Privacy Policy of SCF Connect
How we collect, use and protect your information.
This document can be printed for reference by using the print command in the settings of any browser.
Owner and Data Controller
SCFCONNECT LLC
30 N Gould St
Sheridan, WY 82801
Owner contact email: privacy@scfconnect.com
What this policy covers
This policy covers two things:
- The website at scfconnect.com, our public marketing site.
- The application at app.scfconnect.com, the SCF Connect platform you sign in to.
They are separate systems and they collect different information, so where it matters the sections below are labelled Website or Application. Everything not labelled applies to both.
Two different roles — Application
SCF Connect handles two categories of data under two different roles.
Account and usage data
Information about you as a user of the platform: your identity, your login activity, your subscription. We decide how this is processed, and this policy governs it.
Customer Content
Compliance evidence, control narratives, assessment findings and files uploaded by an organization into its own workspace. We process this only on that organization's instructions, in order to provide the Service. If you are an employee, contractor, assessor or vendor whose personal information appears inside another organization's Customer Content, that organization controls it, and access, correction and deletion requests should go to them. We assist them in responding.
Information we collect
Website
If you only browse the website, we collect technical information such as your IP address, browser and device type, and the pages you visit, through the services listed below. Analytics is set only if you accept it.
If you fill in a form or book a meeting with us, we collect the details you provide, typically your name, email address, telephone number and organization.
Application
Provided by you, or by whoever invited you to the platform
- Name, email address and telephone number
- Job title and website
- Profile image, if you choose to add one
- Password, stored only as a cryptographic hash and never in readable form
- A multi-factor authentication secret, if you enable MFA
About your organization
- Organization name and location
- Business identifiers, where supplied
- Owner contact details
- Organization size
- Organization logo, if provided
Collected automatically
- Sign-in events and activity attributed to your account
- Change history: prior versions of records are retained together with who changed them and when
- Technical information such as IP address, browser and device type, and pages visited, through the services listed below
Customer Content uploaded by you or your organization
- Uploaded files, together with their name, type and size
- Compliance evidence and its validity dates
- Control narratives, assessment findings, risk and vendor records
- Discussion comments, including mentions of other users
Uploaded files may contain personal information that we do not inspect and cannot catalogue. Organizations are responsible for what they choose to upload.
Payment data
Card details are entered directly into our payment provider's hosted fields and are never transmitted to or stored on our systems. We retain only a subscription reference, the plan, its status, and whether a card was verified.
Where your information is processed
Your information is processed in the United States, on Amazon Web Services.
SCF Connect is intended for users in the United States. We do not offer or direct the Service to residents of the European Union, the United Kingdom, or other jurisdictions whose data-protection law would require us to maintain a specific transfer mechanism. If you access the Service from outside the United States, you do so on your own initiative and your information will be transferred to and processed in the United States.
Security — Application
- Passwords are stored as cryptographic hashes and cannot be recovered by us or by our staff.
- Optional multi-factor authentication.
- Uploaded files are served through short-lived, individually authorized links rather than public ones, and the underlying storage blocks public access.
- Stored data is encrypted at rest.
- Change history means unauthorized modification can be traced to an account and a time.
No system is completely secure, and we cannot guarantee absolute security.
Retention — Application
- Accounts are deactivated rather than deleted; the record and its history are preserved.
- Change history is retained for audit purposes.
- Uploaded files remain until the organization removes them. Evidence expiry dates trigger renewal reminders and do not delete the file.
- When a subscription ends we retain the organization's content rather than deleting it, so the subscription can be reactivated without loss. We do not delete it automatically.
- An organization may request deletion of its content at any time, and we will action a verified request within 30 days. Some records may be retained where law requires it, and routine backups are overwritten on their own cycle.
- Database backups are retained for a limited period.
Third-party services
Each provider receives only what it needs for its purpose.
Website
Google Analytics (Google LLC)
Understanding how the website is used. Set only if you accept analytics cookies. Information processed: trackers; usage data; IP address.
Ahrefs Web Analytics (Ahrefs Pte. Ltd.)
Website traffic and search performance measurement. Information processed: usage data; IP address.
HubSpot Meetings (HubSpot, Inc.)
Booking a meeting with us, on pages offering that option. Information processed: the details you provide when booking.
Application — essential to providing the Service
Amazon Web Services (Amazon Web Services, Inc.)
Hosting, database and file storage. All account information and all Customer Content, including uploaded evidence, is stored on AWS infrastructure in the United States.
Stripe (Stripe, Inc.)
Payment processing and subscription billing. Card details are collected by Stripe directly and are never held by us. Information processed: billing contact details and subscription state.
Postmark (ActiveCampaign, LLC)
Transactional email such as invitations, password resets and notifications. Information processed: email address; first name; last name; and the contents of the message.
reCAPTCHA (Google LLC)
Protection against automated abuse at sign-up and sign-in. Information processed: IP address; browser and device information; interaction signals.
Application — support and contact management
HubSpot (HubSpot, Inc.)
In-app support chat, customer relationship management, and meeting scheduling. Information processed: company name; email address; first name; last name; telephone number; website; user type; subscription type and end date; last activity date; signup source.
The HubSpot script loads on pages throughout the application, including when you are signed in, because it provides the in-app support chat. It sets its own cookies and records the pages you visit so that a support conversation has the context of what you were doing.
Application — analytics
Google Analytics (Google LLC)
Understanding how the platform is used, on sign-in and registration pages only. Analytics is not loaded on pages inside the application.
Content delivery
Pages load fonts, icons and software libraries from third-party networks, which necessarily discloses your IP address, browser information and the referring page to those providers.
Cookies and trackers
Website
A cookie banner lets you accept or reject analytics cookies. Rejecting them prevents Google Analytics from being loaded. Cookies strictly necessary for the site to function cannot be disabled. We do not use advertising or marketing cookies on the website.
Application
The application sets a session cookie necessary for you to stay signed in.
The in-app support chat sets cookies on pages throughout the application, including when you are signed in, so that support conversations carry context. Analytics cookies are set only on sign-in and registration pages, not on pages inside the application. The anti-abuse service used at sign-up and sign-in sets its own cookies.
Your rights
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
If you live in a US state with a comprehensive consumer privacy law, including California, you may have the right to:
- Know what personal information we hold about you and obtain a copy of it
- Have it corrected if it is inaccurate
- Have it deleted, subject to the limits described under Retention above and to records we are required to keep
- Not be discriminated against for exercising any of these rights
To make a request, contact privacy@scfconnect.com. We will verify your identity before acting, which normally means confirming control of the email address on the account, and will respond within the period required by the applicable law. You may use an authorized agent where the law permits it.
Where your personal information sits inside an organization's Customer Content, that organization is responsible for responding. Send your request to them, or send it to us and we will direct it to them.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated to account holders, and the date below reflects the most recent change.
Latest update: July 15, 2026