Legal
Privacy Policy
Jurisdictional Coverage: Florida (primary, FIPA and Florida Digital Bill of Rights), California (CCPA / CPRA), EU / UK / EEA (GDPR, future-proofed).
Important Notice — Please Read Carefully
By creating an account, clicking “I Agree,” or otherwise accessing or using the Service, you agree to the data practices described in this Privacy Policy. This policy is incorporated by reference into our Terms of Service.
Introduction and Scope
Scope Techlabs LLC (“Scope,” “we,” “us,” or “our”) operates the Scope Inspect platform (“Service”), a B2B SaaS solution for service businesses. This Privacy Policy describes how we collect, use, share, and protect information in connection with the Service, and explains the rights available to you regarding your data.
This Privacy Policy applies to:
- ·Customers: businesses and organizations subscribing to and accessing the Service
- ·Authorized Users: employees, contractors, and agents of Customers who use the Service
- ·End Recipients: individuals who receive SMS or other communications transmitted through the Service on behalf of a Customer (for example, homeowners and other property owners receiving service-appointment messages from a service business using Scope as its messaging platform)
- ·Visitors: individuals who visit our website or contact us directly
This Privacy Policy is incorporated by reference into our Terms of Service. By using the Service, you agree to the data practices described in this Privacy Policy.
Information We Collect
2.1 Information You Provide. We collect information you provide directly, including:
Account and Registration Data: name, email address, company name, job title, phone number (including mobile number where provided for SMS-based notifications), and account credentials.
Subscription and Billing Data: billing address and subscription tier. Payment card information is processed directly by our third-party payment processors (Stripe, Helcim) and is not stored by Scope.
Customer Data: service reports, photographs, video recordings, customer records, job records, business operational data, and all other content you upload or create through the Service.
Communications Data: information you provide when contacting our support team, submitting feedback, or communicating with us by email, SMS, or through the Platform.
SMS and Mobile Messaging Data: where you provide a mobile phone number and opt in to SMS communications, we collect the mobile number, the date and method of opt-in (web form submission, in-app toggle, or replied keyword such as START), keyword history (STOP, HELP, START, UNSTOP), delivery and engagement metadata, and the campaign or message category associated with each communication. SMS opt-in is voluntary and is not a condition of subscribing to or using the Service.
2.2 Information Collected Automatically. When you access or use the Service, we automatically collect:
Log Data: IP addresses, browser type and version, operating system, device type and identifiers, pages accessed, actions taken, access timestamps, and referring URLs.
Usage Data: feature usage patterns, session duration, interaction data, and engagement metrics.
Cookie and Tracking Data: data collected through cookies and similar tracking technologies as described in Section 6.
2.3 Information from Third Parties. We may receive information about you from:
- ·Payment processors (Stripe, Helcim): transaction confirmation and payment verification data
- ·Integration partners: data from third-party tools you connect to the Platform
- ·Publicly available sources: business contact information for account verification
2.4 Information Submitted by Customers About End Recipients (Platform Messaging). When a Customer uses the Service to send SMS or other messages to its own end consumers (for example, a service business sending service-appointment confirmations to homeowners), the Customer submits to Scope the mobile numbers, names, and message content needed to deliver those communications. Scope processes this information as a service provider on behalf of the Customer, solely to deliver, monitor, and log the requested messages. The Customer is the controller of, and is responsible for, the lawful collection and use of this information, including obtaining valid prior express consent (or, for marketing, prior express written consent) from each end recipient under the Telephone Consumer Protection Act (TCPA) and applicable carrier and CTIA requirements.
How We Use Your Information
We use the information we collect for the following purposes.
