Server-only secrets
OpenAI, Stripe, Resend, and Supabase service credentials stay in server environment variables and are not shipped in the public widget.
Security and data handling
This is a practical account of the controls Scoutform uses today. Scoutform does not currently claim SOC 2 or ISO 27001 certification.
OpenAI, Stripe, Resend, and Supabase service credentials stay in server environment variables and are not shipped in the public widget.
Supabase authentication identifies account owners. Row-level security policies restrict customer-facing database access to owned business records.
Public and authenticated API routes validate input, restrict payload size, and rate-limit repeated requests. Stripe webhook signatures are verified.
Business answers use retrieved knowledge sources. Internal source metadata is stored with assistant messages so responses can be reviewed.
Stripe hosts checkout and billing management. Scoutform stores subscription identifiers and status, not customer card numbers.
Security or privacy concerns can be reported directly to hcook.24@wymcol.org. Reports are reviewed manually.
Data lifecycle
Account, business, knowledge, chat, and lead records are retained while they are needed to provide the service or until the account owner removes them or requests deletion.
Some billing, fraud-prevention, backup, or operational records may remain for a reasonable period where required for legal, accounting, security, or service-recovery purposes.
To request access, correction, export, restriction, or deletion, email hcook.24@wymcol.org.
Service providers
Supabase
Authentication, PostgreSQL data storage, and vector retrieval
OpenAI
Embeddings and grounded assistant responses
Stripe
Checkout, subscriptions, invoices, and billing portal
Resend
Lead and contact notification email delivery
Vercel
Application hosting, server functions, and optional consented analytics
Responsible use
Businesses remain responsible for checking important prices, availability, regulated advice, and claims before relying on AI-generated responses.
Scoutform should not be used to collect unnecessary sensitive data or provide emergency, medical, legal, or financial decisions without appropriate human review.
See the privacy policy and terms of service for the broader data and acceptable-use position.
Help us measure what works
Scoutform can use optional traffic analytics and ad pixels to measure page views and contact conversions. You can reject them and still use the site.
Privacy policy