Privacy And Data

Privacy Policy

Smart Scout exists to help Clash Royale teams scout, verify, and coordinate recruitment using public game data and account-level workflows. This page explains what data supports that system and how it is handled. Last updated 9 June 2026.

What We Collect

Smart Scout stores the minimum account and public game data required to power scouting, saved views, watched clans, and verification.

We collect account details needed to run the app, plus public Clash Royale player and clan information returned through authorized API access. That includes identifiers, profile attributes, roster information, shortlist activity, and saved scouting views.

We do not ingest private chat, device-level surveillance data, or unrelated personal content. Data collection is limited to what is required for the product workflows visible inside Smart Scout.

Smart Scout is not directed at children. You must be at least 13 years old (or the minimum digital-consent age in your country, if higher) to create an account, and we do not knowingly collect account data from anyone younger.

How Platform Data Is Used

Public Clash Royale data is used to support search, imports, watchlists, recent changes, and team decision-making inside the product.

Smart Scout relies on authorized API access to retrieve player and clan data that powers discovery, filtering, watchlists, and change tracking. We process that information to help teams identify prospects, monitor movement, and keep scouting records current.

The data is used to operate Smart Scout features, not to build unrelated advertising profiles or resell private behavioral intelligence.

Verification And Security

Verification uses temporary ownership signals and role-based access so clan administration stays controlled inside the real app.

Clan verification may use temporary ownership codes, linked player tags, and internal administrative review to confirm control of a clan. Those checks are designed to validate access without exposing private account credentials to other users.

Access to account features is governed through application permissions and protected authentication flows. Verification data is processed only for trust, ownership, and moderation workflows.

Billing And Account Operations

Payments are handled by Stripe. Smart Scout never sees or stores your full card details.

Paid subscriptions are processed by Stripe, which handles checkout, card storage, and recurring billing. Smart Scout stores only the operational references it needs — your Stripe customer and subscription identifiers and the current plan state — never your card number.

We use that data to keep the service running, enforce plan access, and support account administration. We do not present billing information as public scouting data.

Third-Party Services

Smart Scout runs on a small set of named providers: Supabase, Stripe, Resend, and the official Clash Royale API.

We share data with service providers only so they can run parts of the product for us: Supabase hosts our database and authentication, Stripe processes payments, Resend sends transactional and Scout-match emails to the address on your account, and public game data comes from the official Clash Royale API operated by Supercell.

If you configure a Scout to deliver matches to a Discord channel or your own webhook, match data is sent to the destination you chose; you control those destinations and can remove them at any time. We do not sell personal data or share it with advertisers.

Cookies

Two essential sign-in cookies, nothing else — no analytics, advertising, or cross-site tracking cookies.

Smart Scout sets two cookies, smart_scout_access_token and smart_scout_refresh_token, which keep you signed in. They are essential for the service to work, are marked HttpOnly and Secure, and are removed when you sign out. The refresh cookie lasts up to 30 days.

We do not set analytics, advertising, or cross-site tracking cookies, which is why you will not see a cookie consent banner.

Retention And Requests

Account data is kept only while your account exists. You can delete your account and its data yourself from the account page at any time.

Cached scouting records, shortlist entries, notifications, and saved views may remain available so teams can maintain continuity in recruiting and account history. Account-level data is retained only while your account exists; public Clash Royale data cached from the official API is refreshed or expires on a rolling basis.

You can permanently delete your account at any time from the Delete account control on your account page. Deletion removes your profile, saved views, shortlists, watched clans, linked player tags, scouts, and notifications, and cancels any active subscription. Deletion is immediate and cannot be undone.

For a copy of the data associated with your account, or any other data request, email support@rorystandley.co.uk from the address on your account so we can verify ownership. Requests are reviewed in the context of account ownership, verification, and platform obligations.