Privacy policy
Last updated 20 September 2026
BuyerPing finds people who are publicly signalling that they are ready to buy, and hands our customer the evidence. That means we process personal data about two different groups, and the rules are different for each. This page says which is which in plain terms.
The two groups of people in this policy
Customers are the people who sign up and use BuyerPing. Tracked people are the ones our customers' searches surface, someone who posted publicly about a product, or who visited a customer's website. We are the data controller for customer data. For tracked people we act as a processor on our customer's instructions, and the customer is the controller.
The single most important thing to know about the second group: we never send them email, ever. Not a newsletter, not an outreach message, not a notification. It is the product's core promise, it is enforced in our build pipeline, and the mail permissions we request from Google and Microsoft are read-only, so we could not send from a customer's mailbox even if we tried.
What we collect about customers
- Account details. Your name, work email address and the workspace you belong to. Sign-in is handled by Clerk; we never see or store your password.
- Billing details. Your plan, your billing contact and your invoice history. Card numbers go directly to Stripe and never reach our servers.
- What you connected, which CRM, Slack workspace, mailbox or calendar you linked, and the access tokens for them. Those tokens are encrypted before they are written down.
- How you used the product, which leads you accepted or rejected, when runs happened, what they cost us. The accept and reject decisions are also what train your scoring.
- Ordinary technical logs, request times, errors and the like.
What we collect about tracked people
Two sources, and they are genuinely different. The first is public: posts, comments, reviews and articles that anybody can read without logging in, Reddit, Hacker News, public forums, news and job feeds, and X where a customer has connected it. We keep the quote, a working link back to it, who wrote it, when, and what our model made of it.
The second is the customer's own website. A customer can install our pixel, which records visits to their pages. Outside the United States that is company-level only , we resolve the visitor's network to an organisation and go no further. Person-level matching is United States only, requires the customer to have completed a data protection impact assessment, requires consent through their consent banner, and is geofenced in the script itself. People in the EU and the UK are excluded from person-level matching.
We also try to find a work email address for a tracked person, and we stop at the first answer. In order: an address they published in the post itself, then their public profile, then a match from Apollo where a real name is known, then a guess built from the company's address format, and a guessed address is never shown to anybody unless ZeroBounce confirms the mailbox accepts mail. People who post on X stop at the first two steps, because matching an X account to a person off X is not something its users agreed to.
How long we keep it
A public post is only useful while it is recent, so we apply an age limit per search type and discard anything older:
| Search type | Oldest signal we will use |
|---|---|
| Competitor switching | 30 days |
| Front-door (a competitor's own forum, status page or pricing) | 14 days |
| Funding, hiring and leadership triggers | 60 days |
| Life events | 60 days |
| Brand mentions and custom searches | 30 days |
Customer account data is kept while the account is open and deleted afterwards on request. Website sessions recorded by the pixel are kept for as long as the customer who installed it configures.
Who else processes it
These are the companies that handle data on our behalf. The list is taken from our own deployment configuration rather than from a template, so it is what is actually running.
| Who | What they do for us | What reaches them |
|---|---|---|
| Render | Hosting, database and cache | Everything the product stores |
| Clerk | Sign-in and sessions | Customer name, email, session |
| Stripe | Payments and metered billing | Billing contact, plan, usage counts |
| OpenRouter (running DeepSeek), with OpenAI as fallback | Judging whether a post shows buying intent, and drafting suggested replies | The text of public posts, which can contain personal data |
| Apollo | Company details, and matching a name to a work address | Company domains; a name where one is known |
| ZeroBounce | Checking whether an address accepts mail | One email address per check |
| Resend | Our own email to customers, invites, resets, digests | Customer email addresses only |
| Upstash | Scheduling runs | Job identifiers, no personal data |
Separately, a customer can connect their own HubSpot, Pipedrive, Salesforce, Slack, Google or Microsoft account. Those are the customer's own tools and their own choice; we push leads into them and read outcomes back, and mail and calendar permissions are requested read-only.
The model providers deserve one extra sentence, because it is the question a security reviewer asks: the text of a public post is sent to them to be classified and, where a customer asks for a draft, to be written about. It is treated strictly as data. Nothing a model returns is allowed to choose a destination, a URL or a recipient.
Having your data removed
If you are a tracked person and you want to be removed, write to us and we will erase you. It is one operation and it covers everything: the signals, the quotes we kept, any leads built from them, and any website sessions.
It also adds you to a suppression list, which matters more than the deletion does. Without it the next search would simply find the same public post again and rebuild the same record. The suppression list is keyed so that we can recognise you again without keeping a readable copy of what you asked us to delete.
If you are a customer, you have the usual rights over your own account data, see it, correct it, export it, delete it. Ask and we will do it.
How it is protected
- Every workspace's data is isolated at the database level, not only in application code, so a bug in a query cannot return another customer's rows.
- Credentials for connected accounts are encrypted before storage.
- Incoming webhooks are signature-verified; we reject anything unsigned.
- Mail and calendar permissions are read-only, by design and not by policy.
- We pay for every source and enrichment call ourselves. Those costs are never passed on to you, and we have no incentive to over-collect.
Contact
Write to help@buyerpingai.com for anything on this page: an erasure request, a question about what we hold, or a data processing agreement.