3.1 Service Delivery. We use your information to provide and operate the Service, including:
- ·Provide, maintain, operate, and improve the Service
- ·Process subscription payments and manage billing
- ·Authenticate users and maintain account security
- ·Deliver AI-powered features: report generation, workflow automation, and business insights
3.2 AI Data Processing
AI Processing Disclosure — Customer Data may be processed by Scope’s AI systems to generate service reports, automate field workflows, and produce business insights. Customer Data is NOT used to train shared or publicly available AI models without your prior written consent. Customer Data may be routed through third-party AI infrastructure providers solely to deliver AI Features. Currently, AI Features are powered by OpenAI, L.L.C.’s API. Under OpenAI’s API data usage policy (effective March 1, 2023), Customer Data submitted to OpenAI through the API is not used to train OpenAI’s foundation models. If Scope changes or adds AI providers in a way that materially affects this disclosure, this Privacy Policy will be updated under Section 13. All AI-generated outputs require review and validation by you. Scope is not responsible for decisions made based on AI outputs without independent verification.
3.3 Service Operations. We use your information for the following operational purposes:
- ·Communicate with you about your account, subscriptions, and service updates
- ·Provide customer support and respond to inquiries
- ·Send service-related notifications and promotional communications. You may opt out at any time
3.4 Product Development and Analytics. We use aggregated and de-identified data to improve the Service, including:
- ·Analyze usage patterns and feature engagement to improve the Service
- ·Develop new features using aggregate, de-identified data
3.5 Legal and Compliance. We process information as required to comply with applicable legal obligations:
- ·Comply with applicable laws, including FIPA breach notification obligations
- ·Respond to legal process, court orders, and lawful government requests
- ·Maintain records for audit, tax, and legal defense purposes
3.6 SMS and Text Message Communications (Scope-Originated)
SMS Program Disclosure, Scope-Originated Messages — Where you provide a mobile phone number and affirmatively opt in, we use your mobile number to send SMS or text messages relating to the Service.
Categories of SMS communications:
- ·Account verification and security codes (one-time passcodes)
- ·Account, billing, and subscription notifications
- ·Service status updates, outage alerts, and security advisories
- ·Customer support communications
- ·Product updates and feature announcements (where separately opted in)
Message frequency. Up to fifteen (15) transactional messages per active user per month. Promotional messages, where separately opted in, are capped at four (4) per user per month.
Carrier charges. Message and data rates from your wireless carrier may apply. Scope is not responsible for any wireless carrier charges incurred from receipt of SMS messages.
Opt-out. Reply STOP to any SMS from Scope to opt out at any time. After opt-out, Scope will send a single confirmation message and will not send further SMS to that number unless and until you re-opt in.
Help. Reply HELP to any SMS for assistance, or contact us at support@scopeinspect.io.
Carrier non-liability. Wireless carriers are not liable for delayed or undelivered messages.
3.7 Platform Messaging Originated by Customers (ISV / Reseller). Scope Techlabs LLC is registered as an Independent Software Vendor (ISV) Reseller with messaging service providers (including Twilio) and provides Customers with the technical infrastructure to send SMS communications to their own end recipients.
When a Customer uses this platform functionality:
- ·The Customer is the sender of record and the data controller for recipient information
- ·Scope acts as the messaging platform and service provider on the Customer's behalf
- ·Scope processes recipient mobile numbers and message content solely to deliver, monitor, and log the Customer's communications, and to provide related analytics to the Customer
- ·The Customer is solely responsible for obtaining valid prior express consent (and, for marketing content, prior express written consent) from each end recipient under TCPA, CTIA, and applicable carrier requirements before sending any SMS through the Service
- ·Scope does not use end-recipient mobile information for any purpose other than delivering the Customer's requested communications
End-recipient message profile (platform messaging):
- ·Categories: service-appointment scheduling, confirmations, reminders, day-of arrival updates, post-visit follow-up, service report delivery, and (where the end recipient has separately opted in) promotional offers from the Customer
- ·Frequency: up to twenty (20) messages per appointment cycle and up to four (4) promotional messages per end recipient per month
- ·Carrier charges: message and data rates from the recipient's wireless carrier may apply
- ·Opt-out: end recipients may reply STOP to any platform SMS to opt out of further messaging from the originating Customer. Scope automatically honors STOP requests across the platform
- ·Help: end recipients may reply HELP for assistance or contact the originating Customer directly using the contact information provided in messages
Legal Basis for Processing (GDPR)
Applies to: EU / UK / EEA Users
For EU / UK / EEA users, we process personal data on the following lawful bases under Article 6 GDPR:
| Lawful Basis | GDPR Reference | Processing Activities |
|---|---|---|
| Contract Performance | Art. 6(1)(b) | Providing the Service, managing subscriptions, fulfilling Terms of Service obligations |
| Legitimate Interests | Art. 6(1)(f) | Analytics, product improvement, security monitoring, fraud prevention, enforcing legal rights |
| Legal Obligation | Art. 6(1)(c) | Complying with FIPA, financial record retention, legal process responses |
| Consent | Art. 6(1)(a) | Marketing communications and SMS opt-in. Withdrawable at any time without affecting prior processing |
How We Share Your Information
We do not sell your personal data. We share information only in the circumstances described below.
