Privacy Policy
Effective 1 October 2026. This policy explains how The Hashtag Crew, 12515 Barker Cypress Rd, Suite #9305, Cypress, TX 77429 ("we", "us") handles personal data in connection with NectarScout, the website at nectarscout.com and the software service it provides (the "platform").
It covers two groups of people:
- Our customers and their team members, the agencies and businesses that sign up and use the platform. For this data we are the controller: we decide why and how it is used.
- People whose details our customers find or store using the platform, mostly owners and staff of local businesses, and people who contact a customer through a feature such as a website form. For this data our customer is the controller and we process it on their instructions, under our Data Processing Agreement. Section 6 explains what this means for you and how to reach us anyway.
We do not sell personal data. We do not share it for advertising. We do not use it to build profiles of people for anyone other than the customer who collected it.
1. Data about our customers and their team members
What we collect
- Account details: name, work email address, password (stored only as a one-way scrypt hash), role, and the team you belong to.
- Business details: agency name, website, postal address, phone number, logo, brand colours, tax number and payment details you choose to show on your own proposals and invoices.
- Billing records: your plan, what you were charged and when. Card payments are taken by Stripe; we never see or store your full card number.
- Connected services: the mailbox, phone system and AI key details you connect. Passwords and keys are stored encrypted (AES-256-GCM).
- Usage and technical data: sign-in times, the actions you take (for example who changed a setting, who sent an email, who logged a call), the IP address and browser of a request, and error logs.
- What you tell us: support emails, demo requests and feedback.
Why we use it, and our legal basis (the basis matters in the UK, the EU and some other countries)
- To provide the service you signed up for, run your account and take payment: performance of our contract with you.
- To keep the platform secure, prevent abuse and protect the sending reputation all customers share: our legitimate interests, and in some cases a legal obligation.
- To send you service messages (invitations, password resets, security notices, changes to these documents): contract and legitimate interests.
- To answer you and improve the product: legitimate interests.
- To keep financial records and meet tax and legal duties: legal obligation.
We will only send you marketing about our own products where the law allows it, and every such message will let you opt out.
2. Data our customers process using the platform
Customers use the platform to find local businesses and to contact them. On their instruction, the platform may collect and store:
- Business information from public sources: the business name, address, phone number, website, opening hours, category, star rating and number of reviews, as shown on public business listings such as Google Maps and on the business's own website.
- Information from the business's website: text, images, screenshots, the logo and colours, social media links, and the names and job titles of people named on the site (for example "Jane Smith, Owner").
- Contact details published by the business, such as a work email address or phone number.
- What our customer adds: notes, call logs, files, proposals, invoices, and the emails they send and receive.
- Email activity: replies, bounces and unsubscribes. Some follow-up emails sent through the platform can record whether a link was clicked or an image was loaded. A first email is sent as plain text with nothing that tracks it.
- Call information: if a customer connects a phone system, the time, length and direction of calls, and a reference to a recording. Recordings stay with the phone system; we play them on request and do not keep a copy.
- Messages from website visitors: if a customer uses a chat or form feature, what the visitor types and the contact details they choose to leave.
Each customer's data is kept in that customer's own workspace. We do not pool it, share it between customers or sell it. One customer cannot see another customer's prospects.
The customer is responsible for having a lawful reason to collect and use this data and for the messages they send. Our Acceptable Use Policy sets out what they must and must not do.
3. Artificial intelligence
The platform uses AI models to review websites, write audits, design website previews and draft emails. To do this we send the relevant business information and website content to the AI provider that runs the model (see Sub-processors). We send only what the task needs, and only to paid AI services. We do not sell this data, and we do not use it to train AI models of our own. A customer who connects their own AI account uses that account's terms instead.
AI output can be wrong. Customers must check anything generated before they rely on it or send it to anyone.
4. Who we share data with
- Service providers who help us run the platform, such as hosting, email delivery, AI models and payments. They may only use the data to provide their service to us. The current list is on our Sub-processors page.
- Services you connect. When a customer connects their mailbox or phone system, data passes between the platform and that service on the customer's instruction, under the customer's own agreement with that provider.
- The recipients our customers choose. An email, proposal, invoice or website preview a customer sends goes to the person they send it to.
- Our affiliate Spiresol, which collects payments for us through Stripe.
- Authorities and advisers, where the law requires it, to protect our rights or the safety of others, or to our lawyers and accountants under a duty of confidence.
- A buyer or successor, if our business or the platform is sold or reorganised, under the same protections as this policy.
