1. Scope of this policy
This Privacy Policy explains how the operator of Corp Code Scout (“we”, “us”) handles personal information in connection with the Corp Code Scout website, application, and related services (the “Service”). It applies to visitors, prospective invitees, account holders, administrators, trial users, and members.
It forms part of our Terms of Service. Words defined there have the same meaning here.
The Service is operated from British Columbia, Canada, and is available internationally. We handle personal information under applicable Canadian federal and provincial privacy laws, including British Columbia’s Personal Information Protection Act (PIPA) and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and, where they apply to you, the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended (CCPA/CPRA).
2. Information we collect
We deliberately collect little. We do not use personal information for advertising and have not added third-party product analytics, tracking pixels, or cross-site tracking to the Service.
Invite request information, when you ask for access before sign-in:
- your name and Google account email address;
- your company, role, and the benchmarking use case you describe;
- security-verification and technical information processed by Cloudflare to prevent automated abuse; and
- the request notification and delivery information held by Resend and our published mailbox providers.
Invitation information, created before sign-in when an administrator invites you:
- the email address the invitation is tied to;
- an internal invitation record and its pending status;
- the dates the invitation record was created and last updated; and
- email delivery information held by Resend when we send the invitation.
Account information, added to or updated on that invitation record when you sign in with Google:
- an internal account identifier we generate;
- an authentication identifier from Amazon Cognito, which links your sign-in to your account;
- your email address;
- your display name, only when your identity provider supplies one;
- your account role, which is either standard user or administrator;
- the date and time you accepted the Terms;
- whether an administrator made your account eligible for complimentary Member checkout; and
- the dates your account record was created and last updated.
We do not receive or store your Google password. We do not collect your contacts, calendar, files, or any other Google data beyond the basic profile and email address needed to create your account.
Search information, created when you use the Service:
- the destination, travel dates, hotel groups, and other inputs you choose for a search;
- the results of that search, including hotels, rates, corporate codes, and comparisons;
- the run’s status, progress, timing, and diagnostic information used to operate and debug the Service.
Membership information, if you start a Stripe membership or receive Member access from an administrator:
- your plan, membership status, whether access came from Stripe or an administrator, and current billing-period dates;
- whether cancellation is scheduled and when Stripe was last synchronized;
- the Stripe customer and subscription identifiers for your account;
- your search allowance, how much of it you have used, and the associated accounting timestamps; and
- whether and when we sent the one-time membership activation email.
Stripe’s hosted checkout collects and retains your billing address, phone number, and payment details on our behalf. Stripe sends us customer and subscription identifiers and billing-status information, but we do not receive or store your full card number, expiry date, or security code in our database.
Technical information, collected automatically by our hosting and infrastructure providers as part of delivering the Service: IP address, IP-derived country, browser and device characteristics, requested pages, timestamps, and error diagnostics. We use the country signal to choose the regional default currency and membership price, and use the other technical information for security, abuse prevention, and troubleshooting.
Bug reports and error information, when you submit a report or the Service encounters an error: your account identifier, email address, display name, the page where the problem occurred, browser and device context, error details and stack traces, the description you submit, and any optional image or video attachments you choose to upload. Attachments can include personal or sensitive information, so review each file before submitting it.
Correspondence, when you email us: your email address, any name or signature you include, the message and attachments you send, and our related response records.
3. How we use information
We use personal information to:
- review invite requests and communicate with prospective invitees;
- create, send, and manage invitations and transactional membership emails;
- create and secure your account and authenticate your sign-in;
- run the searches you request and show you their results and history;
- apply and enforce trial allowances, membership limits, and fair-use limits;
- process membership payments and manage renewals and cancellations through Stripe;
- operate, maintain, debug, and improve the reliability and accuracy of the Service;
- detect, investigate, and prevent abuse, fraud, and security incidents;
- receive, investigate, and respond to bug reports and application errors;
- respond to your support, privacy, and legal requests; and
- comply with legal obligations and enforce our Terms.
We do not sell or share personal information for cross-context behavioural advertising, as those terms are used in the CCPA/CPRA. We do not use your searches or results to build advertising profiles, and we do not use your personal information to train machine-learning models.
We may produce aggregated or de-identified statistics about how the Service is used, including rate-coverage and performance measures. Such information no longer identifies you, and we do not attempt to re-identify it.
4. Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
- performance of a contract, to give you the account, searches, results, and membership you asked for;
- our legitimate interests, to manage invitation-only access, send transactional emails, keep the Service secure, prevent abuse, debug problems, and improve the product, balanced against your rights;
- compliance with a legal obligation, for tax, accounting, and lawful requests; and
- your consent, where we ask for it — which you may withdraw at any time without affecting processing already carried out.
Where PIPEDA applies, we collect, use, and disclose personal information with your knowledge and consent, for the purposes set out in this policy, except where the law permits or requires otherwise.