5.1 Service Providers and Processors. We share information with the following third-party providers who process data on our behalf:
| Category | Provider | Purpose |
|---|---|---|
| Payment Processors | Stripe, Inc.; Helcim Inc. | Payment processing and billing |
| Cloud Infrastructure | Amazon Web Services, Inc. (AWS) | Data storage and hosting |
| Website and Product Analytics | Google LLC (Google Analytics 4) | Traffic measurement, feature usage analysis, and product improvement |
| AI Infrastructure | OpenAI, L.L.C. | Powering AI Features (report generation, workflow automation, business insights) |
| SMS / Messaging | Twilio Inc. | SMS delivery, A2P 10DLC campaign routing, opt-in and opt-out logging |
We share only the minimum data necessary for each provider to perform its function. Customer support is provided directly by Scope via email at support@scopeinspect.io. No third-party support, ticketing, or live-chat tool processes customer support communications at this time.
5.2 Legal Requirements. We may disclose information when required by law, court order, or lawful government request, or to protect the safety, rights, or property of Scope, our users, or the public.
5.3 Business Transfers. In connection with a merger, acquisition, or sale of substantially all of Scope’s assets, Customer Data may be transferred to the successor entity under the same privacy protections.
5.4 With Your Consent. We may share information in other circumstances with your prior written consent.
5.5 Mobile Information Sharing. No mobile information collected for SMS or text messaging purposes (including mobile phone numbers, opt-in records, and consent data) will be shared with third parties or affiliates for marketing or promotional purposes. Mobile information will be disclosed only to subcontractors and service providers acting on our behalf to deliver the Service (for example, the SMS gateway provider, customer support tooling, and billing platforms), and only to the extent necessary to deliver the requested communications. All other categories of data described in this Privacy Policy exclude text messaging originator opt-in data and consent. This opt-in information will not be shared with any third parties. For end-user-facing details on how SMS notifications work and how to opt out, see our SMS Notifications Opt-In Statement.
Cookies and Tracking Technologies
Cookies are small text files placed on your device when you access the Service. We also use local storage, session tokens, and web analytics beacons.
6.1 Essential Cookies (Required). Strictly necessary for the Service to function. Cannot be disabled without preventing Service access.
- ·Session tokens: maintain authenticated sessions
- ·Security cookies: CSRF protection and fraud prevention
- ·Load balancing cookies: server routing
6.2 Analytics Cookies. Used to understand how users interact with the Service and improve functionality.
- ·Google Analytics 4 cookies (Google LLC), including _ga, _ga_<container-id>, and Google Tag Manager identifiers: traffic measurement, feature usage analysis, and session reporting
- ·Performance monitoring: page load times and error rate tracking
You may disable analytics cookies in your browser settings without affecting Service access. To opt out of Google Analytics globally, install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
6.3 Cookie Management. Manage cookie preferences through your browser settings. Disabling essential cookies will prevent Service access.
