Last updated: 17 August 2026
This Privacy Policy explains how Himo Tech (“we”) collects, uses, discloses and protects personal information when you use LeadsBullseye (the “Service”), and the rights you have. It covers customers in Canada, the United States, and the EU/UK.
Himo Tech is the controller of the account information you provide to us. For business-listing data you collect through the Service, you (our customer) are the controller and we act as your processor — see our Data Processing Agreement.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, phone, company, role, password (hashed by our auth provider) | Create and secure your account; provide the Service |
| Billing data | Plan, subscription status, and payment identifiers held by Stripe (we do not store full card numbers) | Process subscriptions |
| Usage data | Searches run, leads returned, API request counts, estimated cost, timestamps | Enforce quotas, meter usage, operate and improve the Service |
| Lead data you collect | Business names, addresses, business phone numbers, website status from public listings | Provided to you as the output of the Service; we process it on your behalf |
| Enriched business contact data | Customer-initiated: only when you click to enrich a specific saved lead do we retrieve contact details that business has published publicly — on its own website, in public directories (e.g. Yelp, Yellow Pages, BBB, chamber-of-commerce and industry listings), or on public social/company pages. Each value (email, phone, a role-holder's name where a public page identifies them in that role, or a social/web link) is stored with the source page name, the source URL, a verbatim quoted line from that source, and a retrieval timestamp | Provided to you as the output of the Service, at your request; we process it on your behalf |
| Your API keys (BYOK) | Google Maps / Gemini keys, if you supply them | Run searches/AI on your behalf; stored encrypted, never displayed again |
| Technical data | IP address, browser type, essential session cookie | Security, authentication, and delivering the site |
| Product analytics data (only if you accept analytics cookies) | Pages viewed, clicks within the app, approximate location from your IP address, and — once signed in — your account identifier, email, name and plan. Collected via HeyCatch; see our Cookie Policy | Understand which features are used so we can improve them. Never used for advertising |
Business contact details are often about an organization rather than an identifiable individual. However, where a listing identifies an individual (for example a sole proprietor’s name, or a personal mobile used as a business number), it can be personal information/personal data under PIPEDA, Quebec Law 25, GDPR and UK GDPR. We therefore treat lead data as potentially personal and handle it under the safeguards in this policy and our DPA. Enriched business contact data obtained through the on-demand contact enrichment feature is treated the same way. You are responsible for having a lawful basis to process and contact the individuals in leads you collect.
We use vetted service providers to run the Service. Current subprocessors are listed in our DPA and include our cloud/database provider (Supabase), payment processor (Stripe), AI/geodata providers (Google), and our product-analytics provider (HeyCatch — used only where you have accepted analytics cookies). We do not sell your personal information.
Your information may be processed outside your country, including in Canada, the United States, and the EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum) for transfers of EU/UK personal data.
To exercise any right, email hmounir@himo-tech.ca. We will verify your request and respond within the timeframes required by applicable law.
If you are an individual whose contact details were retrieved through our on-demand contact enrichment feature, you may email hmounir@himo-tech.ca to have them deleted from LeadsBullseye systems.
We use encryption in transit, row-level tenant isolation, encrypted storage of any API keys you supply (AES-256-GCM), least-privilege access, and access logging. No system is perfectly secure; we will notify you and regulators of breaches as required by law.
The Service is for business use and is not directed to children; we do not knowingly collect data from children.
We will post updates here and, for material changes, notify you in-app or by email.