← Back

Privacy Policy

Last updated: February 21, 2026

1. Introduction

Bullseye Interviews Inc. (“we,” “us,” or “our”) operates the Review Pipe application (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), and other applicable U.S. state privacy laws.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, phone number, business name, and password when you create an account.
  • Customer data: customer names and phone numbers you enter when logging jobs. This data is used solely to send review requests on your behalf.
  • Payment information: processed by Stripe, Inc. We do not store credit card numbers or bank account details on our servers.
  • Google Business Profile data: when you connect your Google account, we access your Google Business Profile reviews and business information to display and respond to reviews within our Service.

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, timestamps, and interaction patterns collected via PostHog analytics.
  • Device information: browser type, operating system, and device type.
  • Error data: application errors and performance data collected via Sentry for debugging purposes.
  • UTM parameters: marketing attribution data from URL parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content).

3. How We Use Your Information

  • To provide and maintain the Service, including sending SMS review requests to your customers on your behalf.
  • To process payments and manage your subscription.
  • To generate AI-drafted review responses for your Google reviews.
  • To send you transactional communications (verification codes, weekly stats, review alerts) via SMS.
  • To improve the Service through analytics and error monitoring.
  • To comply with legal obligations.

4. Third-Party Services

We share data with the following third-party service providers who process information on our behalf:

  • Stripe, Inc. — Payment processing. Subject to Stripe's Privacy Policy.
  • Twilio, Inc. — SMS delivery for review requests, verification codes, and notifications.
  • Google LLC — Google Business Profile integration for review management via OAuth 2.0.
  • DeepSeek — AI-powered review response generation. Review text and business context are sent for processing; no customer phone numbers or personal contact information is shared.
  • PostHog — Product analytics. Collects anonymized usage data.
  • Sentry — Error tracking and performance monitoring. No personally identifiable information (PII) is sent.
  • Vercel — Application hosting and deployment.
  • Railway — Database hosting (PostgreSQL).

5. Data Retention

We retain your account data for as long as your account is active. If you cancel your account, we retain your data for up to 30 days to allow for reactivation, after which it is permanently deleted. Analytics events are automatically pruned after 90 days. Verification tokens expire after 5 minutes and are cleaned up daily.

6. Data Security

We implement industry-standard security measures including: encrypted connections (HTTPS/TLS), bcrypt password hashing, rate-limited authentication endpoints, session version tracking for revocation, encrypted storage of sensitive credentials, and strict Content Security Policy headers.

7. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate data.
  • Right to erasure: Request deletion of your personal data.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent.

Our legal basis for processing your data is: (a) performance of a contract (to provide the Service), (b) legitimate interests (analytics, security), and (c) consent (marketing communications).

8. Your Rights Under CCPA/CPRA

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to delete: Request deletion of your personal information.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt-out of sale/sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: We only use sensitive personal information as necessary to provide the Service.
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.

Categories of personal information collected: Identifiers (name, email, phone), commercial information (subscription status), internet activity (usage data), and geolocation (country code).

We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than providing the Service.

9. Additional U.S. State Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws have similar rights to access, correct, delete, and opt out of targeted advertising. To exercise these rights, contact us using the information below.

10. Cookies and Tracking

We use essential cookies for authentication and session management. Our analytics provider (PostHog) may use cookies or similar technologies to collect usage data. We do not use advertising cookies or trackers. You can manage cookie preferences through your browser settings.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that we have collected data from a minor, we will delete it promptly.

12. International Data Transfers

Your data is processed and stored in the United States. If you access the Service from outside the U.S., your information may be transferred to, stored, and processed in the U.S. where data protection laws may differ from your jurisdiction. By using the Service, you consent to such transfers. For EEA/UK users, transfers are governed by Standard Contractual Clauses where applicable.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

To exercise your privacy rights or if you have questions about this policy, contact us at:

Bullseye Interviews Inc.
Email: support@pipenomics.com

For GDPR inquiries, you also have the right to lodge a complaint with your local data protection authority.