scan a domain, IP address or system that you own or are expressly authorised to test. Starting a scan is your confirmation that this permission exists.
  • You must not use the service to harass, attack, disrupt, gain unauthorised access to, or attempt to compromise another person’s systems.
  • You must not evade rate limits, bypass human checks, overload the service, interfere with other users, or use results to facilitate harmful activity.
  • Automated bulk use, scraping, reverse-engineering, copying scanner logic, or commercial resale of the service or its results is prohibited without our written permission.
  • We may limit, suspend or block access where reasonably necessary to protect the service, investigate misuse, comply with law, or respond to a request from a target owner or hosting provider.
Important

Unauthorised access or security testing may breach Part 10.7 of the Australian Criminal Code Act 1995 and laws in other jurisdictions. You are responsible for confirming the scope of your authority before entering a target.

4 Paid services

We offer paid services including the Pre-Compliance ASV Scan, PCI Pulse, Windows Server initial configuration, Diagnose & Repair, and SAQ assistance. Prices are displayed in USD unless stated otherwise. Your card issuer may apply currency conversion or international transaction fees.

The scope, deliverables, price and any service-specific conditions shown when you order form part of the engagement. You must provide accurate contact and target information, valid credentials where required, appropriate authorisation, and timely cooperation. We may pause delivery while required information or access is outstanding.

Card details are entered into payment fields supplied by Stripe. We receive payment status and transaction references, but not your complete card number, expiry date or CVV.

Pre-Compliance ASV Scan

This paid service is a deep external diagnostic scan of an authorised IP address or domain. The scan takes approximately four hours and includes a 34-page technical PDF report ranking detected findings by severity. Scan duration may vary where the target, network or scanning platform affects collection.

This service is diagnostic only. It is not certification, formal ASV attestation, an Attestation of Compliance, or a substitute for a scan that your acquirer or compliance programme requires from an Approved Scanning Vendor. A clean result does not itself establish PCI DSS compliance. Each rescan is a separate purchase unless we expressly agree otherwise in writing.

PCI Pulse

The annual PCI Pulse fee covers 12 months from activation for one website or public IP. PCIScan.org runs its 45-check external scan approximately every six hours and sends email and SMS alerts when a check that was passing starts to fail. PCI Pulse is continuous external monitoring only; it is not an official ASV scan, PCI certification, or a substitute for any required ASV scan. The annual checkout is a one-time payment and does not automatically renew.

You must keep the authorised target scope and contact details current. Monitoring and alerts depend on the target remaining publicly reachable and on third-party networks, firewalls, filtering services, email systems and mobile carriers allowing the relevant traffic and messages.

5 Refunds

Each paid service has its own refund position, set out on its product page. In summary:

  • Diagnose & Repair — full refund if we cannot resolve the issue, as described on the service page.
  • SAQ assistance — full refund if our team cannot fully understand your server or deployment scenario, as described on the assessment page.
  • Pre-Compliance ASV Scan, PCI Pulse and Server initial configuration — refunds are considered case-by-case where we are at fault. Change-of-mind refunds are not generally available once scanning, monitoring or technical work has commenced.

Nothing in this section limits a refund, re-performance, compensation or other remedy available under the Australian Consumer Law. Send requests to info@pciscan.org with your order reference and a description of the issue. Approved refunds are returned to the original payment method.

6 Intellectual property

All content on pciscan.org — including the scanner logic, page layout, copy, graphics, logos and the underlying source — is owned by or licensed to Pool.com.au Pty Ltd and protected by Australian and international copyright laws.

You may view, link to and print public pages and your own scan reports for internal, non-commercial use. You may not republish, reproduce, sell, systematically extract or substantially copy the site, scanner implementation or check library without our prior written consent.

The official PCI DSS SAQ documents linked from this site are the property of the PCI Security Standards Council and are made available under their own terms.

7 Disclaimers & liability

The free scanner, check explanations and assessment tools are provided "as is" and "as available". They are general technical information, not legal advice, an audit opinion, a promise of PCI compliance, or a recommendation to make a particular business decision.

We do not warrant that every vulnerability will be detected, every reported issue is exploitable, every warning is relevant, or the service will always be available or error-free. Security conditions can change immediately after a scan.

To the maximum extent permitted by law, we are not liable for indirect or consequential loss arising from reliance on a free result. Where liability can lawfully be limited, our total aggregate liability for the free site is limited to AUD $100, and liability for a paid service is limited to the amount paid for the specific service giving rise to the claim.

Nothing in these terms excludes, restricts or modifies a consumer guarantee, right or remedy under the Australian Consumer Law or another law where doing so would be unlawful.

Privacy policy

8 Privacy policy

Pool.com.au Pty Ltd is responsible for the personal information handled through pciscan.org. This policy explains the kinds of information we collect, how and why we use it, the service providers involved, and how to contact us about access, correction or a complaint.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. We aim to follow the same practical privacy safeguards across the site even where a particular legal obligation does not apply.

You can use the free scanner without creating an account. If you choose not to provide optional information, some paid, contact or report-delivery features may not be available.

9 Information we collect & use

When you run a scan

  • The domain or IP address you enter, resolved addresses, scan responses, check results, timestamps and a randomly generated scan identifier.
  • Your source IP address and basic request information, used for security, rate limiting, troubleshooting and abuse prevention.
  • When you confirm permission to scan, we retain the confirmation time, authorised target, source IP, country code, scan identifier, browser user agent and the version of the authorisation statement you accepted.
  • A generated HTML report, where report generation is available.

