ZipScout

Privacy Policy

How ZipScout handles information — for customers and for the people named in leads.

In effect as of August 17, 2026 (v1.0). This is ZipScout's operative privacy policy. It is

scheduled for attorney review; any revisions will be published here with a new effective date.

ZipScout ("ZipScout", "we", "us") operates zipscout.io and sells weekly business-to-business

sales lead lists. This policy explains what personal information we handle, why, and what choices

people have. It covers two very different groups of people, and the distinction matters:

1. Customers — the sales representatives and publishers who buy ZipScout subscriptions.

2. Business contacts — the people named in the leads we compile, who are identified in their

professional capacity at a business, not as private individuals.

Effective date: August 17, 2026. Contact: support@zipscout.io. Operator: ZipScout, zipscout.io.

A full registered business address will be listed here once attorney review is complete.


1. Information we collect from CUSTOMERS

When you create an account or subscribe we collect:

DataWhyKept
Name, business email, phoneaccount, delivery of your weekly lists, supportlife of account + 24 months
Passwordauthentication — stored only as a salted hash, never in readable formlife of account
Territory ZIP codes / postal codesto build and de-duplicate your territorylife of account + 24 months
Subscription tier, plan, invite codebilling and entitlementlife of account + as tax law requires
Delivery + feedback history (which leads you received, call outcomes you log)duplicate prevention, replacement credits, quality improvementlife of account + 24 months
Login timestamps, IP address, basic access logssecurity, fraud and abuse prevention12 months

Payment card data is never seen or stored by ZipScout. Card details are collected directly by

Stripe, Inc., our payment processor, under their own privacy policy (stripe.com/privacy). We

retain only Stripe's customer and subscription identifiers, the plan, and payment status.

We do not sell customer personal information, and we do not use it for advertising.

2. Information in the LEADS we compile

Our lead lists identify businesses and the person who makes marketing decisions at that business

— typically an owner, principal, or marketing director. For each lead we may hold: business name,

category, business address, business phone, business email, website, the decision-maker's name and

job title, whether the business runs trackable digital advertising, and the public sources that

confirmed the name.

Sources. This information is compiled exclusively from public and publicly accessible sources,

including: federal and state professional and business licensing registries (for example the

national NPI registry, state contractor licensing boards, state real estate and care-facility

licence rolls), state business entity filings, businesses' own public websites and staff pages,

public professional profiles, open mapping data, and public directories. We do not buy personal

data from data brokers, and we do not scrape private, password-protected, or paywalled sources.

Basis and purpose. This is business contact information about people acting in a professional

capacity, compiled and supplied for business-to-business sales outreach. Where the law requires a

lawful basis (for example legitimate interests under GDPR-style regimes), our basis is the

legitimate interest of enabling B2B commerce, balanced against the limited privacy impact of

business-role contact details. We do not knowingly collect purely personal or household contact

information, and we do not collect special-category data.

Verification standard. A lead is only delivered when at least two independent public sources

agree on the decision-maker. Recorded sources travel with each lead so any claim can be traced.

Retention. Leads are retained while a territory is active and are periodically re-verified.

Records identified as closed, stale, or unverifiable are removed or quarantined.

3. Calling and messaging compliance

ZipScout supplies business contact data; **our customers are solely responsible for how they

contact the businesses on their lists.** Every lead is screened as a business line, and any number

identified as a personal or mobile number is flagged so customers can apply extra caution. We do

not place calls or send messages to leads ourselves. Customers must comply with all applicable

telemarketing and anti-spam law in their jurisdiction, including the US Telephone Consumer

Protection Act and applicable Do-Not-Call rules, and Canada's Anti-Spam Legislation (CASL) for

Canadian contacts. See the Terms of Service for the full contractual allocation of this duty.

4. Your choices — including if you are a lead

If you are a business contact appearing in our data, you may ask us to correct or remove your

information. Email support@zipscout.io from an address at that business, or include enough

detail to identify the record. On a verified request we will delete or correct the record and add

it to a suppression list so it is not re-compiled from the same public sources. We aim to action

these within 30 days, and we do not charge for it.

If you are a customer, you may access, correct, export, or delete your account information by

emailing support@zipscout.io. Some records are kept as long as tax and accounting law requires,

even after account closure.

Depending on where you live you may have additional rights — for example, under the California

Consumer Privacy Act (CCPA/CPRA) the right to know, delete, correct, and to opt out of "sale" or

"sharing" of personal information. **ZipScout does not sell or share customer personal information

as those terms are defined by the CCPA.** Our lead lists consist of business contact information

supplied for B2B purposes; if you believe your information appears and you want it removed, use

the process above. We will not discriminate against anyone for exercising these rights.

5. Who we share information with

We share personal information only with service providers who need it to run the service, under

contract, and only for that purpose:

We may also disclose information where required by law, to enforce our Terms, or in connection

with a merger or sale of the business — in which case this policy continues to apply to the

information transferred.

6. Security

Data is transmitted over HTTPS and stored on access-restricted servers in the United States.

Passwords are stored only as salted hashes. Administrative actions are recorded in an audit log,

and databases are backed up nightly with a limited retention window. No system is perfectly

secure; we cannot guarantee absolute security, and customers are responsible for keeping their

own login credentials confidential.

7. International transfers

ZipScout is operated from the United States and information is processed there. Customers and

business contacts outside the United States should be aware that US law may differ from their

local law.

8. Children

The service is sold to businesses and is not directed to anyone under 18. We do not knowingly

collect information from children.

9. Changes

We may update this policy. The effective date above will change, and material changes affecting

customers will be notified by email to the account address.

10. Contact

Questions, corrections, or removal requests: support@zipscout.io

ZipScout · zipscout.io

Terms of Service · Questions or removal requests: support@zipscout.io

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.