6.4 EU / UK / EEA Cookie Notice
GDPR / ePRIVACY Notice
6.5 Do Not Track. We do not currently respond to browser “Do Not Track” (DNT) signals, as no uniform industry standard exists. We will revisit this policy as standards develop.
Data Retention
7.1 Active Subscriptions. We retain Customer Data for the full duration of your active subscription.
7.2 Post-Termination Retention Schedule
| Period | Treatment |
|---|---|
| 30-Day Export Window | Customer Data retained for 30 days post-termination. You may request a data export during this period (where supported) |
| 7-Year Retention Period | Following the export window, Customer Data is retained for 7 years from the date of termination or expiration |
| Log and Analytics Data | Server log data retained up to 12 months. Aggregate de-identified analytics data may be retained indefinitely |
| SMS Opt-In Records | Retained for the longer of (a) the duration of the active subscription, (b) two (2) years following the last SMS message sent to the user, or (c) any period required by applicable law (e.g., TCPA defense purposes), in each case to evidence consent |
7.3 Basis for 7-Year Retention. The extended retention period is maintained for the following reasons:
- ·Audit, tax, and financial compliance record-keeping
- ·Legal defense in connection with professional liability claims related to service records
- ·Applicable legal and regulatory record-keeping obligations
7.4 Deletion Rights and Carve-Outs. You may request deletion of your personal data at any time (Section 9). We will honor deletion requests except where retention is:
- ·Required by applicable law or regulation
- ·Necessary for the establishment, exercise, or defense of legal claims
- ·Required to complete outstanding transactions or contractual obligations
- ·Necessary for financial, audit, or tax record-keeping
- ·Necessary to evidence SMS consent for TCPA defense (records will be retained in a restricted, non-marketing form)
Data Security
Scope implements commercially reasonable technical and organizational security measures, including:
- ·Encryption of data in transit (TLS) and at rest
- ·Access controls, role-based permissions, and multi-factor authentication
- ·Regular security monitoring, vulnerability assessments, and penetration testing
- ·Employee training on data security and privacy practices
- ·Contractual security obligations for all third-party processors
No security system is impenetrable. We cannot guarantee that Customer Data will never be accessed or disclosed by unauthorized parties.
8.1 Data Breach Notification
Florida FIPA Commitment — 30-Day Notification
Your Privacy Rights
9.1 General Rights — All Users. Contact support@scopeinspect.io to exercise any of these rights. We will respond within 45 days.
| Right | Description |
|---|---|
| Access | Request a copy of personal data we hold about you and how it is used |
| Correction | Request correction of inaccurate or incomplete personal data |
| Deletion | Request deletion of personal data (subject to Section 7.4 carve-outs) |
| Data Export | Request export of Customer Data in a usable format (where technically supported) |
| Opt-Out of Marketing Email | Unsubscribe from promotional email at any time via the unsubscribe link or by contacting support@scopeinspect.io |
| Opt-Out of SMS | Reply STOP to any SMS from Scope to unsubscribe immediately. Email requests are also accepted at support@scopeinspect.io |
9.2 California Residents — CCPA / CPRA
Applies to: California Residents
Right to Know: Request disclosure of categories and specific pieces of personal information collected, sources, business purposes, and third-party sharing.
Right to Delete: Request deletion of personal information collected, subject to the carve-outs in Section 7.4.
Right to Correct: Request correction of inaccurate personal information.
Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. Contact support@scopeinspect.io to confirm.
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
Categories of personal information collected in the last 12 months:
- ·Identifiers: name, email address, IP address, account credentials, mobile phone number (for opted-in SMS users)
- ·Commercial information: subscription records, transaction history
- ·Internet or electronic network activity: log data, usage data, cookie data
- ·Professional or employment-related information: job title, company name
- ·Customer-generated content: service reports, photographs, videos, customer records, business operational data
- ·SMS / messaging data: opt-in records, keyword history, delivery metadata
To submit a CCPA request, contact support@scopeinspect.io. We will verify your identity before processing. Authorized agents may submit requests with written authorization.
