Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how Himo Tech (“we”) collects, uses, discloses and protects personal information when you use LeadsBullseye (the “Service”), and the rights you have. It covers customers in Canada, the United States, and the EU/UK.

1. Who we are (controller)

Himo Tech is the controller of the account information you provide to us. For business-listing data you collect through the Service, you (our customer) are the controller and we act as your processor — see our Data Processing Agreement.

2. Information we collect

CategoryExamplesPurpose
Account dataName, email, phone, company, role, password (hashed by our auth provider)Create and secure your account; provide the Service
Billing dataPlan, subscription status, and payment identifiers held by Stripe (we do not store full card numbers)Process subscriptions
Usage dataSearches run, leads returned, API request counts, estimated cost, timestampsEnforce quotas, meter usage, operate and improve the Service
Lead data you collectBusiness names, addresses, business phone numbers, website status from public listingsProvided to you as the output of the Service; we process it on your behalf
Enriched business contact dataCustomer-initiated: only when you click to enrich a specific saved lead do we retrieve contact details that business has published publicly — on its own website, in public directories (e.g. Yelp, Yellow Pages, BBB, chamber-of-commerce and industry listings), or on public social/company pages. Each value (email, phone, a role-holder's name where a public page identifies them in that role, or a social/web link) is stored with the source page name, the source URL, a verbatim quoted line from that source, and a retrieval timestampProvided to you as the output of the Service, at your request; we process it on your behalf
Your API keys (BYOK)Google Maps / Gemini keys, if you supply themRun searches/AI on your behalf; stored encrypted, never displayed again
Technical dataIP address, browser type, essential session cookieSecurity, authentication, and delivering the site
Product analytics data (only if you accept analytics cookies)Pages viewed, clicks within the app, approximate location from your IP address, and — once signed in — your account identifier, email, name and plan. Collected via HeyCatch; see our Cookie PolicyUnderstand which features are used so we can improve them. Never used for advertising

3. Is business-listing data “personal information”?

Business contact details are often about an organization rather than an identifiable individual. However, where a listing identifies an individual (for example a sole proprietor’s name, or a personal mobile used as a business number), it can be personal information/personal data under PIPEDA, Quebec Law 25, GDPR and UK GDPR. We therefore treat lead data as potentially personal and handle it under the safeguards in this policy and our DPA. Enriched business contact data obtained through the on-demand contact enrichment feature is treated the same way. You are responsible for having a lawful basis to process and contact the individuals in leads you collect.

4. How we use information & legal bases (GDPR/UK GDPR)

  • To provide the Service — performance of our contract with you.
  • To secure, meter and bill — legitimate interests and performance of contract.
  • To run on-demand contact enrichment — performance of our contract with you, since the feature only runs when you request it for a specific lead. Where GDPR/UK GDPR applies to the individuals whose publicly available business contact details are retrieved, we rely on legitimate interests in processing publicly available business contact information for B2B prospecting; those individuals may object as described in Section 8. You remain responsible for establishing your own lawful basis before using any retrieved contact for outreach.
  • To measure product usage — consent, given by clicking Accept on our cookie banner and withdrawable at any time via Cookie settings in the footer. We set no analytics cookie and send no analytics data — neither from your browser nor from our own servers — unless and until you accept. This includes the account events our servers would otherwise report, such as a subscription change or a credit purchase: if you have not accepted, or you withdraw, they are not sent either.
  • To comply with law — legal obligation.
  • We do not sell or “share” your personal information for cross-context behavioural advertising as defined under CCPA/CPRA, and we do not use it for our own advertising.

5. Retention (including Google Maps data)

  • Account, billing and usage data: kept for the life of your account and as required for legal/tax purposes, then deleted or anonymized.
  • Google-sourced listing content: Google Maps Platform terms permit indefinite storage of a place’s unique identifier (Place ID) but restrict caching of other place content (such as name and address) to a limited period. We retain place identifiers as needed and refresh or purge other Google-sourced fields in line with those terms. You are responsible for your own retention of any data you export.
  • Enriched contact data: data retrieved through the on-demand contact enrichment feature is deleted 30 days after retrieval, on its own clock — refreshing the underlying lead does not extend it — unless you re-run enrichment on that lead. Deleting a lead deletes its enriched contacts.
  • You may delete leads and your account data at any time from within the Service or by contacting us.

6. Who we share with (subprocessors)

We use vetted service providers to run the Service. Current subprocessors are listed in our DPA and include our cloud/database provider (Supabase), payment processor (Stripe), AI/geodata providers (Google), and our product-analytics provider (HeyCatch — used only where you have accepted analytics cookies). We do not sell your personal information.

7. International transfers

Your information may be processed outside your country, including in Canada, the United States, and the EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum) for transfers of EU/UK personal data.

8. Your rights

  • Canada (PIPEDA / Quebec Law 25): access, correction, withdrawal of consent, and (under Law 25) de-indexing/portability and the right to be informed of automated decisions. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information du Québec.
  • US (CCPA/CPRA and similar state laws): know, access, delete, correct, and opt out of sale/share (we do not sell/share); we will not discriminate for exercising rights.
  • EU/UK (GDPR/UK GDPR): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority.

To exercise any right, email hmounir@himo-tech.ca. We will verify your request and respond within the timeframes required by applicable law.

If you are an individual whose contact details were retrieved through our on-demand contact enrichment feature, you may email hmounir@himo-tech.ca to have them deleted from LeadsBullseye systems.

9. Security

We use encryption in transit, row-level tenant isolation, encrypted storage of any API keys you supply (AES-256-GCM), least-privilege access, and access logging. No system is perfectly secure; we will notify you and regulators of breaches as required by law.

10. Children

The Service is for business use and is not directed to children; we do not knowingly collect data from children.

11. Changes

We will post updates here and, for material changes, notify you in-app or by email.

Privacy contact: hmounir@himo-tech.ca · Himo Tech