Privacy Policy
Last updated: September 2026
Overview
bizvoid collects only the data necessary to provide its service. We do not sell your personal data. On our public marketing pages, and only if you consent, we use the Meta (Facebook) Pixel and TikTok Pixel to measure our advertising; everywhere else, including the logged-in app, we use only strictly necessary cookies.Cookies
bizvoid uses strictly necessary cookies for authentication (always on: they cannot be disabled without breaking login), and marketing cookies only with your consent on our public pages (see below).
| Cookie | Purpose | Duration |
|---|---|---|
sb-*-auth-token | Your login session (JWT access token) | 1 hour (auto-refreshed) |
sb-*-auth-token-code-verifier | OAuth PKCE security code verifier | Session |
These cookies are set by our authentication provider (Supabase) and are classified as strictly necessary under GDPR Article 6(1)(b): processing necessary for the performance of a contract. No consent is required to set them, but we disclose them here for transparency.
Marketing cookies (consent only). If you click Accept all cookies on our cookie banner, our public marketing pages load the Meta (Facebook) Pixel, the TikTok Pixel, and the Google Ads tag, which set advertising cookies and share limited event data (for example page views) with Meta, TikTok, and Google to measure our advertising. These are not set unless you consent, are never loaded in the logged-in app, and you can withdraw consent at any time by choosing Necessary cookies only on the banner or clearing your browser cookies.
With the same consent, we may also send conversion events (for example a completed purchase) to Meta server-side via its Conversions API to measure our advertising. Your email is hashed (SHA-256) before it is sent (Meta does not receive it in readable form), and each event is de-duplicated so it is only counted once. We send these events only if you have accepted marketing cookies.
If you complete a purchase and have accepted marketing cookies, we also report that conversion to Google Ads (the plan and amount charged only, no other account or personal data) to measure our advertising. This is not set unless you consent.
Email communications
When you create a bizvoid account, we send a small number of onboarding and account emails to help you get started and to let you know about relevant plan options and offers. These are sent directly by bizvoid, not through the marketing cookies described above, and do not depend on cookie consent.
Every one of these emails includes an unsubscribe link, and unsubscribing takes effect immediately. Transactional emails tied to your account or billing (for example a receipt or a password reset) are not affected by unsubscribing, since they are not marketing.
Data we collect
- Email address and password hash (for account authentication)
- Subscription and billing data (via Stripe: we do not store card numbers)
- Usage data: zip scans, audits, and pitches performed (for credit accounting)
- Optional profile fields: name, agency name, phone, website (for AI pitch generation)
- If you invoice your own clients: your connected Stripe account identifier, its country, currency, and payment status, plus each invoice's amount, description, billing contact, and whether it was paid. We do not receive your identity documents or bank details. See Client billing & Stripe Connect.
Google Sign-In. If you create an account or sign in using Google, we receive your email address, name, profile picture URL, and Google account identifier from your Google profile. We use this solely to create and authenticate your BizVoid account and to display your name and avatar within the application. We do not use Google user data for advertising, do not sell it, and do not share it with third parties except our infrastructure providers acting on our behalf. This data is retained for the life of your account and permanently deleted within 30 days of account deletion. You can delete your account at any time from Settings, or by emailing support@bizvoid.com. You may also revoke BizVoid’s access at any time via your Google Account permissions page.
SMS / text messaging
bizvoid’s Cold Call Coach feature lets a bizvoid customer text their own leads and customers from a dedicated phone number. If you text or call that number, the bizvoid customer (the business you contacted) can reply to you through the bizvoid platform using that same number.
We do not sell or share your mobile phone number with third parties for their own marketing purposes. Your number is used solely to deliver messages between you and the bizvoid customer you contacted, and is processed by our messaging infrastructure provider (Twilio) strictly to send and receive those messages on our behalf.
Message frequency varies depending on your conversation with the business you contacted. Message and data rates may apply. You can opt out of receiving further messages at any time by replying STOP, or reply HELP for support.
Sanctions compliance & IP geolocation
As a US company, we are legally required to block access to the Service from countries and regions under comprehensive US (OFAC) sanctions. To comply, we determine the approximate country and region of each visit by looking up the visitor's IP address in a MaxMind GeoLite2 database hosted on our own servers. This lookup happens entirely on our infrastructure: your IP address is never sent to MaxMind or any other third party for this purpose. The legal basis for this processing is compliance with a legal obligation (GDPR Article 6(1)(c)). If a visit is blocked, we keep an internal record of the attempt (IP address, detected country or region, and the page requested) as part of our compliance records.
Separately, if you set a prospecting country in your profile, we may compare it against your IP-derived country and, if you have one, your card billing country to detect misuse of the Service (legitimate interest, GDPR Article 6(1)(f)). A mismatch is only logged internally for review; it never blocks your account on its own.
