Cookie Policy

Version 2.2Effective 22 September 2026

Introduction

1.1 This Cookie Policy forms part of the contractual relationship between You (the “User”) and Scout & Co Ltd, for Users located outside Great Britain, or Scout Ltd, for Users located in Great Britain (collectively “Scout,” “We,” “Us”). Terms defined in the Terms & Conditions (“T&Cs”) apply herein.

1.2 Scout acts as the data controller for personal data processed through Cookies on this Website.

1.3 This Cookie Policy describes how Cookies and similar technologies are used on the Website in accordance with Directive 2002/58/EC (“ePrivacy Directive”), the General Data Protection Regulation (“GDPR”), the UK Data Protection Act 2018, the California Consumer Privacy Act (“CCPA”), the Brazilian General Data Protection Law (“LGPD”), and other applicable international and national laws.

1.4 This Cookie Policy shall be read in conjunction with the T&Cs, the Privacy Policy, and any other applicable policies or rules.

1.5 Scout is committed to protecting Your rights and freedoms, including privacy and confidentiality in the electronic communications context. Where personal data is transferred outside the EEA, Scout employs appropriate safeguards (e.g., standard contractual clauses) to ensure an adequate level of protection.

Cookies

2.1 Cookies are text files placed on Your device to facilitate service provision, enhance usability, support security measures, and ensure compliance with AML/KYC obligations. Your Cookie consent preferences are managed by the Website itself: Your choice is recorded in a single first-party Cookie (sgg_consent) that holds only the categories You allowed, and no consent data is shared with any third-party consent provider. No additional personal data will be collected or shared without Your explicit consent.

2.2 Essential Cookies are necessary to deliver services explicitly requested by You and operate under Scout’s legitimate interests (Article 6(1)(f) GDPR) to ensure proper functioning of the Website. Non-essential Cookies (Performance, Targeting) require Your prior, informed consent (Article 6(1)(a) GDPR).

2.3 Cookies process different data types depending on their category. For example, Strictly Necessary Cookies may process session identifiers and security tokens. Performance Cookies may process anonymized IP addresses and session interaction data. Targeting Cookies may process pseudonymous user IDs and inferred interests.

Categories of Cookies and Data Types

3.1 Strictly Necessary Cookies

  • Data Processed: Session identifiers, security tokens, consent choice keys, AML/KYC indicators.
  • Purpose: Core functionalities (secure login, fraud detection, AML/KYC compliance), managing Cookie preferences.
  • Legal Basis: Legitimate interests (Article 6(1)(f) GDPR).
  • Consent: Not required.

3.2 Performance Cookies

  • Data Processed: Anonymized IP addresses, random session identifiers, pageview metrics.
  • Purpose: Analyze traffic, measure usage trends, improve site usability.
  • Legal Basis: Consent (Article 6(1)(a) GDPR).
  • Consent: Required.

3.3 Targeting Cookies

  • Data Processed: Pseudonymous user IDs, inferred interests, advertising performance metrics.
  • Purpose: Tailored advertising, tracking marketing campaign effectiveness, optimizing ad relevance.
  • Legal Basis: Consent (Article 6(1)(a) GDPR).
  • Consent: Required.

Specific Cookies and Services

4.1 Below is the current list of Cookies and storages used on this Website:

Strictly Necessary Cookies

  • sgg_player_session (first-party) Expiration: session, renewed while You are signed in

Purpose: Keeps You signed in and protects Your account against forged requests.

  • sgg_scott_token, sgg_scott_refresh (first-party) Expiration: as issued by the sign-in service

Purpose: Authenticate Your session with the account service and renew it without asking You to sign in again.

  • sgg_confirm_token, sgg_reset_token (first-party) Expiration: short-lived

Purpose: Complete an email confirmation or a password reset You started.

  • sgg_consent (first-party) Expiration: 6 months

Purpose: Remembers the Cookie categories You allowed in the preferences dialog.

  • sgg_locale (first-party) Expiration: 1 year

Purpose: Remembers the language You chose.

  • sgg_brand (first-party) Expiration: session

Purpose: Keeps the partner site You entered through consistent across pages.

