Scope
Public website
The marketing website is static and uses Plausible Analytics when production analytics is configured. The same aggregate analytics may run on Scout notice detail, sign-in and sign-up pages; it does not run on Scout search, buyer, account, workspace, settings, billing, verification or recovery pages. The Winston launch-notification form sends an e-mail address and page source to a narrowly scoped public Scout API endpoint; Cloudflare Turnstile checks that form for automated abuse.
Scout accounts
Scout stores account and user records such as e-mail address, first and last name, optional company, display name, account membership, role, settings and, for local accounts, a password hash. After a local account is verified, those registration details are also held in Winston's Microsoft Dataverse customer relationship system.
Procurement records
Scout stores public procurement records from active sources, keeps raw payloads, and normalises notices, buyers, suppliers, contracts and related source identifiers.
Personal and account data
Scout stores the data it needs to provide accounts, authentication, billing, entitlements and supplier workflow. Public procurement records are kept separately from user and customer-account records.
- Your e-mail address, first and last name, optional company, display name, sign-in status, last sign-in timestamp and account settings.
- Local-account password hashes, or Microsoft Entra provider identifiers when that sign-in path is used.
- Hashed, single-use e-mail-verification and password-reset tokens, their purpose and expiry. Raw link secrets are not stored.
- Customer account name, billing e-mail where set, account membership, role and subscription state.
- Saved searches, buyer follows, favourite state, account profile industries, tags, notes and notice activity that members create in Scout.
- CSV export usage records used to enforce the monthly export allowance.
- Search usage records: which Scout surface ran a search, when, how many rows it matched, and whether it used an included search or a prepaid credit. Each record holds a one-way cryptographic fingerprint of the search criteria so repeated searches can be told apart from new ones. Winston does not store what you searched for beyond the 24 hours the result set stays open.
- Allow-listed product events recording that a defined action happened - a first successful search, a saved search, a buyer follow, a tag or note, a CSV export, reaching or exhausting the daily search allowance, and credit checkout start, completion or failure - with your account identifiers, a timestamp, a single coarse number and an outcome. These events cannot contain search text, e-mail addresses, note or tag content, tokens or documents.
- Prepaid search-credit purchases and an append-only credit ledger: bundle, quantity, amount, currency, status, timestamps and the payment provider's own references. Winston does not store card details.
- Billing customer and subscription references returned by Stripe if a separate paid arrangement applies.
- Alert and contact e-mail content needed to send messages you request or receive through Scout and the public contact route.
- A Winston launch-notification e-mail address, signup source, confirmation and withdrawal timestamps, delivery timestamp and opaque management token. No IP address or user-agent is stored with this request.
How the data is used
Winston Intelligence uses the data described here to run Scout, communicate about Scout and keep procurement evidence inspectable. The public site does not share Scout authentication; only the launch-notification form calls its dedicated public API endpoint.
Measure public acquisition
Plausible provides aggregate page-view, referral, campaign, conversion-click and yes-or-no usefulness reporting on the marketing website. On Scout it provides only page views and referral attribution for notice detail, sign-in and sign-up, so Winston Intelligence can see which public pages lead people towards Scout without measuring their activity inside the product.
Provide Scout
Account, membership, saved-search, buyer-follow, export and workflow records let Scout sign users in, show the right account context and enforce plan limits.
Manage the customer relationship
After you verify a local Scout registration, Winston copies the first name, last name, e-mail address and optional company entered at sign-up into Microsoft Dataverse as a CRM contact. Dataverse is a downstream business record, not the source of your Scout identity, and a Dataverse outage does not block registration or verification. Closing your Scout identity queues deletion of that CRM contact.
Protect public forms
Cloudflare Turnstile runs on the Winston launch-notification and Scout registration forms. It evaluates browser and network signals, returns a short-lived single-use token, and tells Winston only whether that token is valid for the expected hostname and action. Winston does not store the token, enable Turnstile pre-clearance or use it for advertising.
Send account e-mail
Account verification, password recovery and Scout Free alert digests are sent by Azure Communication Services Email when configured. Contact messages use the public e-mail address rather than an in-site form.
Send one Winston launch message
If you make and confirm the separate request, Azure Communication Services Email sends the confirmation and the one eventual Winston launch message. This consent is not used for a newsletter, Scout alerts or account registration.
Meter Scout searches fairly
Search usage records let Scout apply the included daily search allowance, keep paging through one set of results free, and refuse a search honestly when the allowance is spent. The records identify a search by a cryptographic fingerprint of its criteria, never by its text.
