Privacy
Privacy Policy
A plain-English explanation of the information ScopeLock handles and why.
- Effective
- 22 July 2026
- Last updated
- 22 July 2026
Who this policy covers
ScopeLock is operated in Australia under the ScopeLock product name. This policy explains how the ScopeLock operator handles information for the website and service. Contact [email protected] with privacy questions.
ScopeLock aims to handle personal information responsibly and consistently with applicable Australian privacy obligations. This statement does not assert that the operator has been legally confirmed as an entity formally bound by the Australian Privacy Act 1988.
Information ScopeLock may collect
Account and business information
This can include account names and email addresses, password credentials stored as password hashes, business names, ABNs entered by customers, contractor licence details, phone numbers, reply email addresses, business addresses, branding and account settings.
Customer, job and approval information
Contractors may enter customer names, email addresses and phone numbers; property or job-site addresses; contract references and dates; scope, reason, price, GST and timing details; typed signatures; approval or decline records; notes; photos, plans and other uploaded files; delivery history; and generated PDF evidence packs.
Technical and service information
The service receives technical information needed to respond to requests and protect the application, such as network address information, browser or device user-agent information, request timing and service logs. Approval records retain a privacy-preserving network fingerprint rather than the raw customer IP address, together with user-agent information. Security events may also retain hashed network identifiers.
Billing and delivery information
Stripe hosts payment entry and may provide ScopeLock with customer and subscription identifiers, subscription state, invoice status and billing-period information. ScopeLock does not ask users to enter full payment card numbers into ScopeLock. Delivery records can include recipients, channel, time, provider identifiers, status and error information.
How information is used
- Provide accounts, workspaces and the ScopeLock service
- Create variation approval records, decision histories and PDF evidence packs
- Send approval requests, reminders, password resets, deletion notices and other service communications
- Process and reconcile subscriptions and usage
- Prevent abuse, protect accounts, investigate security events and diagnose faults
- Answer customer-support, access, correction and deletion requests
- Meet legal obligations and establish, exercise or defend legal rights where applicable
Service providers and disclosure
ScopeLock may disclose information to providers only as needed to operate the service, process payments, deliver messages, host the application, provide web infrastructure, investigate faults or comply with lawful requirements.
- Railway is the configured application deployment platform.
- Stripe provides hosted Checkout, subscription billing and the customer billing portal.
- Resend is the email-delivery integration when live email delivery is configured.
- Twilio is the SMS-delivery integration when SMS is configured and used.
- Cloudflare may support the production domain and web analytics used by the deployment.
- Reddit receives advertising measurement data when advertising is running: a page-visit signal from ScopeLock's own landing page, and a server-side conversion when a contractor signs up or a variation they sent is approved. What is sent is the advertising click identifier from the landing URL and a one-way hash of the CONTRACTOR's email address. Nothing about the customer who approves a variation is sent — not their name, email, IP address or device — and the advertising pixel is not present on the customer approval page, the crew invitation page or these policy pages.
- Google AdSense connects on the ScopeLock homepage and the trade-comparison marketing pages, where ads may be served. Loading it lets Google and its advertising partners set cookies and similar technologies in a visitor's browser and process device, browser and usage information to select and measure ads, as described in Google's advertising technology and privacy policy. It is not present on the customer approval page, the crew invitation page, the signed-in application or these policy pages.
ScopeLock does not claim that information is stored or processed only in Australia. These providers may process information in other countries under their own infrastructure and terms.
Contractor responsibilities
Contractors decide what customer and job information they enter. They are responsible for having appropriate authority, notices and permissions to enter customer details, signatures, photos, contracts and other content into ScopeLock and to instruct ScopeLock to send messages.
Access, correction and deletion
To request access to, correction of or deletion of information associated with an account, email [email protected]. Include the account email, business name and enough context to identify the relevant record. ScopeLock may need to verify identity, authority and workspace ownership before acting.
Deletion is not always immediate or complete. Some billing, fraud-prevention, security, dispute, approved evidence or legally required records may need to be retained or restricted. The implemented workflow keeps a keyed, non-readable hash derived from a deleted account email to prevent account recreation and trial abuse; this may prevent that email from being registered again. See the Data Storage & Deletion page for the implemented account and workspace process.
Security and data quality
ScopeLock uses application controls intended to protect accounts and separate business workspaces, but no online service can promise absolute security. Users should keep passwords confidential, use accurate information and promptly report suspected unauthorised access.
Changes to this policy
Updates will be published on this page with a revised last-updated date. If a change materially affects how the service handles information, ScopeLock may also communicate it through the service or account contact details where appropriate.
Contact
Privacy enquiries: [email protected]. Replies within one business day.