PRIVACY
Scopearo Privacy Policy
Effective date: July 21, 2026
1. Who controls your information
Hyojun Lim, trading as Scopearo, is the operator and controller of personal information processed through Scopearo. Address: 230, Junggye-ro, Nowon-gu, Seoul, Republic of Korea. Privacy questions may be sent to privacy@scopearo.com.
2. Information we process
We process account information such as name, email address, authentication identifiers, and profile details; workspace information such as company, team, role, and invitations; content you submit such as messages, projects, tasks, approvals, attendance clock records and correction requests, time entries, expenses, invoices, portal updates, integration settings, and preferences; subscription identifiers and status; and limited device, access, security, error, and audit information needed to operate and protect the service.
3. How and why we use information
We use information to create and authenticate accounts, provide isolated workspaces, synchronize team content, enforce permissions, process subscriptions, respond to support requests, prevent abuse, maintain security, comply with law, and improve reliability. Depending on the context, processing is based on performing our contract, legitimate interests in operating and securing the service, consent, or legal obligations.
4. Payments
Paddle acts as merchant of record and independently processes checkout, payment methods, billing addresses, taxes, invoices, cancellations, and refunds under its own privacy terms. Scopearo receives and stores only the customer, subscription, transaction, price, billing interval, and status identifiers needed to provide account access and support.
5. Service providers and international processing
We use Cloudflare for hosting, network delivery, object storage, databases, and operational logs; Clerk for authentication and account management; Paddle for checkout and subscription billing; Resend for transactional and notification email; Google APIs for calendar connections that you explicitly authorize; and OpenAI to generate project summaries only when an authorized user requests that feature. These providers may process information in countries where they or their subprocessors operate. We rely on their contractual and legal safeguards for international transfers where required.
6. Sharing
We do not sell personal information. We share information with service providers only as needed to operate Scopearo, with workspace members according to their permissions, when you direct us to do so, in connection with a lawful business transfer, or when required to comply with law or protect rights and safety.
7. Retention and deletion
We retain account and workspace information while an account or workspace is active and for as long as reasonably necessary for security, dispute resolution, backup recovery, and legal or accounting obligations. Paddle may retain transaction records under its own legal duties. Workspace owners may request deletion from the service, subject to required retention and backup cycles.
8. Cookies, local storage, and service metrics
Scopearo and Clerk use cookies or similar storage that are necessary for authentication, session security, routing, and service preferences. We use limited first-party operational events and error logs to understand feature reliability and protect the service. On permitted public marketing and trial-entry pages only, Google Ads measurement is optional and its script remains unloaded until you choose "Allow measurement." If allowed, Scopearo may send a page view, campaign attribution, and selected trial or purchase events to Google Ads. We do not send page views from authenticated workspace subpages, tokenized portal or intake pages, checkout and payment routes, API routes, or URL query strings. We do not sell personal information or behavioral profiles. Your choice is stored in this browser and can be changed below.
9. Security
We use encrypted transport, workspace-level isolation, server-side authorization, role-based permissions, security headers, audit records, and least-privilege practices. No online service can guarantee absolute security, so you should use a strong password and protect access to your account.
10. Your choices and rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or objection, withdraw consent, or complain to a data-protection authority. Organization-controlled content requests may require coordination with the workspace owner. We may verify your identity before completing a request.
11. Children
Scopearo is intended for business users and is not directed to children. We do not knowingly collect personal information from children who are not legally able to consent to the service in their jurisdiction.
12. Changes and contact
We may update this policy as Scopearo or applicable requirements change. We will update the effective date and provide notice of material changes where appropriate. Contact privacy@scopearo.com for privacy requests.