PRIVACY POLICY

Effective and last updated: August 8, 2026

1. Scope and our role

This Privacy Policy explains how Scoop Systems, Inc. (“Scoop,” “we,” “us,” or “our”) handles personal data when you visit scooplabs.ai and related pages (the “Site”), contact us, schedule a demonstration, or use our hosted software and support services (the “Service”). Scoop is the controller of personal data used to operate the Site, manage accounts, and administer our customer relationships.

Our business customers control the documents, records, and other content that they submit to the Service (“Customer Content”). For personal data in Customer Content, Scoop acts as a processor or service provider on the customer’s behalf, and the customer’s agreement with Scoop governs that processing. If your request concerns Customer Content, we may direct you to the customer that controls it.

2. Personal data we collect

Data you or your organization provides

  • Contact and business data: name, business email, employer, job title, meeting details, and the contents of messages you send us.

  • Account data: email address, name, organization, role, authentication or single-sign-on identifiers, account settings, and invitation status. Supabase processes passwords and authentication credentials; Scoop does not receive passwords in readable form.

  • Customer Content: documents, product and supplier records, regulatory claims, research materials, communications, instructions, AI prompts and outputs, and other information submitted by authorized users.

  • Support and relationship data: support requests, feedback, training records, and communications concerning the Service.

Data collected automatically

  • Technical and log data: IP address, request time, browser and device type, operating system, referring page, pages or routes requested, and security and diagnostic events.

  • Usage and performance data: feature interactions, audit events, approximate country or region, and anonymous application-performance metrics.

  • Browser storage: the strictly necessary authentication cookie and limited local or session storage described in Section 7.

We may receive the same types of data from your employer or account administrator, an identity provider used for single sign-on, a service integration you authorize, or a scheduling provider when you book a meeting. We do not collect payment-card data through the Site or Service.

3. How and why we use personal data

  • Provide, authenticate, secure, maintain, and support the Site and Service.

  • Process Customer Content and perform features requested by authorized users.

  • Manage accounts, organizations, demonstrations, contracts, and communications.

  • Detect abuse, investigate incidents, troubleshoot errors, and keep audit records.

  • Measure and improve reliability, accessibility, performance, and product design.

  • Comply with law, enforce agreements, and protect Scoop, customers, users, and others.

Where a law requires a legal basis, we rely on performance of a contract, steps you request before entering a contract, our legitimate interests in operating and securing a business service, compliance with legal obligations, and consent where required. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.

4. AI and document processing

When an authorized user invokes an AI, search, extraction, or document-processing feature, Scoop sends the information needed for that request to our contracted cloud and model providers, including Google Cloud’s Vertex AI and Document AI services. Scoop uses Customer Content to provide the customer-requested Service, not to build advertising profiles or sell personal data. AI output can be incomplete or inaccurate and must be reviewed by an appropriately qualified person before it is relied upon.

5. When we disclose personal data

We disclose personal data only as needed for the purposes described above: • Service providers. Providers process data under contract to help us operate the Site and Service. Current provider categories and functions include: • Framer: public-site hosting, forms, and cookie-free site analytics. • Vercel: application hosting and anonymous performance measurement. • Supabase: authentication and database services. • Google Cloud: cloud hosting, storage, document processing, and AI features. • Resend and Twilio SendGrid: website and service email delivery. • Cal.com: demo scheduling when you choose to book a meeting. • Your organization and integrations. We disclose data to authorized administrators and users of your organization and to integrations that the customer directs us to use. • Legal and safety. We may disclose data when reasonably necessary to comply with law or legal process, investigate fraud or abuse, enforce agreements, or protect rights, safety, and security. • Corporate transactions. Data may be reviewed or transferred as part of a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections. We do not sell personal data, share it for cross-context behavioral advertising, or use third-party advertising networks on the Site or Service. We have not done so in the preceding 12 months.

