1. Scope of this Policy
This Policy applies to personal information processed by Bobbuilt in connection with the Services, including information collected through the Site, our marketing pages, our customer dashboard, our APIs, our voice and SMS features, our embedded widgets, and our communications with you (such as email, phone, and in-product messaging).
This Policy does not apply to information that our customers (insurance agencies and brokers) collect from their own leads, prospects, and clients using the Services. In those cases, Bobbuilt acts as a service provider or processor on behalf of the customer (the “controller” or “business”), and the customer’s privacy notice governs that processing. If you are a consumer who received a call, text, email, or quote from a Bobbuilt customer, please contact that customer directly to exercise rights regarding their processing of your information.
2. Who we are
Bobbuilt, Inc. is a Delaware corporation with its principal place of business at 1209 N Orange Street, Wilmington, Delaware 19801, United States. For data protection purposes, Bobbuilt is the controller of personal information we collect about visitors to the Site, prospects, customers, and customer personnel. For personal information processed on behalf of our customers, Bobbuilt is a processor and our Data Processing Addendum (“DPA”) governs that processing.
3. Information we collect
We collect the categories of personal information described below. The specific information we collect depends on how you interact with us.
3.1 Information you provide directly
- Identifiers and contact details: name, business email, phone number, mailing address, job title, employer, and producer license information.
- Account credentials: username, password hash, multi-factor authentication secrets, and recovery information.
- Billing information: billing contact, billing address, tax identification numbers, and the last four digits and brand of payment cards. Full card numbers are collected and stored by our PCI-DSS Level 1 payment processor, not by Bobbuilt.
- Customer content: configurations, funnel content, ad creative, scripts, contact lists, and other content you upload, submit, or generate within the Services.
- Communications: the contents of emails, support tickets, chat messages, survey responses, and call recordings (where lawfully recorded with notice and consent).
3.2 Information collected automatically
- Device and connection data: IP address, device identifiers, browser type and version, operating system, language preferences, and referring URLs.
- Usage data: pages and screens viewed, features used, clicks, scroll depth, session timestamps, error logs, and performance telemetry.
- Approximate location: coarse location derived from IP address (typically city and region). We do not collect precise GPS location from the Site.
- Cookies, pixels, and similar technologies: see Section 14 below.
3.3 Information from third parties
- Identity and enrichment providers (e.g., business email verification, company firmographics) used to validate accounts and prevent fraud.
- Advertising and analytics partners (e.g., Meta, Google, Microsoft Clarity) that share aggregated campaign and engagement data with us.
- Integrations you connect (e.g., CRM, calendar, telephony, ad accounts), limited to the scopes you authorize at connection time.
- Public sources such as state insurance department licensing databases.
4. Sources of information
We obtain personal information (i) directly from you, (ii) automatically from your device when you use the Services, (iii) from our customers if you are a contact at a customer organization, and (iv) from the third parties described in Section 3.3.
5. How we use information
We use personal information for the following business and commercial purposes:
- Provide and operate the Services, including authenticating users, processing transactions, delivering features, and maintaining the security and availability of the platform.
- Customer support, including responding to inquiries, diagnosing issues, and providing technical assistance.
- Billing and accounting, including processing payments, calculating taxes, preventing fraud, and collecting amounts owed.
- Product improvement and analytics, including measuring engagement, identifying defects, and developing new features. Where feasible, we use aggregated or de-identified data for these purposes.
- Marketing and sales, including sending product updates, newsletters, event invitations, and other communications you can opt out of at any time.
- Security and abuse prevention, including detecting and preventing unauthorized access, malicious activity, spam, and violations of our Terms of Service.
- Legal and compliance, including meeting our obligations under applicable law, responding to lawful requests from public authorities, and enforcing our agreements.
6. Legal bases for processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — to provide the Services you have requested.
- Legitimate interests — to operate, secure, and improve our business, where those interests are not overridden by your rights and freedoms.
- Consent — where required, for example for certain cookies and direct marketing. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Compliance with legal obligations — for tax, accounting, and regulatory requirements.
7. How we share information
We do not sell personal information for money. We disclose personal information only as described in this Policy and only to the categories of recipients below.
- Subprocessors and service providers that perform services on our behalf (hosting, storage, email, telephony, analytics, payments, customer support tooling, AI infrastructure) under written agreements that restrict their use of personal information.
- Customer-authorized integrations when you choose to connect a third-party product (e.g., your CRM or ad account) to the Services.
- Professional advisors such as auditors, attorneys, accountants, and insurers, bound by confidentiality obligations.
- Corporate transactions — in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to this Policy.
- Law enforcement, regulators, and others when required by law, subpoena, court order, or other legal process, or to protect our rights, your safety, or the safety of others.
- With your consent or at your direction.
For purposes of certain US state privacy laws, our use of cookies and similar technologies to support digital advertising may be considered “sharing” or “targeted advertising.” You can opt out as described in Section 13.
8. Subprocessors
We use a limited set of trusted subprocessors to deliver the Services. Current categories include cloud hosting and database, email delivery, SMS and voice telephony, analytics and session replay, customer support, payments, and AI inference. A current list of subprocessors is available on request to the contact form at bobbuilt.io/contact. We require subprocessors to implement appropriate technical and organizational security measures.
