This policy explains what Minor Tangent Studios LLC ("we") collects through LeadScout, why, who we share it with, and the choices you have. We don't sell your personal information and we don't run advertising or analytics trackers.
1. Who is responsible
For your account data we are the controller. For information about leads that you submit or that arrives through your intake form or webhook, you decide why it is collected and we process it for you under our Data Processing Addendum (see section 8). Contact: support@getleadscout.io, 55 Everglades Blvd, #110-52, Naples, FL 34120.
2. What we collect
You give us:
- Account: email address, and a password (stored only as a hash by our sign-in provider). If you turn on two-factor authentication, an authenticator factor and recovery codes.
- Profile and settings: studio name, website, business type, ideal client, about text, your services, time zone, intake form settings, report destinations (email addresses, webhook URL and its signing secret) and your inbound webhook token.
- Scout requests: company name, website, reference links, contact name, email and phone, message and notes, whether you type them or they arrive through your form or webhook.
- Payments: Stripe handles card details. We receive and keep the amount, currency, pack size, date, status, receipt link and Stripe identifiers.
- Email preferences: whether you opted in to marketing email, and when.
We create:
- Scout reports and their delivery records, a credit ledger, and the estimated cost of each run.
- Short-lived rate-limit counters keyed to your IP address (and hashed email addresses) to block abuse, and a one-way hash of your normalized email address that records that a free Scout was claimed.
Collected automatically:
- Essential cookies that keep you signed in. We don't use advertising or analytics cookies.
- Standard server logs (IP address, browser, pages requested, errors) kept by our hosting provider.
- Error and performance diagnostics (such as error messages, stack traces, browser and device details, your IP address and your account ID) sent to Sentry when something goes wrong in the app.
- A time zone setting from your browser, used to show dates correctly.
From public sources: to build a report we search and read publicly available web pages about the company you name (its website, listed social profiles, news, directories). These may contain information about people connected to the business, such as owners, staff and public reviews. We use this only to produce your report.
3. How we use it
- To provide the Service: sign you in, run Scouts, deliver reports, track credits and take payment.
- To secure the Service: prevent fraud, enforce one free Scout per person, rate-limit abuse, require extra verification for admin access.
- To support you, send account and security emails (confirmation links, password resets, report deliveries), and meet legal and accounting obligations.
- To send you marketing email (product news, tips and offers) only if you opted in. See section 7.
- To maintain and improve reliability and cost control, using operational data such as run status and estimated cost.
Where the GDPR or UK GDPR applies, our legal bases are performing our contract with you, our legitimate interests in running and securing the Service, compliance with legal obligations, and your consent for marketing email.
4. Who we share it with
We use these service providers, who process data only to provide their service to us:
- Supabase: sign-in and database hosting.
- Vercel: application hosting, background workflows and the AI Gateway that routes requests to AI model providers.
- AI model providers (reached through Vercel AI Gateway): receive the Scout request details, your profile and services, and the web content gathered, to write the report. We require zero data retention, so requests only go to providers that have agreed not to store prompts or outputs or use them to train models. Providers: OpenAI and other providers available through Vercel AI Gateway, all with zero data retention required.
- Exa (web search, reached through Vercel AI Gateway): receives search queries, which usually include the company name.
- Firecrawl: searches and reads public web pages for research. It receives the company name, website and links.
- Stripe: payments.
- Sequenzy: sends report, account and (if you opted in) marketing emails.
- Cloudflare Turnstile: bot protection on sign-up and sign-in forms.
- Sentry: error monitoring. It receives the diagnostics described in section 2 so we can find and fix bugs.
We also share information when you direct us to (for example, delivering a report to your webhook), when the law requires it, to protect rights and safety, or in a merger or sale of the business with notice to you. Where providers are outside your country, including the United States, we rely on appropriate safeguards such as standard contractual clauses.
5. How long we keep it
- Account, profile, services, scouts, reports, destinations and credit history: until you delete your account. Credits never expire, so we don't delete accounts for inactivity.
- When you delete your account, that data is removed from our live database right away. Copies in the database provider's backups are not edited individually; they are overwritten as backups rotate, within 7 days. Server and workflow logs at our hosting provider age out on their own schedule, within 30 days.
- Payment records are kept for tax and accounting, with nothing linking them to you (amount, date and Stripe's identifiers). Stripe keeps its own records under its policies.
- The one-way hash that records a claimed free Scout is kept so the same email can't claim another.
- If you unsubscribe from marketing, we keep a record of that so we don't email you again.
- Rate-limit counters expire within a day.
6. Security
Data is encrypted in transit. Database access is restricted to our servers, accounts are isolated from each other in code, passwords are never stored by us in readable form, and optional two-factor authentication is available to everyone and required for administrators. Webhook deliveries are signed. No system is perfectly secure; tell us at support@getleadscout.io if you find a problem.
7. Your choices and rights
- Delete: you can delete your account and its data yourself on the Account page.
- Marketing email: it is off unless you choose it. Unsubscribe at any time with the link in any marketing email, or in your account settings. You will still get essential service emails.
- Access, correct, export, object or restrict: email us. Depending on where you live (for example the EEA, UK, California and other US states) you have rights to access, correct, delete, port and object to processing, and not to be discriminated against for using them. We respond within the time the law requires.
- Complaints: you can complain to your data protection authority.
If you are a person named in a lead or a report and want information corrected or removed, contact the LeadScout customer who received it, or email us and we will pass your request on or act on it ourselves where we are able.
8. Leads you collect through the Service
If you use an intake form or webhook, we process the lead details you receive on your behalf under our Data Processing Addendum. You are responsible for notifying leads and for having a lawful basis.
9. Children
The Service is for people 18 and over. We don't knowingly collect information from children.
10. Changes
We may update this policy and will change the effective date above. For material changes we will notify you by email or in the app.
11. Contact
Minor Tangent Studios LLC, 55 Everglades Blvd, #110-52, Naples, FL 34120. support@getleadscout.io.
