DRAFT — for legal review, not legal advice. To be reviewed by a qualified lawyer licensed in Ontario; not for publication until counsel signs off and the operator removes this banner.
Privacy Policy
Effective date: [VERIFY: set on publication] · Last updated: [VERIFY: set on publication]
Who we are
B Found is operated by B Found Search Inc., a corporation incorporated under the Canada Business Corporations Act, with its mailing address at 354 Guelph St, Unit 23-450, Georgetown, ON L7G 4B5. In this policy, "we", "us", and "our" mean B Found Search Inc., and "B Found" is the brand name under which we operate bfound.ca.
Definitions
In this policy:
- Personal Information means information about an identifiable individual. This is the meaning the federal privacy statute, the Personal Information Protection and Electronic Documents Act (PIPEDA), gives the term, and we use it the same way throughout.
- Services means the B Found website at bfound.ca and the products and services we provide through it.
- Service Provider means a third party that processes Personal Information on our behalf. Every Service Provider we use is listed in Who we share it with.
What we collect and why
We collect the following categories of Personal Information when you use B Found, and only for the purposes stated:
- Audit requests — the business website you enter, business name, your name, email, phone (optional), city and services (optional), and the Google business listing and keywords we resolve for the audit. Purpose: run the audit you asked for, deliver the results, and follow up about them.
- Consent records — the date and time you checked the consent box, your IP address, the form you used, the exact consent wording shown to you, and your email address. Purpose: prove your express consent for marketing messages, as Canada’s anti-spam law requires of us.
- Accounts — your name, email, sign-in credentials (stored as secure hashes; or your Google sign-in), and session records. Purpose: create and secure your client dashboard account.
- Billing — payment records from our payment processor (customer and payment identifiers, purchase status, amounts) and invoice records. Purpose: process and reconcile payments. We never store your card number.
- Operational logs — IP-derived rate-limit keys, and a log of our own staff’s actions (including staff IP addresses and browser details). Purpose: prevent abuse and keep our staff accountable.
- Client reporting data — your business’s rankings, Google Business Profile metrics, reviews, and AI-visibility measurements. Purpose: populate your reporting dashboard. This is business-level data and mostly not Personal Information.
We collect only what we need for these purposes. Where we rely on your consent, you can withdraw it as described in Consent and how to withdraw it.
How we use your information
We use Personal Information only for the purposes listed in What we collect and why. If we want to use it for a new purpose, we will tell you what that purpose is and ask for your consent before we start. We disclose Personal Information only as described in Who we share it with.
We keep Personal Information as accurate, complete and up to date as its purposes require. Your access and correction rights explains how to have it corrected.
Consent and how to withdraw it
You give us consent through the action that provides the Personal Information: requesting an audit, creating an account, or purchasing a paid service.
Marketing messages are opt-in. The consent box on the audit form is never pre-checked, and we record exactly what you agreed to and when. We send commercial electronic messages only with your express consent. To unsubscribe, use the unsubscribe address linked in every message ([email protected]). We give effect to an unsubscribe request without delay, and no later than 10 business days after you send it, at no cost to you.
Even after you unsubscribe, we keep the record that proves your original consent — the date and time, your IP address, the form you used, the exact consent wording shown to you, and your email address. Canada’s anti-spam law places the burden of proving consent on the sender, so we store these records in an append-only ledger and keep them while they could be needed as evidence; no law sets a fixed retention period for them.
You can withdraw any consent at any time, subject to legal and contractual restrictions and reasonable notice, by contacting our privacy officer (Privacy officer and complaints). If you withdraw consent, we may not be able to provide the parts of the Services that depend on that information. How long we keep it identifies the records a legal or contractual restriction requires us to keep after withdrawal.
Who we share it with
We do not sell Personal Information. We share it only with the Service Providers below — under contract, and only the data each one needs for its role:
- Resend — sends our transactional and audit-delivery email. Shared: your email, name, and the audit report content. Region: United States.
- PostHog — product analytics. Shared: usage events and, for logged-in clients, an identified user profile. Region: United States.
- Stripe — card and bank-debit payments. Shared: your email, billing details, and payment method. Region: United States / global.
- DataForSEO and AI-assistant platforms (via our audit system) — search-ranking and AI-visibility data sources. Shared: your business’s website, name, city, and keywords — business identity, not your personal contact details. Region: United States.
- Cloudflare — network edge and security. Shared: IP address and request metadata. Region: global.
- Google — optional sign-in. Shared: your email and name. Region: United States / global.
