Skip to main content
← Back to Home

Privacy Policy

Last updated: September 10, 2026

What we collect

  • Account details — your email address and authentication identifiers, handled by Clerk.
  • Billing details — a Stripe customer and subscription identifier, plus your plan and renewal date. We never see or store your card number; Stripe handles payment details directly.
  • Usage records — for each API call: the endpoint, the query parameters you sent (search term, location, platforms), the HTTP status, and the response time. These power your dashboard and your monthly allowance.

We do not use advertising trackers, and we do not sell personal information.

Why we collect it

To authenticate you, to meter usage against the plan you bought, to bill you, to show your request history, and to diagnose failures. That is the whole of it.

Who processes it

These providers process data on our behalf:

  • Clerk — authentication and account records
  • Stripe — payments and subscription state
  • Supabase — the application database (US)
  • Upstash — cache and rate-limit counters (US)
  • Vercel — hosting and request logs
  • ScraperAPI and RapidAPI — receive your search terms in order to fetch marketplace results

Your search queries are sent to our scraping providers to fulfil requests. They are not linked to your identity when we do so.

Retention

Cached marketplace results expire after fifteen minutes. Usage records are kept while your account is open so your history and monthly totals remain accurate. When you delete your account, account and usage records are deleted within thirty days, except where we must retain billing records for tax and accounting purposes.

Your rights

You can request a copy of your data, correction of it, or its deletion, by emailing support@scoutapi.io. We respond within thirty days. Depending on where you live, you may also have the right to object to processing or to complain to a data protection authority.

Security

API keys are stored as SHA-256 hashes, never in plaintext — which is why a lost key must be regenerated rather than recovered. Traffic is served over HTTPS. Database access is restricted to the application.

Changes

If we change how we handle your data, we will update this page and notify account holders by email before the change takes effect.

Questions? Email support@scoutapi.io.