  • sgg_btag, sgg_btag_tag, sgg_click (first-party) Expiration: 30 days

Purpose: Records the partner link You arrived through so the referral can be credited under our contractual obligations. These Cookies contain a partner reference only and do not track You across other websites.

Performance Cookies

  • _ga, _ga_* (first-party, Google Analytics via Google Tag Manager) Expiration: up to 13 months

Purpose: Distinguish unique users and measure site usage. Set only after You allow the Marketing category, because they are set by the Google Tag Manager container, which loads only with Marketing consent.

Targeting Cookies

  • _gcl_au and other cookies set by the tags in our Google Tag Manager container (first-party or third-party, depending on the tag) Expiration: up to 13 months

Purpose: Measure marketing campaign effectiveness and ad relevance. Set only after You allow the Marketing category; until then the tag container is not loaded at all.

4.2 The Website uses no local storage for tracking purposes.

User Consent Management

5.1 Non-essential Cookies (Performance and Targeting) are placed only after obtaining Your prior, informed consent, through the consent banner shown on Your first visit and the Cookie preferences dialog.

5.2 Granular controls are provided. You may accept all non-essential Cookies, select the Analytics and Marketing categories individually, or refuse all non-essential Cookies ("Necessary only").

5.3 You may withdraw or modify consent at any time via:

(a) The Cookie preferences dialog ("Manage cookies" in the Website footer and on this page);

(b) Browser settings (refer to browser documentation).

5.4 Refusal of non-essential Cookies does not affect access to core functionalities.

Data Security and Confidentiality

6.1 Scout implements appropriate technical and organizational measures in accordance with GDPR Article 32 and the ePrivacy Directive to safeguard personal data processed via Cookies. Third parties whose Cookies We allow are vetted for security standards.

6.2 Access to Cookie-derived data is restricted to authorized personnel.

6.3 Regular audits and penetration tests maintain appropriate security levels.

Data Retention and Justification

7.1 Typical retention periods:

  • Strictly Necessary: Active during the session or as listed above (e.g., sgg_consent: 6 months; sgg_btag: 30 days), ensuring session security, Your saved choices and referral crediting.
  • Performance: Up to 13 months (e.g., _ga), supporting trend analysis and site optimization while minimizing retention duration.
  • Targeting: Up to 13 months or as listed above (e.g., _gcl_au), reflecting advertising campaign durations, performance assessments, and frequency capping needs.

7.2 Retention periods are reviewed periodically to ensure compliance with the GDPR principle of data minimization and operational relevance.

User Rights

8.1 Under GDPR and other applicable laws, You have the right to:

(a) Access Cookie-related personal data;

(b) Request data portability;

(c) Object to data processing;

(d) Withdraw consent at any time without affecting prior lawful processing;

(e) Right to the data erasure.

8.2 To exercise these rights, contact Our Data Protection Officer at wen@igagroup.com.

Third-Party Compliance and Monitoring

9.1 Third-party providers, including advertising/analytics services, must comply with GDPR, AML, and other applicable laws.

9.2 Scout conducts due diligence and may audit compliance, terminating relationships with non-compliant providers.

9.3 The cookie list details third-party providers; see their respective privacy policies on their websites.

Cross-Border Data Transfers

10.1 For data transfers outside the EEA, Scout uses safeguards like standard contractual clauses. Third parties must also adhere to these safeguards.

Incident Response

11.1 In the event of a personal data breach involving Cookie data, Scout notifies affected Users and relevant authorities without undue delay and, where feasible, within 72 hours (GDPR Article 33).

11.2 Users are informed of the breach nature, mitigation steps, and contact points for further information (GDPR Article 34).

Regulatory Compliance

12.1 This Cookie Policy aligns with the ePrivacy Directive, GDPR, UK Data Protection Act 2018, CCPA, LGPD, ASA rules, UKGC guidance, and AML laws.

Changes to This Policy

13.1 Material changes to this Cookie Policy will be communicated via notices on the Website and, where appropriate, by email.

13.2 Continued use of the Website after changes indicates acceptance of the updated Cookie Policy. If You do not accept these changes, You must discontinue using the Website and may close Your User Account as outlined in the T&Cs.

End of Cookie Policy

We use necessary cookies to run the site. With your consent we also use analytics and marketing cookies. Cookie policy