← Back to RivalScout

Privacy Policy

Last updated: March 8, 2026

1. Who We Are

RivalScout (“we,” “us,” or “our”) operates rivalscout.app, a SaaS platform that helps businesses track competitor pricing and receive automated alerts. Questions? Email privacy@rivalscout.app.

2. Data We Collect

Account data

Your email address, collected when you sign up or log in. We use magic links and OAuth — no passwords stored.

Tracking data

Product URLs and competitor URLs you submit for price tracking, along with the prices and price history we retrieve for those URLs.

Billing data

Subscription tier and billing status. Payment card details are processed and stored by Stripe — we never see or store raw card numbers.

Usage data

Basic product analytics (pages visited, features used) to improve the service. No third-party ad tracking.

3. How We Use Your Data

  • Authenticate your account and maintain your session
  • Run scheduled price checks on your tracked URLs
  • Send price-change alerts and product notifications to your email
  • Process subscription payments and manage your billing
  • Diagnose bugs, improve reliability, and develop new features
  • Comply with legal obligations

We do not sell your data. We do not use your data to train AI models. We do not serve ads.

4. Third-Party Services

We share data only with the vendors necessary to operate the service:

VendorPurposeData shared
SupabaseDatabase & authenticationEmail, tracking data, price history
StripePayment processingEmail, billing info
ResendTransactional emailEmail address, alert content
VercelHosting & CDNRequest logs (IP, user agent)

5. Data Retention

We retain your account data and tracking history for as long as your account is active. When you delete your account, your personal data and tracked URLs are permanently deleted within 30 days. Aggregated, anonymized price data may be retained longer for service improvement. Stripe retains billing records as required by financial regulations.

6. Your Rights

You can at any time:

  • Access — request a copy of the data we hold about you
  • Correct — update your email address via account settings
  • Delete — delete your account in Settings → Danger Zone; your data is purged within 30 days
  • Export — request a data export by emailing privacy@rivalscout.app
  • Opt out — unsubscribe from marketing emails at any time (transactional alerts required for service operation)

If you are in the EU/EEA, you have rights under GDPR including the right to lodge a complaint with your local supervisory authority.

7. Cookies & Tracking

We use session cookies for authentication only. We do not use advertising cookies or cross-site tracking. You can disable cookies in your browser, but the app requires session cookies to function.

8. Security

All data is encrypted in transit (TLS 1.2+) and at rest. Authentication uses passwordless magic links and OAuth providers. Access to production data is restricted to authorized personnel only. Despite these measures, no system is 100% secure — please notify us immediately at privacy@rivalscout.app if you discover a vulnerability.

9. Children

RivalScout is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If we learn we have, we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice in the app. Continued use after changes constitutes acceptance of the updated policy.

Contact

Privacy questions, data requests, or concerns: privacy@rivalscout.app