Privacy Policy
Who We Are
SalesScout is a product of FreightScout.ai, built to provide AI-powered sales intelligence for freight brokerages. Our platform helps sales representatives discover prospects, generate outreach, and track pipeline activity. This policy explains how we collect, use, and protect your data.
What Data We Collect
Account information: When your brokerage onboards to SalesScout, we store your name, work email address, brokerage affiliation, and role. This data is provided by your brokerage administrator during setup.
Email integration data: If you connect your Microsoft Outlook or Google Gmail account via OAuth, we store encrypted authentication tokens that allow SalesScout to send emails on your behalf and — for Microsoft Outlook connections only — to detect whether a prospect has replied. We do not store, read, or retain the content of your emails. This access is limited to sending outbound prospecting emails you approve and, for Microsoft accounts, detecting whether a prospect has replied. SalesScout does not read Gmail messages.
Prospect and pipeline data: SalesScout generates intelligence briefs about prospective companies using publicly available information. Pipeline status, outreach history, and contact records are stored to provide continuity across sessions.
Usage data: We log interactions with the platform including queries, brief requests, and email sends to improve service quality and provide activity reporting to brokerage managers.
How We Protect Your Data
Encryption: All OAuth tokens (Microsoft and Google) are encrypted at rest using AES-256-GCM encryption. Tokens are decrypted only in-memory at runtime by our backend service. Raw tokens are never written to disk, included in logs, or exposed in any user-facing interface. Even direct database access does not reveal plaintext tokens.
Key separation: Encryption keys are stored as environment variables on the application server, completely separate from the database. Compromise of the database alone does not expose token data.
Access control: All database access is restricted to our backend service using a private service key. No public API access is permitted. Row-level security is enforced on all tables.
Automatic cleanup: When a sales representative is deactivated by their brokerage administrator, all associated OAuth tokens and email connection data are automatically and permanently deleted from our systems.
Email & Calendar Integration Specifics
When you connect your work email account, SalesScout requests the following permissions:
Microsoft Outlook: Mail.Send (send emails on your behalf), Mail.Read (detect inbound replies), offline_access (maintain the connection without repeated sign-ins), and User.Read (identify your account).
Google Gmail: gmail.send (send emails on your behalf), used solely to send emails that you compose or approve within SalesScout. SalesScout does not request read access to Gmail and does not read, access, or store the content or metadata of messages in your Gmail mailbox.
For Microsoft Outlook connections, SalesScout does not access, read, or store any email content beyond detecting whether a reply to a SalesScout-sent email has been received. For Google Gmail connections, SalesScout does not read your mailbox at all. In neither case do we scan your inbox, access personal emails, or read email content unrelated to SalesScout outreach.
Google Calendar: When you connect your Google Calendar for the Scout Notetaker assistant, SalesScout requests calendar.readonly (read-only). We read your scheduled meetings' times, titles, and attendees solely to identify which meetings the notetaker should join and to dispatch it. SalesScout does not create, modify, or delete calendar events.
Data Retention
Account and pipeline data is retained for the duration of your brokerage's subscription. Upon cancellation or at the request of your brokerage administrator, all data associated with your organization is permanently deleted within 30 days. Individual representatives can request deletion of their personal data at any time by contacting us.
Data Sharing
We do not sell, rent, or share your data with third parties. Data is not used for advertising. The only external services that process your data are our infrastructure providers (database hosting, email delivery) under strict data processing agreements.
Your Rights
You may request access to, correction of, or deletion of your personal data at any time. Brokerage administrators may deactivate representatives, which triggers automatic deletion of all associated authentication tokens. To exercise your rights, contact us at hello@freightscout.ai.
Changes to This Policy
We may update this policy as our product evolves. Material changes will be communicated to active brokerage administrators via email. The "last updated" date above reflects the most recent revision.
Contact
For privacy-related questions or data requests, contact us at hello@freightscout.ai.