How results are displayed over time
Scan results, website audits, generated pitches, and similar results you generate in the app remain in your account and gradually fade in the interface after 30 days, so more recent results stand out visually. This fading is a display convention only: it does not delete anything, does not affect any saved-item limit your plan allows, and does not change how long we retain the underlying data. Your data remains available for as long as your account is active, or until you delete your account (see “Your rights” below).
Third-party services
- Supabase: authentication and database (EU/US servers)
- Stripe: payment processing, and (if you invoice your own clients) identity verification, payouts, and fraud and sanctions screening for your connected account. Stripe is an independent controller of the verification data you give it directly.
- OpenRouter / Google: AI inference for pitch and audit features
- Google Places / PageSpeed APIs: business and website data lookup
- MaxMind GeoLite2: IP-to-region database used for sanctions compliance; runs entirely on our servers, no visitor data is shared with MaxMind
- Meta (Facebook) Pixel: advertising measurement on our public pages, loaded only with your consent
- TikTok Pixel: advertising measurement on our public pages, loaded only with your consent
- Google Ads: advertising measurement on our public pages plus purchase conversion reporting after checkout, loaded only with your consent
We do not use Google Analytics or Intercom. The Meta and TikTok Pixels, and Google Ads conversion reporting, are used solely to measure our own advertising, only after you consent, and never inside the logged-in app.
Google API Services User Data Policy & Limited Use
bizvoid’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect Google Meet to create real meetings for your bookings, bizvoid requests the calendar.events scope, used only to create, update, or delete a single Calendar event for each appointment booked through your shared link. The only information written to that event is the client’s name and the appointment’s start and end time. No meeting description and no attendee list is ever added to the event, and no Google Calendar or Workspace data is read back beyond what is needed to update or cancel that same event later.
Data obtained through this or any other Google API is never used to train, improve, or fine-tune any machine learning or AI model, ours or a third party’s, and is never sold, shared with advertisers, or used for any purpose beyond creating and maintaining your calendar event. bizvoid’s AI features (used for cold-outreach pitch drafts, website audit reports, and Site Builder content, via OpenRouter and Google’s Gemini API) run only on a freelancer’s own business details or on publicly available information about a prospective lead’s business, never on Google Calendar or Workspace data.
Bizvoid's Own Advertising Accounts
This section describes BizVoid’s own read-only access to its own Google Ads campaign data, via a separate Google Cloud project; it involves no end-user data and is unrelated to Google Sign-In above.
Our internal operations dashboard (BizVoid Ops) accesses campaign performance and spend data from a single Google Ads account owned by BizVoid LLC via the Google Ads API. This access is strictly read-only and used exclusively for internal analytics displayed to authorized BizVoid team members. Google Ads data is not shared with BizVoid customers, third parties, or advertisers, and is not used for profiling or advertising purposes. It is retained only as long as needed for internal reporting.
Data Protection
BizVoid LLC implements the following measures to protect sensitive data, including data accessed via the Google Ads API through BizVoid Ops:
- Encryption in transit and at rest. All data transmitted between our services, third-party APIs (including Google Ads), and our database is encrypted using industry-standard TLS. Data stored in our database is encrypted at rest using the security infrastructure provided by our cloud database provider (Supabase / PostgreSQL with AES-256 encryption).
- Access controls. Access to sensitive data, including Google Ads data accessed via BizVoid Ops, is restricted to authorized BizVoid team members and administrators. Access is protected by strong authentication requirements including two-factor authentication (2FA). All administrative access is logged and auditable.
- Credential management. API credentials, OAuth tokens, and other secrets used to access third-party services (including Google Ads) are stored as environment variables in secure production infrastructure and never committed to source code. Access to production credentials is restricted to authorized administrators.
- Data minimization. BizVoid Ops requests only the minimum scope of Google Ads API access necessary for its function (
https://www.googleapis.com/auth/adwords), used solely for reading campaign performance and spend data. We do not request or use additional Google API scopes beyond what is required. - Data retention and deletion. Google Ads data accessed through BizVoid Ops is retained only as long as needed for internal reporting purposes. Cached data is subject to a 30-day maximum retention period consistent with the Google Maps Platform / Google Ads API caching requirements. Users may request deletion of their personal data at any time by contacting admin@bizvoid.com.
- Incident response. In the event of a security incident affecting user data, BizVoid LLC will notify affected users and, where required by law, regulatory authorities within the timeframes required by applicable data protection regulations.
- Third-party access. Data accessed via the Google Ads API is not shared with third parties, resold, or used for advertising or profiling purposes. It is used exclusively for internal analytics displayed to authorized BizVoid team members.
