Launch offer — $149 $29 once, 80% off while it lasts.
Legal

Privacy & the data we hold

ShopScoutr is a business-contact dataset. This page says plainly what we collect, where it comes from, what we do with it, and how to get a store taken out.

Last updated 29 August 2026 Contact hey@storescoutr.com

Who we are

ShopScoutr is operated by PeakProgg. We build and sell a dataset of publicly reachable Shopify storefronts, together with the signals a seller needs to qualify them. We are the data controller for both the store records described below and for your own account data.

Questions, complaints and requests all go to one place: hey@storescoutr.com. A person reads it.

What is in the store database

Every row in the dataset describes a storefront, not a private person. For each domain we record the fields below.

  • store_url The storefront domain and its TLD.
  • contact_email Addresses the store publishes on its own site.
  • country · language Where the store trades and the language it sells in.
  • product_count · industry Catalogue size and the category we classified it into.
  • theme · is_premium_theme The Shopify theme the storefront renders with.
  • pixels_detected Which of Meta, TikTok, Snapchat, Google Ads, GA and GTM are firing.
  • est_monthly_traffic Modelled organic and paid traffic estimates.
  • seo_score A 0–100 score derived from a crawl of the storefront.

Contact addresses are the ones a store publishes on its own site — the address on the contact page, in the footer, or in the store's structured data. We do not guess addresses, buy them from brokers, or attempt to unmask a person behind a role address.

Where the data comes from

Everything is collected from the public web: the storefront's own HTML, its sitemap.xml, its public product endpoints, DNS records, and public traffic estimates. We read pages the same way a browser does, at a rate meant to stay well inside what a storefront can absorb.

We do not log into stores, bypass access controls, use customer accounts, place orders, or touch anything behind a password. We do not collect data about a store's customers — no order data, no shopper identities, no cart contents.

Why we are allowed to hold it

Where a record contains personal data — in practice, a named owner's email such as anna@herstore.com — we rely on legitimate interests under Art. 6(1)(f) GDPR: business-to-business outreach to a trading company, using a contact address that company published for exactly that purpose.

That basis is not unconditional, and it gives you a right to object. Any store owner can have their store removed for any reason, with no justification required — see store removal. We do not treat a removal request as a negotiation.

Your account data

If you buy the database or pull the free sample, we store your email address, a hashed password, and a record of what you downloaded and when. That is contract data under Art. 6(1)(b) — we cannot give you the file or support the purchase without it.

Card details never reach our servers. Payment is handled by our payment processor, which returns a transaction reference we keep for accounting.

Cookies and analytics

One cookie, and it is the session cookie that keeps you logged in. It is strictly necessary, so there is no consent banner to dismiss. We run no advertising pixels and no cross-site trackers — which, given what we sell, felt like the least we could do.

We do count traffic to the public pages — this one and the front page — using Plausible, which we run ourselves on tracking.peakprogg.com. It sets no cookies, stores nothing on your device, and follows nobody between sites. Because it is our own server, no analytics company gets a copy either.

A visit records the page you landed on, where you arrived from, your browser, operating system and device type, and a rough location worked out from your IP address. The IP itself is never written down: it is mixed with your browser string and a salt we throw away every night to form a one-day identifier, which is only there so one person reading three pages counts as one visitor rather than three. By the next day it cannot be recomputed. Where we tag a particular button, we learn that it was clicked, never who clicked it.

None of this reaches a name, an email or an account, and the signed-in app is not measured at all. Our basis is legitimate interests — knowing which pages get read is how we decide what to write next. Since nothing is stored on your device and nothing identifies you, there is nothing to consent to; but if you would rather not appear in the counts, any tracker blocker stops the script and we make no attempt to work around one.

Who the data goes to

The store dataset is the product: customers who buy it receive a copy of the CSV and may use it for their own outreach. Buyers are bound by our terms to use it lawfully, to honour opt-outs they receive, and not to resell the file as a dataset of their own.

Beyond that, data reaches only the processors that run the service — hosting, the database, transactional email and the payment processor. Analytics is not on that list because we host it ourselves; see cookies and analytics. We do not sell or share your account data with anyone.

A removal takes a store out of the live database and out of every build shipped after it. We cannot claw back a CSV a customer already downloaded, and we will not pretend otherwise — but we do notify buyers of removals so they can drop the row.

How long we keep it

Store records live until the domain stops resolving as a Shopify store, or until removal. Stale domains are dropped on the next crawl. Account data is kept while your account exists and for seven years afterwards where invoicing law requires it. Removal requests themselves are kept as a permanent suppression entry — a domain and a date, nothing more — so a later crawl cannot quietly re-add a store you already asked us to drop.

Your rights

If you are in the EU/EEA or the UK you can ask us to do any of the following, and we will answer within 30 days:

  • See a copy of what we hold about you or your store (access).
  • Have an inaccurate field corrected (rectification).
  • Have the record deleted (erasure) — for stores this is the removal request below.
  • Object to our legitimate-interests processing, which we honour without asking why.
  • Receive your account data in a portable, machine-readable format.
  • Ask us to restrict processing while a dispute is open.

Send requests to hey@storescoutr.com. You also have the right to complain to your national data protection authority, though we would rather you gave us the chance to fix it first.

Store removal request

Take my store out of the database.

No reason needed, no form to fill in, no reply asking you to reconsider. Email hey@storescoutr.com from an address on the domain, or from the address listed in the record, and include:

  1. 01 The store domain, exactly as it appears in the record.
  2. 02 Confirmation that you own or operate the store — a reply from the domain's own mailbox is enough.
  3. 03 Optionally, whether you also want the address suppressed from future crawls of other domains you run.

We remove the record within 5 working days, add the domain to the permanent suppression list so no future crawl picks it up again, and email you when it is done.

Request removal →

Changes to this policy

If we change what we collect or who we share it with, we update this page and move the date at the top. Material changes to how account data is handled are emailed to account holders.

Still not sure whether your store is in there? Ask — we will check the database and tell you.

hey@storescoutr.com