Legal

Privacy Policy

Last updated August 14, 2026

StayScoped (“we”, “us”) provides software that helps client-facing teams turn client scope changes into priced, documented Change Requests. This policy explains what data we process to run that service.

Data we process

  • Name and email of the account owner
  • Team / company name
  • Client contact information you enter (name, email)
  • Project information and Change Request content you enter
  • Approval history (who approved or declined, when, and why)
  • Billing metadata (plan, subscription status; payment details are handled directly by Stripe)
  • Timestamps for account and Change Request activity
  • Authentication data (via Supabase Auth)
  • Operational security data (e.g. request logs) used to keep the service reliable and secure

Why we process it

This data is processed to operate the core product: creating, sending, and recording approvals for Change Requests, authenticating your account, and billing your subscription.

Who can see client-facing content

A Change Request's approval page is reachable only via a unique, unguessable link. We do not index these pages or share their content with anyone other than the team that created the Change Request and the client it was sent to.

Third-party processors

  • Supabase - database, authentication
  • Stripe - billing and payment processing
  • Resend - transactional email delivery
  • Vercel - application hosting

Contact

Questions about this policy can be sent to the email address listed on your StayScoped invoice or account.