Who we are
ShopScoutr is operated by PeakProgg. We build and sell a dataset of publicly reachable Shopify
storefronts, together with the signals a seller needs to qualify them. We are the data controller
for both the store records described below and for your own account data.
Questions, complaints and requests all go to one place:
hey@storescoutr.com. A person reads it.
What is in the store database
Every row in the dataset describes a storefront, not a private person. For each domain we record
the fields below.
-
store_url
The storefront domain and its TLD.
-
contact_email
Addresses the store publishes on its own site.
-
country · language
Where the store trades and the language it sells in.
-
product_count · industry
Catalogue size and the category we classified it into.
-
theme · is_premium_theme
The Shopify theme the storefront renders with.
-
pixels_detected
Which of Meta, TikTok, Snapchat, Google Ads, GA and GTM are firing.
-
est_monthly_traffic
Modelled organic and paid traffic estimates.
-
seo_score
A 0–100 score derived from a crawl of the storefront.
Contact addresses are the ones a store publishes on its own site — the address on the
contact page, in the footer, or in the store's structured data. We do not guess addresses, buy
them from brokers, or attempt to unmask a person behind a role address.
Where the data comes from
Everything is collected from the public web: the storefront's own HTML, its
sitemap.xml, its public product endpoints, DNS records, and public traffic
estimates. We read pages the same way a browser does, at a rate meant to stay well inside what a
storefront can absorb.
We do not log into stores, bypass access controls, use customer accounts, place orders, or touch
anything behind a password. We do not collect data about a store's customers — no order
data, no shopper identities, no cart contents.
Why we are allowed to hold it
Where a record contains personal data — in practice, a named owner's email such as
anna@herstore.com — we rely on legitimate interests under
Art. 6(1)(f) GDPR: business-to-business outreach to a trading company, using a contact address
that company published for exactly that purpose.
That basis is not unconditional, and it gives you a right to object. Any store owner can have
their store removed for any reason, with no justification required — see
store removal. We do not treat a removal request as a negotiation.
Your account data
If you buy the database or pull the free sample, we store your email address, a hashed password,
and a record of what you downloaded and when. That is contract data under Art. 6(1)(b) —
we cannot give you the file or support the purchase without it.
Card details never reach our servers. Payment is handled by our payment processor, which returns
a transaction reference we keep for accounting.
Cookies and analytics
One cookie, and it is the session cookie that keeps you logged in. It is strictly necessary, so
there is no consent banner to dismiss. We run no advertising pixels and no cross-site trackers
— which, given what we sell, felt like the least we could do.
We do count traffic to the public pages — this one and the front page — using
Plausible,
which we run ourselves on tracking.peakprogg.com. It sets no cookies, stores nothing
on your device, and follows nobody between sites. Because it is our own server, no analytics
company gets a copy either.
A visit records the page you landed on, where you arrived from, your browser, operating system
and device type, and a rough location worked out from your IP address. The IP itself is never
written down: it is mixed with your browser string and a salt we throw away every night to form a
one-day identifier, which is only there so one person reading three pages counts as one visitor
rather than three. By the next day it cannot be recomputed. Where we tag a particular button, we
learn that it was clicked, never who clicked it.
None of this reaches a name, an email or an account, and the signed-in app is not measured at
all. Our basis is legitimate interests — knowing which pages get read is how we decide what
to write next. Since nothing is stored on your device and nothing identifies you, there is
nothing to consent to; but if you would rather not appear in the counts, any tracker blocker
stops the script and we make no attempt to work around one.
Who the data goes to
The store dataset is the product: customers who buy it receive a copy of the CSV and may use it
for their own outreach. Buyers are bound by our terms to use it lawfully, to honour opt-outs
they receive, and not to resell the file as a dataset of their own.
Beyond that, data reaches only the processors that run the service — hosting, the database,
transactional email and the payment processor. Analytics is not on that list because we host it
ourselves; see cookies and analytics. We do not sell or share your
account data with anyone.
A removal takes a store out of the live database and out of every build shipped after it. We
cannot claw back a CSV a customer already downloaded, and we will not pretend otherwise —
but we do notify buyers of removals so they can drop the row.
How long we keep it
Store records live until the domain stops resolving as a Shopify store, or until removal. Stale
domains are dropped on the next crawl. Account data is kept while your account exists and for
seven years afterwards where invoicing law requires it. Removal requests themselves are kept as a
permanent suppression entry — a domain and a date, nothing more — so a later crawl
cannot quietly re-add a store you already asked us to drop.
Your rights
If you are in the EU/EEA or the UK you can ask us to do any of the following, and we will answer
within 30 days:
- See a copy of what we hold about you or your store (access).
- Have an inaccurate field corrected (rectification).
- Have the record deleted (erasure) — for stores this is the removal request below.
- Object to our legitimate-interests processing, which we honour without asking why.
- Receive your account data in a portable, machine-readable format.
- Ask us to restrict processing while a dispute is open.
Send requests to hey@storescoutr.com. You also have
the right to complain to your national data protection authority, though we would rather you
gave us the chance to fix it first.
Store removal request
Take my store out of the database.
No reason needed, no form to fill in, no reply asking you to reconsider. Email
hey@storescoutr.com
from an address on the domain, or from the address listed in the record, and include:
-
01
The store domain, exactly as it appears in the record.
-
02
Confirmation that you own or operate the store — a reply from the domain's own mailbox is enough.
-
03
Optionally, whether you also want the address suppressed from future crawls of other domains you run.
Request removal →
Changes to this policy
If we change what we collect or who we share it with, we update this page and move the date at
the top. Material changes to how account data is handled are emailed to account holders.