Two data sources: Apollo.io (verified B2B contact database, ~275M people, SOC 2 Type II) and Google Places API (public business listings for indie retailers). Apollo email addresses are verified at the moment they're revealed to you. Bounces auto-suppress within 24 hours. We don't scrape LinkedIn. We don't buy lists. We don't resell your data.
Our two data sources
When you build an audience in Pitch2Retail, the contact records come from one (or both) of these:
| Source | What it provides | Best for |
|---|---|---|
| Apollo.io | Verified work emails, job titles, LinkedIn URLs, company info โ for retail chain buyers, category managers, store managers, procurement directors | RONA, Home Hardware, London Drugs, Whole Foods, Sobeys, regional chains |
| Google Places API | Public business listings โ store name, address, phone, website, photos, opening hours, ratings โ for indie retailers without a buyer in Apollo | Independent gift shops, specialty grocers, wineries, single-location restaurants |
Both sources are public-information based. Apollo aggregates publicly available work-context data and runs it through verification pipelines. Google Places exposes the same listings you see when you search a store on Google Maps.
Apollo.io โ verified B2B contacts
Apollo is a SOC 2 Type II certified B2B sales intelligence platform with around 275 million person profiles. They are our primary source for buyer-role contacts at retail chains.
How Apollo gets the data:
- Public web sources (company websites, press releases, public filings, conference attendee lists)
- Licensed data partnerships with B2B data providers
- Opt-in contributor network (sales reps who connect their inboxes contribute non-PII metadata)
- Contact form submissions on Apollo's own products
What we use Apollo for:
- Searching by company domain + role keywords (e.g., "buyer", "category manager", "procurement")
- Pulling work email + verification status
- Pulling job title and LinkedIn URL for personalization
What we don't use Apollo for:
- Personal email addresses (we filter these out โ only role-based or work emails are imported)
- Phone numbers (Apollo provides them; we don't import or expose them)
- Mass data dumps (we pull contacts on-demand for each audience build, not in bulk)
Read Apollo's privacy posture: apollo.io/privacy-policy
Google Places โ indie retailer discovery
For independent stores that don't have a named buyer in Apollo (typical for single-location boutiques, indie wineries, gift shops, specialty grocers), we use the Google Places API to find them.
What Places returns:
- Business name, address, website, phone, opening hours
- Place type tags (gift_store, liquor_store, restaurant, etc.)
- Up to 10 photos of the storefront/interior
- Star rating + review count
Where the email comes from for indie retailers:
- We retrieve the store's website from Places
- Our crawler visits the contact / about page (respecting
robots.txt) - If a public
info@/hello@/contact@email is published on the page, we surface it for your review - You confirm the email before any send โ masked until you approve
If no public contact email is findable, the contact is marked "manual research required" and won't be auto-emailed.
How verification actually works
Email verification happens at three checkpoints:
| Stage | Check | Failure action |
|---|---|---|
| Reveal | Apollo runs SMTP + MX + catch-all detection at the moment we request the email | Marked unverified ยท excluded from sends unless you override |
| Pre-send | We re-validate the recipient domain has a valid MX record | Auto-skip ยท audit log entry |
| Post-send | Bounce webhook from Resend (hard or soft bounce) | Auto-suppress within 24h ยท contact marked bounced |
Apollo classifies emails into three buckets, which we expose to you:
- Verified โ SMTP handshake completed cleanly. Highest confidence. ~92% of our reveals.
- Likely deliverable โ Catch-all domain (we can't directly confirm the inbox exists, but the domain accepts mail). Use with care.
- Unverified โ Could not confirm. Excluded by default from sends.
Data freshness and update cadence
Apollo refreshes its verified contact pool continuously. Because we pull on-demand for each audience build (rather than caching a static list), every audience you create reflects Apollo's most current data at that moment.
- Per-audience builds: live query at audience creation time
- Re-verification cadence: any contact older than 90 days in your audience is flagged for re-verify before the next sequence touch
- Job-change detection: when Apollo flags a person as having changed companies, we mark the contact
staleand prompt you to refresh - Google Places refresh: indie retailer data refreshed weekly or on-demand per audience
What we don't do
- No LinkedIn scraping. We don't crawl LinkedIn. We don't run automation against LinkedIn search. We don't extract emails from LinkedIn profile pages.
- No purchased lists. We don't buy CSVs from "B2B leads vendors" of the kind that show up in spam folders. Our only purchased data is via the licensed Apollo + Google Places APIs.
- No personal email harvesting. If a record's only email is a
@gmail.com/@yahoo.com/@hotmail.comaddress, it's filtered out. We only surface work / role emails. - No data resale. Your audience data, your reply data, your account data โ never sold, never licensed to third parties, never used to train AI models outside your account.
- No facial-image gathering. Profile photos are not retrieved or analyzed. Storefront photos from Google Places are used for the vision filter only and never persisted longer than the verification step.
- No EU/UK contact reveals without legitimate-interest review. Apollo lets you pull EU contacts; we surface a warning and require LIA documentation before reveal (see our GDPR page).
Suppression and removal
Anyone who unsubscribes, marks one of your sends as spam, hard-bounces, or asks to be removed is added to your tenant's permanent suppression list within minutes. The list is enforced at send time โ even if the same contact reappears in a future Apollo refresh, they will be silently skipped.
Recipients who want to be permanently removed across all Pitch2Retail customers (a "global suppression") can email remove@pitch2retail.com. We honor these within 10 business days as required by CASL s.11(3) and CAN-SPAM s.5(a)(4).
For the underlying source: contacts can request removal directly from Apollo via apollo.io/privacy-policy (the data subject deletion link is in the footer of every Apollo page). Once removed at the source, they will not reappear in future audience builds.
Your uploaded data
If you upload your own CSV of contacts (e.g., your existing customer list), that data is governed by the same rules:
- Stored in Canada (DigitalOcean Toronto)
- Encrypted at rest (AES-256-GCM) and in transit (TLS 1.3)
- Never shared, never sold, never used for AI training
- Deletable on request โ full account deletion processed within 30 days
You remain the controller of your uploaded data. We are the processor. See our Data Processing Agreement for the full controller/processor terms.
Verified contacts. Honest sourcing. No grey-area tactics.
Start your 14-day trial. Build your first audience in under 5 minutes.
Start free trial โ