Privacy Policy
Last updated: June 14, 2026
1. Who we are
Bolsivo ("Bolsivo," "we," "us," or "our") is a B2B software-as-a-service platform that helps service business owners in the United States find, qualify, and contact potential business clients using publicly available data and AI-assisted tools. Our registered service operates at https://bolsivo.com.
This Privacy Policy explains how we collect, use, share, and protect information when you use our platform. It applies to all users of Bolsivo, including account holders, organization members, and visitors to our website.
2. Information we collect
2.1 Information you provide
- Account information: email address, full name (optional), organization name, service type, operating city
- Business profile: business name, "from" email address, phone, website, postal address, services offered
- Pricing profile (Scale plan): hourly rates, margins, payment methods, proposal templates
- Content you create: campaign configurations, email draft edits, notes on leads, estimate details
- Payment information: processed entirely by Stripe. We never store raw card numbers.
2.2 Information we collect automatically
- Session and authentication tokens (managed by Supabase Auth)
- Language preference (stored as a cookie)
- Feature usage events: which actions you take in the app (e.g., campaign created, email approved)
- Timestamps of key actions for audit and compliance purposes
2.3 Third-party data about business prospects
When you use Bolsivo to search for prospects, we query the Google Places API on your behalf to display publicly available information about local businesses. You then select which businesses to add as leads to your account.
- We store the Google
place_idindefinitely for deduplication — explicitly permitted by Google's Terms of Service (Maps Platform § 3.2.3) - Business name and address are stored to support basic lead management functionality
- Dynamic data (phone, rating, website) is fetched on-demand using the stored
place_idand displayed without being persisted — following Google's recommended "store the reference, not the content" pattern - Data is used only for outreach within the scope of your campaigns
- Never sold to third parties
- Displayed with required Google attribution per Maps Platform policies
Important: Bolsivo is a B2B-only platform. We prioritize business-level data (legal name, commercial address, website). However, data associated with small businesses or sole proprietors may contain personal information (e.g., emails in the format name@business.com, direct phone numbers). We minimize collection of individual-level data and avoid storing personal information where possible.
3. How we use your information
- To provide the service: searching for prospects, scoring leads, generating email drafts, processing estimate calculations, delivering PDF proposals
- To operate billing: creating Stripe checkout sessions, managing subscription status, processing plan upgrades and cancellations
- To send platform communications: daily digest emails (pending approvals and lead summaries) sent only to the account owner of the relevant organization
- To enforce safety and compliance: maintaining suppression lists, enforcing per-day email limits, logging approval actions for audit purposes
- To improve the product: aggregated, anonymized usage data to understand which features are used. We do not sell this data.
- To comply with law: responding to lawful requests, enforcing our Terms of Service
4. Email outreach and CAN-SPAM compliance
Bolsivo is designed as a human-in-the-loop outreach tool. No email is sent to any prospect without explicit, individual approval from the account user. This is a core design principle, not a configurable setting.
- All outbound emails include the sender's physical postal address
- All outbound emails include a visible unsubscribe mechanism
- Unsubscribe requests result in immediate suppression — the email address is added to a suppression list and never contacted again through Bolsivo
- Daily send limits are enforced per organization to prevent abuse
- Hard bounces are not retried
- We log each email approval: who approved it, when, which campaign, and which version of the draft
Users are responsible for ensuring their outreach complies with CAN-SPAM, CASL (if targeting Canadian businesses), and any other applicable laws in their jurisdiction.
4b. SMS, voice, and call recordings (Luna AI)
When the Luna AI receptionist feature is enabled, Bolsivo may send outbound SMS messages and handle voice calls through Twilio and Retell AI. The following applies:
- Call recordings: calls handled by Luna AI may be recorded and processed by Retell AI for quality, transcription, and analysis purposes. Recordings are stored temporarily. Users are responsible for complying with applicable call recording consent laws in their jurisdiction — some states (including California under Penal Code §632) require all parties to consent before a call is recorded. Consult legal counsel regarding your disclosure obligations before enabling call recording in any state.
- AI disclosure: certain jurisdictions may require callers to be informed that they are speaking with an AI system. Users are responsible for configuring Luna AI to provide appropriate disclosures under applicable state and local laws.
- SMS opt-out: recipients can reply STOP to any SMS to opt out immediately. Opt-outs are honored automatically and no further SMS messages are sent to that number.
5. Data sharing and subprocessors
We share data with the following trusted subprocessors to operate the service:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, auth, storage | All user and org data |
| Anthropic (Claude) | AI lead scoring, email generation | Lead public data, campaign config. User email data passed to Claude is not used to train AI models. |
| Google Places API | Business prospect search | Search query (city + industry) |
| Google OAuth / Gmail API | Gmail inbox sync for Unibox (scope: gmail.modify) | Email message content, metadata — only for accounts that explicitly connect Gmail |
| Yelp Fusion API | Supplemental business prospect search | Business name and address used for lead discovery. Only the Yelp business ID is stored; dynamic data (rating, phone) is never persisted per Yelp API Terms § 5(a). |
| Resend | Email delivery | Approved email content + recipient |
| Twilio | SMS delivery and voice communications | Phone number, SMS message content — only for accounts with SMS or voice features enabled |
| Retell AI | AI voice receptionist (Luna feature) | Call audio, transcripts, call metadata — only for accounts with Luna AI receptionist enabled |
| Stripe | Payment processing | Email, org name, subscription data |
| Vercel | Hosting and CDN | Request logs (IP, user agent) |
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
6. Data retention
- Active accounts: data is retained for as long as your account is active
- Cancelled accounts: organization data is retained for 90 days after cancellation, then deleted
- Audit logs: retained for 2 years for compliance purposes
- Suppression lists: retained indefinitely to prevent re-contacting opted-out addresses
- Stripe billing data: governed by Stripe's retention policies
7. Your rights
Depending on your location, you may have the following rights:
- Access: request a copy of the data we hold about you
- Correction: update inaccurate or incomplete data
- Deletion: request deletion of your account and associated data
- Portability: receive your data in a machine-readable format
- Objection: object to certain processing activities
To exercise any of these rights, email us at privacy@bolsivo.com. We will respond within 30 days.
California residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete it, and the right to opt out of any sale of personal information. We do not sell personal information. To submit a request, contact privacy@bolsivo.com.
8. Security
We implement industry-standard security practices including:
- All data transmitted over HTTPS with HSTS enforced
- Row-Level Security (RLS) on all database tables — each organization can only access its own data
- API keys and secrets stored only in server-side environment variables, never exposed to the browser
- Stripe webhook signature verification on all payment events
- Rate limiting on lead searches, email sends, and API endpoints
No security system is perfect. If you discover a vulnerability, please report it responsibly to privacy@bolsivo.com.
9. Cookies
We use the following cookies:
- Authentication cookies: set by Supabase Auth to maintain your session. Required for the service to function.
- Language preference cookie: stores your preferred language (ES/EN). Expires after 1 year.
We do not use advertising cookies or third-party tracking cookies.
10. Children's privacy
Bolsivo is a B2B platform intended for business owners and professionals. We do not knowingly collect information from individuals under 18. If you believe we have collected information from a minor, contact us at privacy@bolsivo.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify active account holders of material changes by email. Continued use of Bolsivo after the effective date constitutes acceptance of the updated policy. The most current version is always available at https://bolsivo.com/privacy.
12. Contact
For any privacy-related questions or requests:
BolsivoEmail: privacy@bolsivo.com
Website: https://bolsivo.com