5. Service providers and disclosure
We do not sell personal information. We disclose it only as needed to operate the Service. Providers acting on our behalf are governed by applicable contractual terms; providers you interact with directly may also process information under their own terms and privacy policies:
- Google — sign-in, when you choose to authenticate with a Google account;
- Amazon Web Services, including Amazon Cognito — authentication, application hosting, and the infrastructure that performs searches;
- Cloudflare — DNS, traffic delivery, Turnstile security verification, abuse prevention, and network-error reporting for public web requests;
- Vercel — web application hosting and delivery;
- Neon — the managed Postgres database that stores account, membership, and search records;
- Sentry — application and search-infrastructure error monitoring, operational diagnostics, and user-submitted bug reports, including optional user-uploaded image or video attachments;
- Resend — delivery of invite-request notifications, invitations, and membership emails, including the recipient address and message content;
- Lark Suite — hosting the published support and privacy mailbox and the invite requests and correspondence sent to it;
- Stripe — payment processing, subscription billing, and membership management;
- Frankfurter — reference exchange-rate data requested by our server. We do not include account or search information in those requests; and
- OpenFreeMap — the map tiles rendered in result maps. Your browser requests these tiles directly, so that provider receives your IP address and the map area you view.
Sentry processes this information under its Privacy Policy. We use Sentry for error monitoring and bug reports, not for analytics or session replay.
To perform a search, our infrastructure sends the selected destination, dates, hotel properties, and corporate-rate queries to supported hotel websites and rate systems. We do not include your account name, email address, or account identifier in those hotel requests. Those providers receive technical requests from our search infrastructure and apply their own terms and privacy practices.
When you follow an outbound link to a hotel website, that hotel receives your request directly and its own privacy practices apply. We do not send it your account information.
We may also disclose personal information where we reasonably believe it is required to comply with law or a valid legal process, to enforce our Terms, or to protect the rights, safety, or property of users, the public, or us. If the Service is involved in a merger, financing, acquisition, or sale of assets, personal information may be transferred as part of that transaction, and we will require the recipient to honour this policy or give notice of any material change.
6. International transfers
We operate from Canada, and our providers process personal information in Canada, the United States, and other countries. Those countries may have different data-protection laws than your own, and personal information may be accessible to courts, law enforcement, and national security authorities there under their local law.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one covers the transfer, or on standard contractual clauses with appropriate safeguards.
8. How long we keep information
- Invite requests: the Resend delivery record is available for 30 days under Resend’s standard retention; the mailbox copy is kept for as long as needed to review and respond to the request, then deleted when it is no longer required.
- Pending invitations: until the invitation is revoked, the account is created, or the pending record is deleted.
- Account records: for as long as your account exists. When an account-deletion request is completed, the account is removed from the active database immediately; limited copies may remain in routine provider backups and restore history until their configured recovery windows expire.
- Search inputs, results, and history: kept while your account exists. If you delete a search, it is immediately removed from your history, but the underlying search and results are retained until your account is permanently deleted.
- Membership records in our database: kept with your account and removed from the active database when the account is permanently deleted, unless we must retain a record to meet a legal obligation. Stripe applies its own retention to billing and payment records it holds.
- Application errors and user-submitted bug reports held by Sentry: available to us for 30 days under our current Sentry configuration.
- Invitation and membership email records held by Resend: available for 30 days under Resend’s standard retention.
- Support, privacy, and legal correspondence: kept for as long as needed to resolve the request and meet any related legal obligation, then deleted when it is no longer required.
- Technical and security logs in systems we configure: generally up to 30 days, or longer where needed to investigate a specific incident. Infrastructure providers may apply their own limited retention to records they control.
We may keep information longer where a legal obligation, dispute, or investigation requires it, and will delete it once that need ends.
9. Security
We use measures appropriate to the sensitivity of the information, including encryption in transit, authentication tokens stored in cookies that scripts on the page cannot read, access controls that scope searches and results to the account that created them, managed infrastructure with security patching, and least-privilege access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the relevant regulator as required by law.
10. Your privacy rights
Subject to your local law, you may ask us to:
- confirm whether we hold personal information about you, and give you access to it;
- correct information that is inaccurate or incomplete;
- delete your account and the personal information associated with it;
- give you a copy of the information you provided in a portable format;
- restrict or object to certain processing, including processing based on our legitimate interests;
- withdraw a consent you previously gave; and
- know the categories of personal information we collect, the purposes, and the categories of recipients.
To exercise any of these, email admin@corpcodescout.com from the address on your account, or tell us enough for us to verify your identity. We aim to respond within 30 days and always within the period required by applicable law. If the law permits an extension, we will explain the reason and the new deadline. We do not reduce your service for making a request and normally do not charge a fee.
You also have the right to complain to a regulator: the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, your EU member-state supervisory authority, the UK Information Commissioner’s Office, or the California Privacy Protection Agency, as applicable. We would appreciate the chance to address your concern first.
11. Children
The Service is a professional tool intended for adults. It is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Automated decision-making
We do not use your personal information to make automated decisions producing legal or similarly significant effects about you. Search results are computed from live hotel rate data, not from a profile of you.
13. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date and, where the change materially affects how we handle your personal information, we will give additional notice such as an email or an in-app notice before it takes effect.
14. Contact
For questions about this policy, to exercise a privacy right, or to report a concern, email admin@corpcodescout.com. This address reaches the person accountable for personal information handled by the Service, and we aim to respond within a reasonable time.