Privacy policy
This page explains what DataScoop collects about you and why. It is written to be read, not skimmed past.
What we collect
Your email address, when you request an API key, so we can issue and manage the key. Payment details are collected and stored by Stripe, our payment processor; we never see your card number. Stripe shares with us the email and the amount paid so we can deliver what you bought. Server logs (IP address, requested URL, time) are kept briefly for security and reliability.
The account interface uses a strictly necessary, HttpOnly session cookie containing an opaque random token. The server stores only its hash, linked to your account, and expires it after 30 days. It is not used for advertising or analytics.
Service counters
We count successfully displayed explorer previews and checkout requests, starts and failures as daily totals by dataset, market, guide and entry type. Preview sizes are grouped as no matches, 1-25 rows or more than 25 rows. These counters do not use cookies or visitor identifiers and do not store filter values, account details, request headers or payment identifiers. They are processed by DataScoop, not sent to Google. Repeated actions can count more than once; the totals do not identify people or sessions.
Optional analytics
If you choose Accept analytics, public marketing pages load Google Analytics 4 and send page visits and non-personal events such as problem-page and dataset-link clicks. Those events may include the dataset, market and problem page involved, but not filter values, payment details, API keys or checkout identifiers. Query strings are removed from page locations, referrers and link URLs before they are sent. Advertising storage, signals and personalisation are disabled.
Google is the analytics recipient and processor. Its systems and subprocessors may process analytics data outside the UK under its transfer safeguards; see Google's privacy policy. User-level event retention is controlled in DataScoop's Google Analytics property rather than by this website code.
Google Analytics is not loaded on the explorer, signup, login, account or export-delivery pages because those pages accept or display credentials or payment capabilities. Purchases, refunds and subscriptions are measured through server-side Stripe verification and signed webhooks instead. If you reject analytics, the Google Analytics script is not loaded and queued public-page events are discarded.
We store your accept or reject choice in your browser so we can respect it. Use the Analytics settings button on a public page to change that choice. Withdrawing consent stops future analytics loading and removes DataScoop's Google Analytics cookies from this browser.
Why we collect it
To provide the service you asked for (issuing keys, delivering downloads, running subscriptions), to prevent abuse, and to comply with tax and accounting law. Our legal bases for those activities are contract and legitimate interests. We use consent for optional analytics.
The data we sell is not about you
The datasets on this site are official public records about businesses, premises and permits. They are organisational data only. We remove personal fields (people's names, phone numbers, home addresses) from every source that contains them.
Your rights
You can ask us what we hold about you, ask us to correct or delete it, or object to processing, by emailing hello@datascoop.io. You can also complain to your data protection authority (in the UK, the ICO).
Retention
Account emails are kept while your key or subscription is active and for as long as tax law requires afterwards. Logs are kept for a short period and then deleted. Analytics retention is controlled in the DataScoop Google Analytics property; rejecting or later withdrawing consent stops future analytics collection from this browser.
Last updated 2026-08-31.