We may also disclose Personal Information where a law, court order, or other lawful authority requires us to.
Where your information is processed
We run the Services and their database on infrastructure we control in Canada. Some Service Providers process or store Personal Information in the United States or other countries:
- Resend — email delivery (United States)
- PostHog — analytics (United States)
- Stripe — payments (United States / global)
- DataForSEO and AI-assistant platforms — search and AI-visibility data (United States)
- Cloudflare — network edge (global)
- Google — optional sign-in (United States / global)
While your Personal Information is in another country, it is subject to the laws of that jurisdiction and may be accessible to the courts, law enforcement and national security authorities there. We remain accountable for it, and we use contracts with each Service Provider to require a level of protection comparable to what this policy describes. [VERIFY: operator to confirm data-protection/DPA terms are in place with each Service Provider — the standard-DPA providers are fine; check the search/AI data sources, which may run on bare API terms]
Cookies and analytics
We use a small number of cookies and similar technologies. This is the complete list:
- PostHog analytics — sets a cookie and browser storage to measure how the site and dashboard are used (clicks, form submissions, page visits). Session recording is off, we do not use it for advertising, and profiles are tied to an identity only for logged-in clients. Data is processed in the United States.
- Sign-in session cookie — keeps you logged in to the client dashboard for up to 30 days.
- We use no advertising pixels or third-party ad trackers.
We do not show a cookie consent banner; this section is our complete cookies disclosure. [VERIFY: OPC online-tracking/meaningful-consent guidance — whether this tracking profile stays within implied-consent territory; lawyer]
Analytics is not necessary to provide the Services, and you have a choice about it: [VERIFY: operator to confirm the opt-out mechanism — in-product toggle or honoured email request — OPC meaningful-consent guidance expects an accessible choice for non-essential collection]
How long we keep it
We keep Personal Information only as long as its purpose — or a legal or evidentiary requirement — needs it, then delete it:
- Audit requests — [VERIFY: operator to set — currently "as long as we are working with you or following up"; give a concrete practice]
- Consent records — kept while they could be needed to prove consent (see Consent and how to withdraw it); no law sets a fixed period for them
- Accounts — [VERIFY: operator to set — account lifetime + post-deletion window]
- Billing — [VERIFY: operator to set — tax/audit retention for purchase and invoice records]
- Staff action log — about 7 years
How we protect it
We protect Personal Information with safeguards appropriate to its sensitivity: encryption in transit, access controls and logging of our staff’s actions, an append-only consent ledger, and no storage of card numbers — payments are handled by our payment processor. No system is perfectly secure, and we do not promise that — but we notify you and the regulator when the law requires it (If there is a breach).
Your access and correction rights
You can ask us:
- what Personal Information we hold about you, how we use it, and who we have shared it with — we will give you access to it;
- to correct it if it is inaccurate or incomplete; and
- to delete it. We will delete what we are not required to keep. Some records survive a deletion request because a law or a legal obligation requires them — for example, records proving marketing consent (Consent and how to withdraw it) and records we must keep for tax or accounting purposes. How long we keep it lists these.
To exercise any of these, contact our privacy officer (Privacy officer and complaints). We may need to verify your identity first, and we will respond within the time PIPEDA allows.
Privacy officer and complaints
[VERIFY: designated accountable individual — PIPEDA Sch.1 cl.4.1 requires one; operator to name a person or role] is accountable for how B Found Search Inc. handles Personal Information. Reach them at:
Email: [email protected]
Mail: B Found Search Inc., 354 Guelph St, Unit 23-450, Georgetown, ON L7G 4B5
If you have a complaint about our handling of your Personal Information, contact our privacy officer first — we investigate every complaint and tell you what we found and what we changed. If you are not satisfied with our response, you can complain in writing to the Office of the Privacy Commissioner of Canada (priv.gc.ca), which oversees PIPEDA.
If there is a breach
If a breach of our security safeguards creates a real risk of significant harm to you, we will notify you, and report to the Office of the Privacy Commissioner of Canada, as soon as feasible after we determine the breach occurred. We also notify any other organization or government institution that can reduce the risk of harm, and we keep a record of every breach of security safeguards, whatever its size, for at least 24 months.
Changes to this policy
When we change this policy, we post the new version at bfound.ca/privacy and update the "Last updated" date at the top. If a change expands what we collect or how we use it, we will tell you before it takes effect — by email if we have your address, or by a notice on the site — and, where the change needs your consent, we will ask for it.