Improve the product
Allow-listed product events show, in aggregate, which parts of Scout people reach and where the search allowance and export allowance actually bind. They are reviewed as product measurements, are never used for advertising or profiling, and never trigger sales contact on their own.
Operate billing
Scout has no subscription checkout. Prepaid search credits are bought through a one-time payment with Stripe, which processes the payment method, calculates the tax and issues the receipt or VAT invoice; Winston stores only the provider references and the credit ledger needed to apply and support them.
Keep procurement evidence separate
Raw source payloads, normalised fields and generated summaries are stored separately. AI-generated summaries are labelled and kept as generated insight.
Cookies and analytics
Analytics is enabled only for a deliberately configured site hostname. It measures aggregate public acquisition without sharing Scout authentication, session or workspace data. Marketing and Scout use one Plausible site so a same-session journey from the public website to an approved Scout page can retain its original referrer; reporting remains aggregate and can be separated by hostname.
Marketing website
When configured, the public site sends page paths, event times, referral and supported campaign information, browser and device categories, approximate location, named conversion clicks, and whether a visitor marked a page useful or not useful to Plausible Analytics. The prompt sends no free text or contact details and stores no response in the browser. Plausible does not set cookies or persistent identifiers, stores no raw IP address or full user-agent value, and processes visitor data in the EU. The public site has no contact-form cookie.
Scout public pages
When separately enabled on the exact production Scout hostname, the same Plausible site receives a page view from notice detail, sign-in and sign-up pages only. Scout removes the whole query string and page fragment before every report, including campaign parameters and any return destination, token or search criteria. It also reduces the referring URL to its origin, so no referring path, query or fragment is sent. Plausible receives the Scout hostname and public page path, event time, referring site, browser and device category and approximate location. It receives no Scout e-mail address, account or workspace identifier, authentication token, session-cookie value, search criteria or in-product event. Scout does not load Plausible's general-purpose browser tracker, so automatic page-view, form, link, download and engagement capture cannot continue into the product.
Public-form security
Cloudflare Turnstile is loaded only on the public forms it protects. Cloudflare processes technical browser and network signals, including the connecting IP address, to distinguish automated abuse. Winston does not enable Turnstile pre-clearance, so it does not ask Turnstile to set a cf_clearance cookie on Winston domains. See Cloudflare's Turnstile Privacy Addendum for Cloudflare's processing terms.
Scout session
Scout uses a necessary HTTP-only session cookie named ws_session after sign-in. In production it is secure, SameSite=Lax and expires with the one-hour API token. If you explicitly choose “Keep me signed in on this device”, Scout also stores a purpose-limited HTTP-only ws_remember cookie for up to 30 days. It contains an opaque secret used only to renew the short session; Winston stores only its hash, and sign-out, password change, expiry or account suspension revokes it. Scout does not use either cookie for analytics or advertising.
Browser storage
Scout uses local browser storage for interface preferences such as recent searches, page size and table column choices. These help the product remember your view on the same device.
Questions and rights
Signed-in users can download a machine-readable personal-data export and close their identity from Scout settings. You can also contact Winston Intelligence to ask what data is held, correct it, exercise a legal right or raise a privacy concern. Requests are handled without undue delay and normally within one month. Some public procurement records come from public source services and may remain visible in those services even if Scout account data changes.
Closing a user removes sign-in credentials, sessions, direct identifiers, memberships, saved notices and personal pins or favourites. Shared workspace work is retained with a non-identifying former-member attribution so another member's evidence is not destroyed. The corresponding Dataverse CRM contact is queued for deletion. Sole-member workspaces close at the same time. Closed workspace and billing/audit records are reviewed after six years; public procurement source records are not deleted by a customer-account action. Protected backups expire on their own schedule and an erasure must be reapplied before a restored backup enters ordinary use. A paid workspace must end its external subscription before it can close.
Verification and password-reset links expire after 24 hours and 60 minutes respectively and are single-use. Expired security-token and session rows are eligible for routine deletion after 30 days. An unconfirmed launch request and its unusable token are deleted after 30 days. A confirmed record is kept until the launch message is sent and operational follow-up is complete. Withdrawing keeps a minimal suppression record so the address is not mailed; the link on the withdrawal page can erase that record too. Confirmation links expire after seven days. Page-usefulness feedback is held with aggregate Plausible analytics for up to three years and is reviewed as page-level trend data, not an individual record. Search usage records and product events are deleted after 180 days; the sanitised criteria of a search are deleted as soon as its 24-hour result set closes. Prepaid credit purchases and the credit ledger are financial records and are kept for six years.