Privacy Policy
How Docket collects, uses, and protects personal information when you and your clients use the service.
Plain-language summary. Docket helps you record scope changes. We collect the account and project data you give us, plus limited technical data (including the IP address and timestamp captured when a client approves a change — that is the point of the product). We do not sell your data. We share it only with the vendors that run the service (email, file storage, payments, and—only with your consent—analytics) and when the law requires it.
This Privacy Policy explains how Docket ("Docket", "we", "us") collects, uses, and discloses information in connection with the Docket scope-change management service at scopedocket.com (the "Service"). It applies to account holders ("Customers") and to the clients who submit and approve change requests through a Customer's links ("Client Users").
For Client Users, the Customer is the controller of the request and approval data they collect through Docket; Docket acts as a processor on the Customer's behalf for that data.
1Information we collect
Information you provide
- Account data — your name, email address, password (stored only as a salted hash), and organization name when you sign up.
- Project and change data — project names, client details, scope-change requests, impact assessments (days and cost), summaries, internal notes, and any files or reference links you or your clients upload.
- Client submissions — when a Client User submits or approves a request, the email address they enter and the content of their request or decision.
- Communications — messages you send us at hello@scopedocket.com.
Information collected automatically
- Approval evidence — when a change is approved or declined, we record a timestamp, the approver's email, and the IP address of the request, together with a cryptographic signature over the approved statement. This audit record is a core function of the Service and is retained as part of the Customer's permanent project log.
- Authentication cookies — a session cookie set after sign-in to keep you logged in. These are strictly necessary for the Service to function.
- Analytics — on our public website pages we use Google Analytics to understand aggregate, non-identifying traffic patterns (such as page views and referrers). Analytics cookies are not loaded until you consent through our cookie banner, and you can change or withdraw that choice at any time. Analytics is not used in the signed-in application.
- Server logs — standard request metadata (IP address, browser/user-agent, timestamps) generated by our hosting and used for security and reliability.
Payment information
Paid subscriptions are processed by Stripe. We do not receive or store full card numbers; Stripe handles card data directly and provides us with limited billing metadata (such as plan, status, and the last four digits of the card). See Stripe's privacy policy.
2How we use information
- To provide, maintain, and secure the Service, including authentication and the generation of signed approval records.
- To send transactional email — verification, approval notifications, and account-related messages.
- To process subscriptions, billing, and plan limits.
- To respond to support requests and communicate about the Service.
- To detect, prevent, and investigate abuse, fraud, and security incidents.
- To comply with legal obligations and enforce our Terms of Service.
We rely on the following legal bases (where the GDPR or similar laws apply): performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where required, and compliance with legal obligations.
3How we share information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose information only as follows:
- Service providers (sub-processors) — vendors that operate parts of the Service under contract and on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Resend | Transactional email delivery | Recipient email, message content |
| Cloudflare R2 | File and attachment storage | Uploaded files |
| Stripe | Subscription billing and payments | Billing details, card data (held by Stripe) |
| Database & application hosting | Running the Service and storing your data | All account, project, and change data |
| Google Analytics | Aggregate website analytics (consent-based, public pages only) | Usage data, cookie identifiers, IP address |
| Secure Privacy | Cookie consent management | Consent preferences, cookie identifiers |
- Between Customer and Client Users — request and approval data is shared between the Customer and its client as an inherent part of the workflow.
- Legal and safety — when required by law, legal process, or to protect the rights, property, or safety of Docket, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
4Data retention
We retain account and project data for as long as your account is active. Approval and audit records are retained as part of the Customer's project log so they remain available as evidence. When you delete a workspace or close your account, associated data is deleted or anonymized within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Backups are purged on a rolling schedule.
5Security
We use technical and organizational measures to protect personal information, including encryption in transit (TLS), hashed passwords, scoped access controls, and cryptographic signing of approval records. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6International transfers
We and our sub-processors may process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses for such transfers.
7Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at hello@scopedocket.com. We will respond as required by applicable law. If you are a Client User, requests about data a Customer collected through Docket may be directed to that Customer as the controller, or to us — we will forward them as needed.
If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority. If you are a California resident, you may exercise rights under the CCPA/CPRA; we do not sell or share personal information as those terms are defined.
8Children's privacy
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
9Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice. Continued use of the Service after an update constitutes acceptance of the revised Policy.
10Contact
Questions about this Policy or your data? Email hello@scopedocket.com.