5. Where data is stored, and international transfers
The platform is hosted on Oracle Cloud Infrastructure in the United States. Some service providers may process data in other countries, including the United Kingdom, the European Union and, for some AI models, other countries listed on the Sub-processors page.
When personal data from the UK, the EU or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and equivalent safeguards, as set out in our Data Processing Agreement. Similar safeguards apply to transfers from other countries whose laws require them.
6. If a business found through the platform holds your details
If you work at, own or run a business and received an email, call or website preview from one of our customers, that customer found your business's details using the platform and decides how they are used. The quickest way to stop further contact is to reply to that message and say so, or use the unsubscribe option in your email app. The platform records that and blocks further emails from that customer to your address.
You can also contact us at hello@nectarscout.com. Tell us your email address or business name and, if you can, who contacted you. We will:
- tell you which of our customers hold your details, where the law requires it or we are able to;
- pass your request to them and help them answer it;
- on your request, delete your details from the workspaces that hold them, and block your email address from further contact through the platform, unless a customer has a legal reason to keep them;
within 30 days.
7. How long we keep data
- Your account data: for as long as your account is open. After you close your account, we delete your workspace, including the prospect data in it, within 90 days, except what we must keep for legal, tax or accounting reasons (usually billing records, kept for up to 7 years).
- Do-not-contact records: an email address that has unsubscribed, bounced or asked not to be contacted is kept for as long as the customer's workspace exists, so the request can be honoured.
- Backups: copies of the database are kept for up to 60 days and then deleted.
- Logs: technical and security logs are kept for up to 12 months.
8. How we protect data
- All traffic to the platform is encrypted (HTTPS/TLS).
- Passwords are stored as one-way hashes. Mailbox passwords, AI keys and similar secrets are encrypted.
- Sign-in sessions use secure, HTTP-only cookies that expire.
- Each customer's data is separated by account, and inside a team, access follows each person's role.
- The database is backed up every night, and each backup is checked before it is kept.
- Access to production systems is limited to the people who need it to run the service.
No system is perfectly secure. If a breach affects your personal data, we will tell the affected customers without undue delay, and tell regulators and individuals where the law requires it.
9. Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy;
- correct data that is wrong;
- delete your data;
- object to or restrict how we use it, including for direct marketing (an objection to direct marketing is always honoured);
- move your data to another service (portability);
- withdraw consent where we rely on it;
- not be treated differently for using these rights;
- complain to your data protection regulator.
To use any of these rights, email hello@nectarscout.com. We do not yet have a self-service download or delete button, so we handle requests by email. We will answer within 30 days, or sooner where your local law requires it (for example, India's DPDP Act). We may need to confirm your identity first. Where we process your data for one of our customers, we will pass your request to that customer and help them answer it.
By country
- United Kingdom and European Union (including Ireland, Germany, France, Spain, Italy and the Netherlands): the rights above come from the UK GDPR and EU GDPR. You can complain to the ICO in the UK or your local supervisory authority in the EU.
- United States: residents of California and other states with consumer privacy laws (such as Colorado, Connecticut, Virginia, Texas and others) have the rights to know, delete, correct and opt out. We do not sell or share personal information as those laws define it, and we do not use it for targeted advertising or for profiling that has legal effects. We will not discriminate against you for using your rights. You can use an authorised agent.
- Canada: under PIPEDA you can access and correct your information and complain to the Office of the Privacy Commissioner.
- Australia: under the Privacy Act 1988 you can access and correct your information and complain to the OAIC.
- New Zealand: under the Privacy Act 2020 you can access and correct your information and complain to the Privacy Commissioner.
- South Africa: under POPIA you can access, correct and object, and complain to the Information Regulator.
- India: under the Digital Personal Data Protection Act 2023 you can access, correct and erase your data, nominate someone to act for you, and raise a grievance with us at hello@nectarscout.com before going to the Data Protection Board.
- United Arab Emirates: under the Personal Data Protection Law you can access, correct, erase and object.
- Pakistan: you can ask us to access, correct or delete your data, and we apply the protections in this policy to you as well.
10. Cookies
We use only the cookies needed to sign you in and keep your settings. We use no advertising or analytics cookies. See our Cookie Notice.
11. Children
The platform is for businesses. It is not meant for anyone under 18, and we do not knowingly collect children's data.
12. Changes to this policy
When we change this policy in a way that matters, we will update the date at the top and tell customers by email or in the platform before the change takes effect.
13. Contact
The Hashtag Crew, 12515 Barker Cypress Rd, Suite #9305, Cypress, TX 77429
Email: hello@nectarscout.com