9.3 EU / UK / EEA Residents — GDPR
Applies to: EU / UK / EEA Residents
| Right | Article | Description |
|---|---|---|
| Right of Access | Art. 15 | Obtain confirmation of processing and a copy of your personal data |
| Right to Rectification | Art. 16 | Request correction of inaccurate or incomplete data |
| Right to Erasure | Art. 17 | Request deletion where data is no longer needed, consent is withdrawn, or processing was unlawful (subject to Section 7.4) |
| Right to Restriction | Art. 18 | Request limitation of processing in certain circumstances |
| Right to Portability | Art. 20 | Receive personal data in a structured, machine-readable format (where technically feasible) |
| Right to Object | Art. 21 | Object to processing based on legitimate interests or for direct marketing |
| Automated Decision-Making | Art. 22 | Not be subject to solely automated decisions producing significant legal effects, unless necessary for contract or consented to |
To exercise GDPR rights, contact support@scopeinspect.io. We respond within 30 days (extendable to 60 with notice). You may also lodge a complaint with your local data protection supervisory authority.
International Data Transfers
Scope is headquartered in the United States. Customer Data is stored and processed in the US on AWS infrastructure. For users in the EU, UK, or EEA, your personal data will be transferred to and processed in the United States.
10.1 Transfer Mechanisms. We rely on the following legal mechanisms for international data transfers:
- ·EU Standard Contractual Clauses (SCCs): European Commission-approved clauses for EU / EEA to US transfers
- ·UK International Data Transfer Agreement (IDTA): For transfers from the United Kingdom
- ·EU-US Data Privacy Framework (DPF): Where applicable, upon Scope's DPF certification
We apply the same security and data protection standards to all Customer Data regardless of processing location.
Children's Privacy
The Service is intended exclusively for business entities and their authorized representatives. We do not knowingly collect personal information from individuals under 13. If we discover we have collected such information, we will delete it promptly. Contact support@scopeinspect.io if you believe we have inadvertently collected information from a child under 13.
Third-Party Links and Services
The Service may contain links to third-party websites, tools, or services. This Privacy Policy does not apply to third-party privacy practices. We encourage you to review the privacy policies of any third-party services you access. Scope is not responsible for the privacy practices or content of any third-party service.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days’ advance notice via:
- ·Email to the address associated with your account
- ·In-app notification when you access the Service
Your continued use of the Service after the effective date constitutes acceptance of the updated policy. A version history is maintained at scopeinspect.io/privacy.
Contact Us
For privacy-related questions, rights requests, data breach reports, or concerns about our data practices:
| Company | Scope Techlabs LLC |
| Privacy Email | support@scopeinspect.io |
| Website | https://www.scopeinspect.io |
| Privacy Policy | https://www.scopeinspect.io/privacy |
| Terms of Service | https://www.scopeinspect.io/terms |
Change Log
| Version | Date | Summary |
|---|---|---|
| 1.0 | March 19, 2026 | Initial publication |
| 1.1 | May 13, 2026 | Added SMS / A2P 10DLC disclosures (Sections 2.1, 2.4, 3.6, 3.7, 5.5, 7.2, 7.4, 9.1, 9.2). Named sub-processors in Service Providers table (Stripe, Helcim, AWS, Google LLC, OpenAI, Twilio). Removed Customer Support row (support is direct email at support@scopeinspect.io). Added Google Analytics 4 cookie names and opt-out instructions (Section 6.2). Named OpenAI in AI Data Processing with confirmation that OpenAI does not train on API data (Section 3.2). Contact email updated to support@scopeinspect.io and live URLs published. Terminology broadened from inspection-specific to universal service-business: "inspection company" → "service business"; "inspection report" → "service report"; "inspection appointment" → "service appointment"; "inspection records" → "service records". Product name "Scope Inspect" retained. |