9. International data transfers
Bobbuilt is headquartered in the United States and processes personal information there. When we transfer personal information from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), supplemented by additional technical and organizational measures. A copy of the relevant safeguards is available on request.
10. Data retention
We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:
- Account records: for the life of the account plus 24 months after closure.
- Billing and tax records: at least 7 years to meet US tax requirements.
- Customer content and lead data: as configured by the customer in the Services, or per the DPA.
- Server, security, and audit logs: up to 13 months.
- Encrypted backups: rotated on a 35-day cycle.
When retention is no longer required, we either delete the information or irreversibly de-identify it.
11. Security
We maintain a written information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Measures include TLS 1.2+ in transit, AES-256 encryption at rest, role-based access control, least-privilege access, mandatory multi-factor authentication for production systems, audit logging, vulnerability scanning, penetration testing, and an annual security review. No system is 100% secure; we cannot guarantee absolute security but will notify affected individuals and regulators of a personal data breach as required by law.
12. Your privacy rights
Subject to applicable law and certain exceptions, you may have the following rights regarding personal information we hold about you:
- Access — request confirmation of whether we process your personal information and a copy of it.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion of personal information, subject to exceptions such as our need to retain records for legal or accounting purposes.
- Portability — receive a copy of certain personal information in a structured, machine-readable format.
- Restriction or objection — request that we restrict or stop certain processing, including processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Complain to a supervisory authority — for EEA/UK/Swiss individuals, lodge a complaint with your local data protection authority.
To exercise these rights, email the contact form at bobbuilt.io/contact from the address associated with your account. We will verify your identity before responding and will reply within the time required by applicable law. We will not discriminate against you for exercising your rights. If you are a consumer of one of our customers, please contact that customer; we will assist them as required by our DPA.
13. US state privacy disclosures
If you are a resident of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you may have additional rights under your state’s privacy law, including the rights described in Section 12 and the right to opt out of targeted advertising, sale of personal information (as those terms are defined under each law), and certain profiling.
In the prior 12 months, we have collected the categories of information described in Section 3. We disclose those categories for the business and commercial purposes described in Section 5. We do not “sell” personal information for monetary consideration and we do not knowingly process the personal information of consumers under 16 for targeted advertising or sale. Our use of cookies and similar technologies for digital advertising may constitute “sharing” or “targeted advertising” under certain laws.
To opt out of targeted advertising and analytics cookies, use the cookie controls on the Site, enable Global Privacy Control in your browser (we honor recognized GPC signals where required), or email the contact form at bobbuilt.io/contact with the subject line “US Privacy Request.” You may use an authorized agent to submit requests on your behalf; we will require proof of authorization. You may appeal a denied request by replying to our response.
California “Shine the Light.” California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their own direct marketing.
14. Cookies and tracking technologies
We and our service providers use cookies, pixels, local storage, server logs, and similar technologies to operate the Site, remember your preferences, measure performance, and support marketing. The categories we use are:
- Strictly necessary — required to authenticate users, balance load, and deliver core features. These cannot be disabled.
- Functional — remember preferences and recent activity.
- Analytics — measure usage and improve the Site (e.g., Microsoft Clarity).
- Advertising — measure ad performance and deliver relevant ads on third-party platforms (e.g., Meta Pixel, Google).
You can control non-essential cookies through the cookie banner on the Site (where presented), your browser settings, or industry opt-outs such as the DAA opt-out and the NAI opt-out. We honor Global Privacy Control signals as required by applicable law.
15. Marketing communications
You can opt out of marketing emails at any time by clicking the “unsubscribe” link in the email or by emailing the contact form at bobbuilt.io/contact. You may continue to receive transactional and service-related communications (e.g., billing notices, security alerts) even after opting out of marketing. For SMS messages we send to you, reply STOP to opt out and HELP for help. Message and data rates may apply.
16. AI features
Some features of the Services use artificial intelligence and machine-learning models, including models hosted by third-party providers. When you submit content to AI features, we send the minimum necessary content to the underlying model to generate a response. Bobbuilt does not use customer content to train third-party foundation models, and we contractually require our AI subprocessors to refrain from training on customer content. We may use aggregated, de-identified telemetry to evaluate and improve our own prompts and model selection.
17. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you solely by automated means without human involvement. Some features (such as lead scoring or routing) use automation to support decisions made by our customers; those customers remain responsible for the decisions they make.
18. Children
The Services are not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact the contact form at bobbuilt.io/contact and we will take appropriate steps to delete it.
19. Third-party websites and services
The Services may contain links to third-party websites and services that are not operated by Bobbuilt. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party services you use.
20. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify account administrators by email or through an in-product notice at least 30 days before the changes take effect (unless a shorter period is required by law) and update the “Effective” date at the top of this page. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.
21. How to contact us
For questions about this Policy or our privacy practices, or to exercise your rights, contact us at:
Bobbuilt, Inc.
Attn: Privacy
1209 N Orange Street
Wilmington, DE 19801, USA
Email: the contact form at bobbuilt.io/contact
Legal notices: the contact form at bobbuilt.io/contact
Security: the contact form at bobbuilt.io/contact
This Privacy Policy is provided for informational purposes and does not create a contract between you and Bobbuilt. Your use of the Services is governed by our Terms of Service and, for business customers, the Data Processing Addendum.
