This Privacy Policy explains how Bounce Watch International Operating B.V. ("Bounce Watch", "we", "us"), Singel 542, 1017 AZ Amsterdam, the Netherlands, collects and processes personal data when you use our websites, applications and APIs (the "Services"). We act as the data controller for the processing described in this policy, except where stated otherwise.
1. Personal Data We Collect
1.1 Data you provide
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email address, password (hashed), company name, job title | Account creation, authentication, communication |
| Profile & preferences | Persona, use cases, target countries, ICP settings, AI agent configuration | Personalizing signals and outreach suggestions |
| Billing data | Payment details (processed by Stripe — we never store full card numbers), VAT number, billing address | Subscription billing |
| Connected email accounts | SMTP/IMAP credentials or OAuth tokens for Gmail/Outlook (stored encrypted) | Sending outreach from your own accounts, at your direction |
| Content | Notes, lists, message templates, contact form submissions | Providing the Services |
1.2 Data collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage data | Pages viewed, features used, clicks, session duration | Product analytics, improving the Services |
| Device data | IP address, browser type, operating system, approximate location (country) | Security, localization, analytics |
| Cookies | See our Cookie Policy | Sessions, analytics, support chat |
1.3 BounceWatch Signal Tracker browser extension
Our optional Chrome extension is covered by this policy. It only operates for users who have signed in to a Signal Tracker account from within the extension.
| What it sends us | When | Why |
|---|---|---|
The domain name of the page you are viewing (for example stripe.com) — not the full URL, path or query string | While the "Show signals as I browse" option is enabled, when a page finishes loading or you switch tabs | To tell you whether that company is in our database, how many recent signals it has, and whether you are already tracking it |
| The company identifier shown in the address bar of a supported research site (LinkedIn, Crunchbase, Dealroom, PitchBook, Wellfound) and the company name and website shown on that page | Only on company profile pages of those five sites | To match the profile you are viewing to a company in our database and show its signals |
| Your account token | With every request | Authentication |
What the extension never collects: full URLs, page contents, text you type, form data, passwords, cookies, screenshots, or your browsing history. Domains are used to answer the lookup you triggered and are not compiled into a profile of your browsing.
Domains that are never sent: search engines, social networks, webmail providers, payment and banking sites, our own site, and any local, private or internal address (for example localhost, *.local, *.internal, or a bare IP address).
Your controls: browse-time lookups and the on-page overlay can each be switched off in the extension's Options page. Signing out of the extension stops all of its requests. Uninstalling it removes the stored token from your browser.
Limited Use: our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell this data, do not transfer it except as required to provide the extension's features, and do not use it for advertising, credit assessment or lending purposes.
1.4 Business contact data in our company database
Our Services compile information about companies and, in limited cases, business contact details of professionals (such as name, role, business email and public professional profile) from publicly available sources. We process this data under our legitimate interest in providing business-intelligence services (Art. 6(1)(f) GDPR). See Section 7 for the rights of data subjects whose information appears in our database.
2. Purposes and Legal Bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and operating the Services | Art. 6(1)(b) — performance of a contract |
| Billing and accounting | Art. 6(1)(b) and 6(1)(c) — contract and legal obligation |
| Sending outreach emails through your connected accounts | Art. 6(1)(b) — performed at your direction; you are responsible for the lawfulness of your outreach (see Terms) |
| Product analytics and improvement | Art. 6(1)(f) — legitimate interest |
| Security, fraud and abuse prevention | Art. 6(1)(f) — legitimate interest |
| Marketing emails to our own users | Art. 6(1)(f) with opt-out, or consent where required |
| Compiling business/company intelligence from public sources | Art. 6(1)(f) — legitimate interest |
3. Processors and Third Parties
We share personal data with service providers ("processors") who process it on our behalf under data processing agreements:
- Hosting & infrastructure: cloud hosting providers in the EU and US (with appropriate transfer safeguards), content delivery (Cloudflare), object storage
- Payments: Stripe
- Email delivery: transactional email providers (for our own notifications — your outreach goes through your own connected accounts)
- Analytics: Google Analytics, configured for analytics only — Google advertising signals and ad personalization are disabled (see Cookie Policy)
- Data enrichment & verification: providers that supply and validate publicly available business contact data used in our company database
- AI processing: large-language-model providers used to generate summaries and draft messages. We do not permit these providers to train their models on your data.
- Messaging: WhatsApp notification provider (only if you enable WhatsApp notifications)
We disclose categories of recipients rather than naming every individual sub-processor; a current sub-processor list is available to customers on request as part of our Data Processing Agreement. We do not sell personal data, and we do not use Google advertising/ad-personalization signals.
4. Automated Processing
We use automated processing, including AI models, to (a) score and rank companies by how well they match your criteria and how timely a signal is, and (b) generate draft outreach messages. These do not produce legal or similarly significant effects on individuals: the scoring targets companies, and every draft message is reviewed and approved by a human (you) before anything is sent. You may object to processing based on legitimate interest, including any profiling, under Art. 21 GDPR.
5. International Transfers
Some of our processors are based in the United States (for example, analytics, certain AI and infrastructure providers). Where personal data is transferred outside the European Economic Area, we rely on (i) the EU–US Data Privacy Framework where the recipient is certified, (ii) the European Commission's Standard Contractual Clauses, and/or (iii) an adequacy decision — supplemented where necessary by additional technical and organizational safeguards.
6. Retention
- Account data: for the life of your account and up to 30 days after deletion (backups may persist up to 90 days).
- Billing records: 7 years (Dutch tax law requirement).
- Connected email credentials: deleted immediately when you disconnect the account or delete your account.
- Usage logs: up to 24 months.
- Company database records: business contact data is re-validated against public sources on a rolling basis (at least every 12 months); records that can no longer be confirmed, or that are subject to a valid objection/erasure request, are removed and added to a permanent do-not-contact suppression list.
7. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption of stored credentials, access controls, audit logging and least-privilege access for personnel. No system is perfectly secure; we will notify you and the competent authority of personal data breaches as required by Articles 33–34 GDPR.
8. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate data (Art. 16);
- Erase your data ("right to be forgotten", Art. 17);
- Restrict processing (Art. 18);
- Data portability (Art. 20);
- Object to processing based on legitimate interest, including profiling (Art. 21);
- Withdraw consent at any time, where processing is based on consent.
If your business contact details appear in our company database and you wish to access, correct or remove them, the fastest way is our self-service page: Your data & privacy rights. You can also contact us via the form below — we will respond within 30 days as required by the GDPR.
You also have the right to lodge a complaint with your supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
9. Children
The Services are not directed at children under 16, and we do not knowingly collect their data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app notice. The "Last updated" date at the top reflects the latest version.
11. Contact
For privacy questions or to exercise your rights:
Bounce Watch International Operating B.V.
Singel 542, 1017 AZ Amsterdam, the Netherlands
Contact form