Creator Program
BizVoid runs a separate creator program, Bizvoid Creator Payouts, open to independent creators who produce content featuring BizVoid and may be compensated for it. Creators are not BizVoid customers, and this Privacy Policy does not cover the personal data BizVoid collects about them. That is covered by the Creator Privacy Notice published on ops.bizvoid (the app bizvoid also uses to run staff operations and the Bizvoid Creator Payouts program), where creators log in to submit content and track payouts.
Client billing & Stripe Connect
If you use client billing to invoice your own clients, that feature runs on Stripe Connect and involves two sets of personal data: yours, and your clients'.
Your verification data goes to Stripe, not to us
To pay you, Stripe is legally required to verify who you are. It collects that information directly from you through its own onboarding, which we embed in our app for convenience. Depending on your country and business type, Stripe may ask for your legal name, date of birth, home or business address, government identification document, tax identification number, and bank account details.
We never receive or store those documents, your government ID, or your bank account number. They pass from you to Stripe. Stripe acts as an independent controller of that data under its own privacy policy, which you should read before onboarding. What we receive back from Stripe is limited to:
- your connected account identifier;
- the country and currency of that account;
- whether the account can currently accept payments and receive payouts;
- a list of what Stripe still requires, so we can tell you what is outstanding.
Your account country is permanent once set, because Stripe does not allow it to be changed after an account is created.
Your clients' data, and who is responsible for it
When you invoice a client, we process that client's billing name, billing email, the invoice amount and description, and its payment status. Card details are entered directly with Stripe and are never stored by us.
You are the controller of your clients' data and we are your processor for it. You decide who to invoice and what to say. You are responsible for having a lawful basis to bill that person, for the accuracy of the billing contact you enter, and for answering their questions about how you handle their information. We process it only to issue the invoice, route the payment, tell you whether it was paid, and keep the financial records the law requires us to keep.
Where the money goes affects the data
Which path applies is determined automatically by your account's country. Where your country supports accepting card payments directly, your client pays you and the transaction record lives in your own Stripe account. Where your country can receive payouts but cannot accept card payments directly, the payment is collected through our platform account and forwarded to you, so we are a party to the transaction record and retain it as our own financial record. In both cases we retain invoice metadata for as long as tax, accounting, and anti-fraud obligations require, which is generally longer than the rest of your account data and survives deletion of your account.
International transfers and fraud screening
Client billing is available in many countries, so your data and your clients' data may be transferred to and processed in the United States and in other countries where Stripe operates, under the safeguards described in Stripe's own privacy policy. Stripe also screens transactions and accounts for fraud, sanctions, and money laundering, and may restrict, delay, or decline an account or a payment on that basis. Those decisions are made by Stripe under its own legal obligations, and Stripe does not always tell us the reason.
Tax documents
Where the law requires a tax form for payments processed through your connected account, Stripe prepares, files, and delivers it, normally by email and through its own document interface. In the United States this is commonly a Form 1099-K. Stripe may ask you for tax information, including a taxpayer identification number, and holds that information itself.
The Documents tab in your profile links you through to the documents Stripe holds for your account. We do not prepare these documents, do not receive copies of them, and do not store them. Opening one takes you to Stripe. A correction to a form must be pursued with Stripe, since we cannot amend a document we never held.
Your rights
You may ask us for a copy of the billing data we hold about you, or ask us to correct it, as described under Your rights below. Requests about the identity, banking, and tax data you gave to Stripe must go to Stripe, since we do not hold it. We cannot delete financial records we are required by law to retain, and deleting a connected account is done through Stripe.
AI Voice Agents & automated messages
If a bizvoid customer runs an AI agent on their business number, calls to and messages with that number are processed as follows.
Voice calls. Call audio is streamed to Deepgram, which converts speech to text, generates a reply and speaks it back. Deepgram processes the audio to provide that service. bizvoid stores the resulting transcript so the business can see what was discussed, and the call's duration for billing. We do not sell call audio or transcripts.
Text messages. Messages are sent and received through Twilio. We store the message body, the numbers involved, and the time, so the business has a record of the conversation.
Opting out. Reply STOP to any agent message to stop further messages from that business, or STARTto resume. We keep a record of that opt-out — the number, the keyword and the time — specifically so it can be enforced on every later send. That record is kept for as long as the business's account exists, because deleting it would allow messaging to resume, which is the opposite of what you asked for.
Who is responsible.The business running the agent decides who to contact and is the controller of that contact. bizvoid provides the tooling. If you want your details removed from a particular business's records, contact that business; if you want to reach us, use the address below.
Your rights
Under GDPR and CCPA, you have the right to access, correct, or delete your personal data. You can permanently delete your account and all of your data yourself at any time from Settings → Account → Delete account. This is immediate and irreversible: it cancels any active subscription and permanently removes your data, and it cannot be undone. To exercise any other right, or if you prefer we handle the deletion, contact us at support@bizvoid.com.
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice. Continued use after changes constitutes acceptance.