How ZipScout handles information — for customers and for the people named in leads.
In effect as of August 17, 2026 (v1.0). This is ZipScout's operative privacy policy. It is
scheduled for attorney review; any revisions will be published here with a new effective date.
ZipScout ("ZipScout", "we", "us") operates zipscout.io and sells weekly business-to-business
sales lead lists. This policy explains what personal information we handle, why, and what choices
people have. It covers two very different groups of people, and the distinction matters:
1. Customers — the sales representatives and publishers who buy ZipScout subscriptions.
2. Business contacts — the people named in the leads we compile, who are identified in their
professional capacity at a business, not as private individuals.
Effective date: August 17, 2026. Contact: support@zipscout.io. Operator: ZipScout, zipscout.io.
A full registered business address will be listed here once attorney review is complete.
When you create an account or subscribe we collect:
| Data | Why | Kept |
|---|---|---|
| Name, business email, phone | account, delivery of your weekly lists, support | life of account + 24 months |
| Password | authentication — stored only as a salted hash, never in readable form | life of account |
| Territory ZIP codes / postal codes | to build and de-duplicate your territory | life of account + 24 months |
| Subscription tier, plan, invite code | billing and entitlement | life of account + as tax law requires |
| Delivery + feedback history (which leads you received, call outcomes you log) | duplicate prevention, replacement credits, quality improvement | life of account + 24 months |
| Login timestamps, IP address, basic access logs | security, fraud and abuse prevention | 12 months |
Payment card data is never seen or stored by ZipScout. Card details are collected directly by
Stripe, Inc., our payment processor, under their own privacy policy (stripe.com/privacy). We
retain only Stripe's customer and subscription identifiers, the plan, and payment status.
We do not sell customer personal information, and we do not use it for advertising.
Our lead lists identify businesses and the person who makes marketing decisions at that business
— typically an owner, principal, or marketing director. For each lead we may hold: business name,
category, business address, business phone, business email, website, the decision-maker's name and
job title, whether the business runs trackable digital advertising, and the public sources that
confirmed the name.
Sources. This information is compiled exclusively from public and publicly accessible sources,
including: federal and state professional and business licensing registries (for example the
national NPI registry, state contractor licensing boards, state real estate and care-facility
licence rolls), state business entity filings, businesses' own public websites and staff pages,
public professional profiles, open mapping data, and public directories. We do not buy personal
data from data brokers, and we do not scrape private, password-protected, or paywalled sources.
Basis and purpose. This is business contact information about people acting in a professional
capacity, compiled and supplied for business-to-business sales outreach. Where the law requires a
lawful basis (for example legitimate interests under GDPR-style regimes), our basis is the
legitimate interest of enabling B2B commerce, balanced against the limited privacy impact of
business-role contact details. We do not knowingly collect purely personal or household contact
information, and we do not collect special-category data.
Verification standard. A lead is only delivered when at least two independent public sources
agree on the decision-maker. Recorded sources travel with each lead so any claim can be traced.
Retention. Leads are retained while a territory is active and are periodically re-verified.
Records identified as closed, stale, or unverifiable are removed or quarantined.
ZipScout supplies business contact data; **our customers are solely responsible for how they
contact the businesses on their lists.** Every lead is screened as a business line, and any number
identified as a personal or mobile number is flagged so customers can apply extra caution. We do
not place calls or send messages to leads ourselves. Customers must comply with all applicable
telemarketing and anti-spam law in their jurisdiction, including the US Telephone Consumer
Protection Act and applicable Do-Not-Call rules, and Canada's Anti-Spam Legislation (CASL) for
Canadian contacts. See the Terms of Service for the full contractual allocation of this duty.
If you are a business contact appearing in our data, you may ask us to correct or remove your
information. Email support@zipscout.io from an address at that business, or include enough
detail to identify the record. On a verified request we will delete or correct the record and add
it to a suppression list so it is not re-compiled from the same public sources. We aim to action
these within 30 days, and we do not charge for it.
If you are a customer, you may access, correct, export, or delete your account information by
emailing support@zipscout.io. Some records are kept as long as tax and accounting law requires,
even after account closure.
Depending on where you live you may have additional rights — for example, under the California
Consumer Privacy Act (CCPA/CPRA) the right to know, delete, correct, and to opt out of "sale" or
"sharing" of personal information. **ZipScout does not sell or share customer personal information
as those terms are defined by the CCPA.** Our lead lists consist of business contact information
supplied for B2B purposes; if you believe your information appears and you want it removed, use
the process above. We will not discriminate against anyone for exercising these rights.
We share personal information only with service providers who need it to run the service, under
contract, and only for that purpose:
We may also disclose information where required by law, to enforce our Terms, or in connection
with a merger or sale of the business — in which case this policy continues to apply to the
information transferred.
Data is transmitted over HTTPS and stored on access-restricted servers in the United States.
Passwords are stored only as salted hashes. Administrative actions are recorded in an audit log,
and databases are backed up nightly with a limited retention window. No system is perfectly
secure; we cannot guarantee absolute security, and customers are responsible for keeping their
own login credentials confidential.
ZipScout is operated from the United States and information is processed there. Customers and
business contacts outside the United States should be aware that US law may differ from their
local law.
The service is sold to businesses and is not directed to anyone under 18. We do not knowingly
collect information from children.
We may update this policy. The effective date above will change, and material changes affecting
customers will be notified by email to the account address.
Questions, corrections, or removal requests: support@zipscout.io
ZipScout · zipscout.io
Terms of Service · Questions or removal requests: support@zipscout.io
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.