01 · What we collect
What we collect.
Scoutr holds two kinds of data, and the distinction matters.
Your account data
- Identity: your name and email address
- Authentication: a one-way hash of your password (we never store or see the password itself) and session identifiers
- Billing status: your plan and Stripe billing identifiers. Card numbers go to Stripe directly and never touch our servers.
- Usage: standard server logs (IP address, browser, pages visited) used for security and debugging
Your connected business data
When you connect a platform you own (Shopify, Meta, Google Ads, Klaviyo, Mailchimp, TikTok), Scoutr pulls the data needed to do its job: campaign and content performance, audience and list names, product catalogue details, and order attribution data. We pull what the product uses and nothing speculative.
What we never collect. Your platform passwords (connections use OAuth, which means the platform itself logs you in and hands us a revocable token). Your customers' personal identities. Private messages. Payment card numbers.
02 · Where it lives
Where it lives, and how it's protected.
Everything runs on Amazon Web Services. In transit, all traffic is encrypted with TLS 1.2 or better. At rest, stored data is encrypted. Passwords are hashed with PBKDF2-HMAC-SHA256, so a plain-text password does not exist anywhere in our systems. Access to production follows least privilege, accounts lock after repeated failed sign-ins, and encrypted backups run on a cycle no longer than 35 days.
The complete list of technical and organisational measures lives in Section 7 of our DPA.
04 · How long we keep it
How long we keep things.
Active account
Your data is kept while your account is active, because it is what the product runs on.
Closed account
Account data is held for 30 days so you can export anything you need, then deleted.
Disconnected platform
Data pulled from that platform is deleted within 30 days of you disconnecting it.
Backups
Encrypted backups are overwritten in the normal cycle, never held longer than 35 days.
Legal records
A narrow set of transactional records (receipts under Australian tax law) is kept only as long as the law requires, then securely deleted.
05 · Deleting your data
How to delete everything.
Three paths, pick whichever suits:
- Disconnect a platform: Integrations page, click Disconnect. Token revoked immediately, platform data gone within 30 days.
- Close your account: email hello@scoutr.world from your account email with the subject "Account deletion request". We verify it's you, delete within 30 days, and confirm by email when it's done.
- A specific request: anything narrower (one platform's data, a specific export before deletion, a formal GDPR or Privacy Act request), same address. We respond within 5 business days.
06 · Who else touches it
The short list of who else touches it.
A small set of providers helps run Scoutr: AWS for hosting, Stripe for payments, Anthropic for AI synthesis (public market content only, never your account identity), Google for analytics, Meta for ad measurement, and Google Workspace for sending email. Each one is bound by data protection terms no weaker than ours.
The full sub-processor list, with what each one does and where it operates, is maintained in Section 8 of our DPA. We notify account emails 14 days before adding or changing any of them.
One thing we want unambiguous: we do not sell your data, and we do not use your business data to benefit anyone but you.