We use this information to perform the requested checks, display and deliver results, maintain service reliability, investigate misuse, improve check accuracy and keep operational records.

Report links

A generated scan report is available through an unlisted web address. It is not indexed intentionally, but it is not password-protected. Anyone who receives the exact link may be able to view it. Do not include secrets in a target URL, and share report links carefully.

When you contact us, request the SAQ assessment, or email a report

  • Your name, email address, optional phone number, subject, message, report recipient and any technical or assessment information you provide.
  • Your IP address, submission time and basic request information used to prevent spam and investigate delivery problems.
  • For a supplied phone number, its country selection and the validity, carrier or line-type information returned by our phone verification provider.

We use this information to respond, provide requested support, deliver reports, verify contact details, assess your PCI requirements and maintain correspondence records.

When you purchase a paid service

  • Your name, company, email address, phone number, authorised target, selected service, order value, order reference and information needed to perform the work.
  • Payment status and transaction or Checkout references returned by Stripe. Stripe handles your card number, CVV and expiry directly.
  • Technical details, credentials or questionnaire answers you later provide for the purchased service. Please use the secure delivery method we specify rather than sending passwords through ordinary forms.

We use order information to take payment, prevent fraud, deliver the service, communicate about the engagement, maintain accounting records, resolve disputes and meet legal obligations.

10 Cookies & local storage

We use limited browser storage needed to operate the site:

  • Session cookies support form security, server-side session state and restricted administration features.
  • Local storage remembers cart contents and may temporarily retain individual scan-result details so check explanation pages can display the relevant finding.
  • Payment security storage may be set by Stripe when secure payment fields or Checkout are loaded, for payment processing and fraud prevention under Stripe’s policy.

We do not use third-party advertising cookies or sell browsing profiles. You can clear or block browser storage in your browser settings, although forms, the cart or checkout may then stop working correctly.

11 Service providers & overseas processing

We disclose only the information reasonably needed for a provider to perform its function, or where disclosure is required or authorised by law. Providers relevant to the site include:

  • Stripe — payment processing for paid services. Subject to Stripe's privacy policy.
  • Textmagic — validation and carrier lookup for phone numbers entered in contact and checkout forms. Subject to Textmagic’s privacy policy.
  • Our contracted scanning platform — when you purchase a Pre-Compliance ASV Scan, we provide the authorised target and the customer or contact details needed to configure, perform and deliver the diagnostic scan and report.
  • Microsoft Store — if you choose to download our companion Windows app, the Microsoft Store handles delivery under Microsoft's privacy statement.
  • Hosting, email and content-delivery providers — infrastructure used to operate the site and deliver communications may process standard request, message or delivery data.

Some providers operate globally, so information may be processed outside Australia, including in the United States, United Kingdom or European Economic Area, depending on the provider and service used. Those providers handle information under their own privacy terms and contractual obligations.

We do not sell or rent personal information.

12 Security & retention

We take reasonable technical and organisational steps to protect information, including TLS in transit, access restrictions, server-side payment processing and keeping complete card details within Stripe-hosted fields. No internet service can be guaranteed completely secure.

We retain information only for as long as reasonably needed to provide the service, maintain security and accounting records, resolve disputes, or meet legal obligations. Retention periods vary by record type. Scan reports and operational logs may be removed automatically, at our discretion, or following a valid request; residual copies may remain temporarily in backups.

Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches and notify affected individuals and the Office of the Australian Information Commissioner when legally required.

If you believe a security issue exists with this site, email info@pciscan.org with enough detail for us to investigate. We welcome responsible disclosure.

13 Access, correction & complaints

You may contact us to:

  • Request access to the personal information we hold about you.
  • Ask us to correct information that is inaccurate, incomplete or out of date.
  • Request deletion of a stored scan report, contact submission or other record where we are not required to retain it.
  • Make a privacy complaint or ask a question about this policy.

Email info@pciscan.org and identify the relevant email address, order reference, scan target or report link. We may need to verify your identity or authority before providing, changing or deleting information. We aim to acknowledge privacy complaints promptly and provide a substantive response within 30 days.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

Children

The site is intended for business and technical users. We do not knowingly solicit personal information from children under 13. A parent or guardian who believes a child has supplied information can contact us to request its removal.

14 Governing law

These terms are governed by the laws of Queensland, Australia. You and Pool.com.au Pty Ltd submit to the exclusive jurisdiction of the courts of Queensland and the Commonwealth courts sitting in Queensland in respect of any dispute arising out of or in connection with these terms.

15 Changes to these terms

We may update these Terms & Privacy to reflect service, provider or legal changes. The "Last updated" date identifies the current version. Material changes apply prospectively from publication unless law requires otherwise. Your continued use after an update means the revised terms apply to that later use.

Contact

Entity
Pool.com.au Pty Ltd
ACN 615 426 929
Post
PO Box 957
Samford QLD 4520
Australia
Email
info@pciscan.org
Text Support
+61 485 887 550
Back to top
PCI Scan

Free Scans

  • Online scan
  • Windows App

Paid Services

  • Pre-Compliance ASV Scan
  • PCI Pulse

Links

  • SAQ types
  • Terms & Privacy