6. Data retention

We retain each category of personal data only for as long as reasonably necessary for the purpose for which it was collected. We determine the period using the duration of the customer or account relationship, customer instructions and contract terms, the time needed to answer an inquiry or provide support, security and incident-response needs, backup cycles, and applicable legal, tax, accounting, and dispute-preservation requirements. We delete or de-identify data when those purposes no longer apply, unless law requires or permits longer retention. Customer Content is returned or deleted in accordance with the applicable customer agreement and lawful customer instructions.

7. Cookies and browser storage

Public Site. Scoop does not place advertising cookies or other non-essential cookies on the public Site. Framer’s built-in analytics does not use cookies or persistent identifiers; it uses a daily rotating hash to count visits and provides aggregate metrics. Following an external link, such as Cal.com or LinkedIn, takes you to a service with its own privacy and cookie practices. Authenticated Service. After sign-in, the Service uses a first-party Supabase authentication cookie containing session tokens. It is strictly necessary to keep users signed in, authorize requests, and rotate sessions securely; rejecting it prevents authenticated use. The Service also uses local storage for non-sensitive view preferences and session storage for short-lived navigation, organization context, notifications, and AI-chat state. Session storage is cleared when the browser tab or session ends. Vercel Speed Insights collects anonymous performance measurements that are not tied to an identifiable visitor or browsing session. Because we do not sell or share personal data for targeted advertising, Global Privacy Control and browser “Do Not Track” signals do not change our practices. We will honor legally required opt-out preference signals if our practices change.

8. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, tenant isolation, encryption in transit, managed cloud security controls, logging, and restricted service credentials. No security measure is perfect, and we cannot guarantee absolute security. Please report suspected account compromise or security issues to legal@scooplabs.ai.

9. Your privacy rights

Depending on where you live, you may have the right to request access to or a copy of personal data, correction, deletion, portability, restriction or objection to certain processing, and withdrawal of consent. You may also have the right to appeal a denied request and complain to a data-protection regulator. We will not discriminate against you for exercising a privacy right. Submit a request to legal@scooplabs.ai and describe the right you wish to exercise. We will verify requests in a manner proportionate to the data and request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct identity verification. To appeal a decision, reply with the subject “Privacy Appeal.” If Scoop processes the relevant data for your employer or another customer, submit the request to that organization first.

10. California and other U.S. state disclosures

In the preceding 12 months, Scoop has collected the categories described in Section 2, which may correspond under California law to identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; professional or employment-related information; and account-login credentials treated as sensitive personal information. We collect these categories from the sources described in Section 2, use them for the purposes in Sections 3 and 4, and disclose them to the recipient categories in Section 5. We do not use sensitive personal information to infer characteristics about individuals. California residents may have rights to know, access, correct, delete, and obtain information about disclosure, as well as rights to opt out of sale or sharing and to limit certain uses of sensitive personal information. Because Scoop does not sell or share personal data and does not use sensitive personal information beyond permitted service and security purposes, there is no sale, sharing, or additional use to opt out of or limit. Residents of other states may have comparable rights, including the right to opt out of targeted advertising or profiling that produces legal or similarly significant effects; Scoop does not conduct those activities with personal data covered by this Policy.

11. International data transfers

Scoop is based in the United States, and we and our providers process data in the United States and other countries where they operate. Those countries may have different data protection laws. Where required, we use approved contractual safeguards for restricted transfers and make information about those safeguards available on request.

12. Children

The Site and Service are business products not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data to us, contact legal@scooplabs.ai so we can investigate and delete it where appropriate.

13. Changes to this Policy

We may update this Policy to reflect changes in our practices, services, or legal obligations. We will post the updated Policy here and change the date above. If a change materially affects how we use personal data already collected, we will provide additional notice or obtain consent when required by law.

14. Contact us

Questions and privacy requests may be sent to: Scoop Systems, Inc. 2261 Market Street, STE 86744 San Francisco, CA 94114 Email: legal@scooplabs.ai