Privacy Policy & Security Statement

    This document explains what data we collect when you use Scalino, why we process it, who we share it with, and how we protect it. By using Scalino you confirm that you have read and understood this policy.

    Last updated: 07.08.2026

    1. Scope and Data Controller

    This policy covers all services provided through scalino.co and its subdomains. The data controller is the team operating Scalino.

    It applies to account owners, team members invited to an organization, and visitors of our website.

    2. Information We Collect

    We only collect data that is necessary to deliver the service:

    • Account data: full name, email address, country, website and a hashed password.
    • Organization data: organization name, team members and their roles.
    • Usage data: search queries, generated lead volume, automation settings, credit movements and activity logs.
    • Lead data: business information such as name, address, phone, website, rating and review count retrieved from public sources (Google Maps business listings).
    • Integration data: connection and authorization details for the Google Sheets or Odoo CRM accounts you link.
    • Technical data: IP address, browser and device information, language preference and error logs.

    3. Purposes and Legal Bases

    We process your data to create and manage your account, deliver lead generation, track credit and subscription usage, answer support requests, keep the platform secure and meet legal obligations.

    Our legal bases are performance of a contract, legitimate interest (security and service improvement), consent (marketing messages and non-essential cookies) and legal obligation.

    4. Lead Data and Public Sources

    Scalino retrieves lead data from publicly available business listings through the Google Maps Places API. This is business contact information; we do not aim to collect data about private life.

    The lead lists you generate belong to your organization. You are responsible for complying with applicable data protection and electronic marketing laws when using them.

    5. Data Sharing and Service Providers

    We never sell your data. We share it only with infrastructure providers required to run the service and with integrations you connect yourself:

    • Hosting, database and authentication infrastructure providers.
    • Google Maps Places API (for lead search queries).
    • Google Sheets and Odoo CRM accounts you connect (only for the data you choose to sync).
    • Competent public authorities where legally required.

    6. Cookies and Analytics

    We use essential cookies to keep you signed in and remember your language preference. We may also run measurement tools through Google Tag Manager to understand how the site is used.

    You can refuse or delete cookies in your browser settings, but some functions such as signing in may then stop working.

    7. Security Statement

    We apply technical and organizational measures to protect your data:

    • All traffic is transported over HTTPS/TLS encryption.
    • Passwords are never stored in plain text; they are hashed by our authentication infrastructure.
    • Row level security rules are enforced in the database so each organization can only access its own data.
    • Integration keys and API credentials are stored encrypted and are never displayed again in the interface.
    • Administrative actions are restricted by role-based permissions and recorded.
    • Our database infrastructure is protected with regular automated backups.

    8. Your Responsibilities

    Account security is a shared responsibility. Please choose a unique, strong password, never share it, grant team members only the permissions they need, and contact us immediately if something looks wrong.

    If you notice suspicious access or a vulnerability, report it to scalinoco@gmail.com.

    9. In Case of a Security Incident

    If we detect unlawful access to personal data, we investigate without delay, protect the affected accounts and notify the relevant users and authorities within the period required by law.

    10. Data Retention

    We keep your account and usage data while your account is active. When you delete your account, personal data is deleted or anonymized within a reasonable period; records subject to statutory retention are kept for the required duration.

    11. International Transfers

    Our hosting and API providers may operate servers outside your country. In that case, transfers happen only to the extent required to deliver the service and with the safeguards required by applicable law.

    12. Your Rights

    Under GDPR and equivalent laws you have the right to:

    • Learn whether your data is processed and request access to it.
    • Request correction of incomplete or inaccurate data.
    • Request deletion of your data.
    • Request restriction of processing and data portability.
    • Withdraw consent for consent-based processing and opt out of marketing messages.

    13. Children’s Privacy

    Scalino is a business (B2B) service and is not directed to anyone under 18. If we learn that we collected data from a minor, we delete it.

    14. Changes and Contact

    We may update this policy from time to time. For material changes we notify you in the platform or by email, and the current version is always published on this page.

    For any privacy or security question: scalinoco@gmail.com