Legal

Privacy Policy

Last updated

How AcquireScout handles personal data. The short version: we collect the minimum needed to run the product, we don't sell it, we don't track you across the web, and you can export or delete your account yourself at any time.

1. Who this covers

This policy covers personal data we process about you as a user of AcquireScout.

It does not cover information about companies on the Companies House register. That is public data published by Companies House under its own terms; where it includes personal data about company officers and persons with significant control, Companies House is its source and publisher.

2. What we collect

We collect only what the product needs to work:

  • Account data — your email address and password (stored hashed by our authentication provider, never in readable form), plus your organization memberships and role.
  • Content you create — Buy Boxes, watchlists, pipeline entries, tasks, notes, diligence items, memos, and any documents you upload to a Deal Room.
  • Operational records — an audit log of security- and billing-relevant actions (who did what, when), and activity logs within your organization, kept so account owners can see what happened in their workspace.
  • Billing data — if and when paid plans launch, a Stripe customer and subscription identifier. Card details go directly to Stripe; we never receive or store them.

We do not run advertising or cross-site tracking, and we do not sell or share personal data with data brokers.

3. Why we process it, and on what basis

  • To provide the service — performance of our contract with you: authenticating you, keeping your organization's data separated from everyone else's, and running the features you use.
  • To keep it secure and working — our legitimate interests: rate limiting, abuse prevention, audit logging, diagnosing errors.
  • To take payment — performance of contract, once paid plans exist.
  • To meet legal obligations — where we must keep records.

4. Who processes it for us

We use a small number of processors, each for a specific purpose, and we share only what that purpose needs:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting.
  • Companies House — the source of company data. We send company identifiers to it; we do not send it anything about you.
  • Google (Gemini) — generates the natural-language explanations described in our Terms. It receives the company facts and the text of the request being explained. Don't put personal or confidential information into free-text fields you then ask the assistant about.
  • Stripe — payment processing, once paid plans launch.

Some of these operate outside the UK. Where personal data is transferred internationally, it is done under the safeguards those providers offer for such transfers.

5. How long we keep it

Your account data and content are kept while your account is open. Delete your account and they are removed, as described below. Audit-log entries are retained after deletion in a form that no longer identifies you, because they exist precisely to record that security-relevant actions happened.

Company data from the Companies House register is not personal data about you and is retained independently of your account.

6. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict, object to, and port your personal data. Two of these are built into the product and need no request:

  • Export — Settings → Account downloads a machine-readable JSON file containing your profile, organization memberships, the Buy Boxes, watchlists, pipeline entries, tasks, notes, diligence items and memos you created, your activity, and your own audit-log entries.
  • Deletion — Settings → Account deletes your account. Organizations where you are the only member are deleted outright along with their data. If you are the sole owner of an organization that has other members, you must transfer ownership first, so their workspace isn't destroyed with your account.

For anything those don't cover, see the Contact page.

You can also complain to the UK Information Commissioner's Office (ico.org.uk).

7. Security

Data is separated per organization at the database level, so one organization cannot read another's — enforced by the database itself rather than only by application code. Traffic is encrypted in transit. Access to production data is limited to what operating the service requires.

No system is perfectly secure. If a breach affects your personal data and presents a risk to you, we will notify you and the ICO as required.

8. Cookies

We use cookies strictly necessary for the service to function: a session cookie that keeps you signed in, and a cookie remembering which organization you are currently working in. There are no advertising, analytics, or third-party tracking cookies, so there is no consent banner to click through.

9. Changes

If this policy changes, the “last updated” date above changes with it. If a change materially affects how we handle your personal data, we'll make that clear rather than relying on you to re-read this page.