Legal
Privacy Policy
Last updated 6 October 2026
This policy explains what personal data Scopelyst (scopelyst.com) collects, why, who we share it with and the choices you have. Scopelyst is responsible for that data (the “controller”).
Scopelyst is a service for businesses: we collect business contact details and work information, not consumer data.
1. What we collect
- Account details. When you sign up: your name, business email, job title and seniority, and your company's name, website, headquarters location, size and industry. Your password is stored only as a one-way hash, and the 6-digit code that confirms your email only as a keyed hash.
- What you create. Projects and RFPs, uploaded documents (PDF and Word), proposals, questions and messages, company profile content, staffing listings and introduction requests.
- Vendor contacts. The names, job titles and business email, phone and LinkedIn of the management and marketing contacts a vendor adds to its profile.
- Public company information. To build the directory we collect what companies publish about themselves, mainly on their own websites, found with our search provider: services, technologies, industries, locations, certifications and case studies.
- Page views. When you open a company profile, project or staffing listing we record the page, the day, your user and organisation if you're signed in (otherwise an anonymous visitor ID kept in a cookie), and your approximate country and city. The location comes from our hosting provider's reading of your IP address, or from your browser's language; we don't store the IP address with the view.
- Security records. To limit abuse we briefly store your IP address with a counter for actions such as sign-in, search and uploads; these expire with the limit (an hour at most) and are then deleted automatically. We keep an audit log of significant actions, such as sign-ups, admin changes and opening uploaded files.
- Email. Messages we send you (codes, sign-in links, notifications) and their delivery status.
- Payments. When online checkout launches, our payment provider will collect card and billing details. We'll receive only what we need to manage your plan, such as its status and the card's last four digits.
2. How we use it
- to run your account, sign you in and keep each organisation's data separate;
- to match projects with vendors, run the directory and power search;
- to send the emails the service needs: codes, sign-in links and notifications about projects, proposals and messages;
- to show analytics: vendors see how many people viewed their profile and listings, from which countries, and how many signed-in organisations did; buyers see how many vendor organisations viewed their projects; premium vendors see which organisations opened their contact details;
- to prevent fraud and abuse, enforce our Terms and meet legal obligations;
- to understand and improve Scopelyst, using aggregated information.
We rely on the contract with you to provide the service, on our legitimate interests for security, analytics, the business directory and improvements, on your consent where the law requires it, and on legal obligations where they apply.
We don't sell personal data and don't use it for third-party advertising.
3. Who can see what
- Company profiles are public. A vendor's key contacts are shown only to signed-in members who open them with a credit.
- Projects are visible to the audience the buyer chooses (the marketplace, invited vendors, or both). Proposals are visible to the buyer organisation that ran the project.
- Messages are visible to the organisations in the conversation.
- Staffing listings are public with a shortened name (for example “Priya S.”); the vendor decides what else to show.
- Our team can access data to provide support, verify claims, moderate content and keep the service secure.
4. Service providers
We use these providers to run Scopelyst. Each gets only what it needs for its job and is bound to protect it.
- Cloudflare: hosting, content delivery and security (worldwide).
- Backblaze: encrypted storage of uploaded files.
- Our managed PostgreSQL provider: the database.
- Zoho ZeptoMail: sending email.
- DeepSeek: AI text generation and reading requirements out of documents. DeepSeek processes data in the People's Republic of China.
- Google (Gemini API): optional text embeddings for search and matching.
- Exa: web search to find public company information. We send it search terms, company names and domains, not your personal data.
- Dodo Payments: payment processing, once online checkout launches.
We may also disclose data when the law requires it, to protect people's rights and safety, or to a buyer of our business (we'd tell you first).
5. International transfers
Our providers process data in several countries, including the United States, the European Union, India and China. Where the law requires, we use safeguards such as standard contractual clauses.
7. How long we keep data
- Account details: while your account exists. When you delete your account we erase your personal details straight away; records your organisation owns (projects, proposals and messages) stay, shown as “Deleted user”.
- An unfinished sign-up, including its password hash: until you complete or restart it. Its code stops working after 10 minutes.
- Page views: while they're needed for the analytics shown to vendors and buyers.
- Audit logs: as long as needed for security and legal purposes.
- Backups: deleted on our providers' rolling schedules.
8. Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, object to or restrict how we use it, and withdraw consent. Most of this is in Settings: “Export my data” downloads what we hold about you and “Delete my account” erases it. For anything else, write to hello@scopelyst.com; we answer within 30 days.
If someone listed you in the directory or as a vendor contact and you don't use Scopelyst, you can ask us to correct or remove that information from the link on the profile or at hello@scopelyst.com.
You can also complain to your data protection authority, for example the Data Protection Board of India or your supervisory authority in the EU or UK.
9. Security
We use HTTPS everywhere, keep uploaded files in private storage behind short-lived signed links, store passwords and codes only as hashes, separate each organisation's data, rate-limit sensitive actions and log access to files. No system is perfectly secure; if a breach affects your data we'll tell you and the authorities as the law requires.
10. Children
Scopelyst is for business users aged 18 or over. We don't knowingly collect data about children.
11. Changes to this policy
We'll post updates here and change the date at the top. For a significant change we'll also tell you by email or in the app before it takes effect.
12. Contact and grievance officer
For privacy questions and requests, write to hello@scopelyst.com. Our grievance officer under Indian law is the Scopelyst privacy team, reachable at the same address.
