LeadsBullseye

Privacy Policy

Last updated: 19 July 2026

Template notice. This is a starting template for LeadsBullseye, not legal advice. Have a qualified privacy lawyer review it for PIPEDA, Quebec Law 25, CCPA/CPRA, GDPR and UK GDPR before production use.

This Privacy Policy explains how Himo Tech (“we”) collects, uses, discloses and protects personal information when you use LeadsBullseye (the “Service”), and the rights you have. It covers customers in Canada, the United States, and the EU/UK.

1. Who we are (controller)

Himo Tech is the controller of the account information you provide to us. For business-listing data you collect through the Service, you (our customer) are the controller and we act as your processor — see our Data Processing Agreement.

2. Information we collect

CategoryExamplesPurpose
Account dataName, email, phone, company, role, password (hashed by our auth provider)Create and secure your account; provide the Service
Billing dataPlan, subscription status, and payment identifiers held by Stripe (we do not store full card numbers)Process subscriptions
Usage dataSearches run, leads returned, API request counts, estimated cost, timestampsEnforce quotas, meter usage, operate and improve the Service
Lead data you collectBusiness names, addresses, business phone numbers, website status from public listingsProvided to you as the output of the Service; we process it on your behalf
Your API keys (BYOK)Google Maps / Gemini keys, if you supply themRun searches/AI on your behalf; stored encrypted, never displayed again
Technical dataIP address, browser type, essential session cookieSecurity, authentication, and delivering the site

3. Is business-listing data “personal information”?

Business contact details are often about an organization rather than an identifiable individual. However, where a listing identifies an individual (for example a sole proprietor’s name, or a personal mobile used as a business number), it can be personal information/personal data under PIPEDA, Quebec Law 25, GDPR and UK GDPR. We therefore treat lead data as potentially personal and handle it under the safeguards in this policy and our DPA. You are responsible for having a lawful basis to process and contact the individuals in leads you collect.

4. How we use information & legal bases (GDPR/UK GDPR)

5. Retention (including Google Maps data)

6. Who we share with (subprocessors)

We use vetted service providers to run the Service. Current subprocessors are listed in our DPA and include our cloud/database provider (Supabase), payment processor (Stripe), and AI/geodata providers (Google). We do not sell your personal information.

7. International transfers

Your information may be processed outside your country, including in Canada, the United States, and the EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum) for transfers of EU/UK personal data.

8. Your rights

To exercise any right, email hmounir@himo-tech.ca. We will verify your request and respond within the timeframes required by applicable law.

9. Security

We use encryption in transit, row-level tenant isolation, encrypted storage of any API keys you supply (AES-256-GCM), least-privilege access, and access logging. No system is perfectly secure; we will notify you and regulators of breaches as required by law.

10. Children

The Service is for business use and is not directed to children; we do not knowingly collect data from children.

11. Changes

We will post updates here and, for material changes, notify you in-app or by email.

Privacy contact: hmounir@himo-tech.ca · Himo Tech