Data lifecycle

Data Storage & Deletion

What is stored, where providers may process it and what the implemented deletion workflow does.

Effective
22 July 2026
Last updated
22 July 2026

Information stored in ScopeLock

ScopeLock workspaces can store account and business details; customer names and contact details; job-site addresses; contract, scope, price, GST and timing information; signatures and decisions; photos, plans and other uploads; delivery and reminder records; usage and subscription state; audit events; and generated PDF evidence packs.

This information is used to run the variation-approval and evidence-record service, provide support, reconcile subscriptions, protect the service and meet applicable obligations.

Infrastructure and subprocessors

Railway is the configured application deployment platform. Stripe provides hosted subscription billing. Resend provides email delivery when live email is configured, Twilio provides SMS delivery when configured and used, and Cloudflare may support the production domain and web analytics.

Reddit receives advertising measurement data while advertising is running: a page-visit signal from the ScopeLock landing page, and a server-side conversion when a contractor signs up or a variation they sent is approved. The identifiers sent are the advertising click identifier from the landing URL and a one-way hash of the contractor's email address. No customer information is sent to Reddit, and the advertising pixel is not present on the customer approval page.

Google AdSense connects on the ScopeLock homepage and the trade-comparison marketing pages, where ads may be served, and in doing so sets cookies and processes device, browser and usage information for ad delivery and measurement; see Google's advertising technology and privacy policy. It is not present on the customer approval page, the crew invitation page, the signed-in application or these policy pages.

ScopeLock does not claim Australian-only hosting or processing. Provider infrastructure may process information outside Australia, and the current code does not verifiably restrict all processing to Australia.

Keep your own important records

Download and retain important signed PDF evidence packs, approvals and exports in your own business files. Account closure, retention rules, service changes or a dispute can affect how long hosted information remains readily available.

Requesting account deletion

Signed-in users can open Settings → Account and use the clearly labelled account-deletion workflow. It displays affected workspaces, ownership blockers, subscription cancellation and the applicable dates before confirmation. The request locks normal account access immediately; it does not claim to erase every record instantly.

You can also email [email protected] for help. Include the account email, business name, relevant workspace names and any deletion request ID. Support may need to verify your identity, authority and ownership. Do not email your password.

Implemented timing

The application currently schedules user-account finalisation after a configurable grace period of 14 days by default. Full business-deletion processing is scheduled no earlier than 30 days by default so eligible draft handling and billing cancellation can be rechecked. The authenticated status screen shows the actual effective dates for the request.

Those periods are product-policy defaults, not a statement that Australian law requires the same period for every record. Ownership, subscription state, failed file actions, active reservations, disputes or documented retention holds can delay completion.

What is removed or changed

  • Sessions and unused password-reset tokens are revoked when an accepted account-deletion request starts.
  • At finalisation, direct account profile and login details are removed or replaced with restricted, non-reversible deleted-account values, and memberships are removed where ownership rules permit.
  • Under a full business-deletion request, eligible draft-only variations and unreferenced draft attachments can be deleted after the configured period.
  • Temporary settings and uploads can be removed when no evidence, delivery, billing, security, support or dispute dependency remains.

What may be retained

ScopeLock may need to retain or restrict some information for billing and financial reconciliation, fraud and abuse prevention, security auditing, dispute resolution, legal obligations or documented holds. Decided approval records, signatures, hashes, evidence-linked attachments and immutable PDF evidence packs may be retained where changing or deleting them would break the evidence record or where an approved purpose requires retention.

The current workflow retains a keyed, non-readable hash derived from the deleted account email for account-recreation and trial-abuse controls. This can prevent the same email address from being registered again; contact support if you need help after deletion. Stripe customer and invoice records are not automatically deleted. Trial, usage and founding-customer control records are not reset by account deletion. Retention periods depend on the record and applicable purpose, and these controls remain subject to Australian legal, privacy and accounting review.

Backups and delayed removal

Deletion from active systems may not instantly remove information from provider or system backups where those copies exist. Backup copies may remain until their applicable rotation or retention process completes, and deletion changes must be reapplied after a disaster restore before normal service resumes. ScopeLock does not promise a particular backup age-out period or guaranteed data recovery because the production backup configuration has not been verified in this repository.

Help with a request

Contact [email protected]. Replies within one business day. Support acknowledgement does not mean that deletion has completed.