Privacy Policy
The short version: we collect what we need to deliver the service, we don't sell your data, you can export or delete everything anytime, and we comply with CASL (Canada), CAN-SPAM (US), GDPR (UK/EU), and PIPEDA (Canada).
1. Who we are
Pitch2Retail is operated by Beaver Wood Care Inc., a private corporation registered in British Columbia, Canada (the "Operator"). For questions or to exercise your rights, contact hello@pitch2retail.com or write to:
Beaver Wood Care Inc.
3047 Shaleview Drive
West Kelowna, BC, V4T 3L6, Canada
2. What we collect
2a. Account information
- Your name, email, brand name, country (collected at signup)
- Password (stored as a bcrypt hash — we cannot read it)
- Subscription tier + billing details (handled by Stripe; we never see your card)
2b. Brand profile + campaign data
- Products, pricing, brand voice, target retailers — what you enter into the app
- Campaigns, audiences, pitches, replies, send history
2c. Connected services (only what you authorize)
- Gmail / Outlook OAuth tokens (encrypted, used only to send your pitches)
- Resend API key (encrypted)
- Apollo API key (encrypted, only if you provide your own)
- Shopify webhook signing secret (encrypted)
2d. Recipient (retailer buyer) data
To find verified retail buyers, we query Apollo.io's database and Google Places. We store contact records (name, role, business email, business address) under B2B implied consent per CASL s.10(9). Recipients can opt out via a one-click unsubscribe link in every email — once a recipient opts out, we permanently suppress their address across all clients and all future campaigns.
2e. Usage analytics
Server logs (IP, user-agent, request paths) for 30 days for security + debugging. No third-party trackers. No Google Analytics, no Facebook Pixel, no Hotjar.
3. What we do with it
- Operate the service (find buyers, generate pitches, send email, track replies)
- Bill you (via Stripe)
- Send you product updates, transactional notifications, and (only if opted-in) marketing
- Detect abuse and enforce our terms
What we do NOT do: sell your data, share it with advertisers, train AI models on your customer data, or use your campaign content to improve our templates without consent.
4. How long we keep it
| Data type | Retention |
|---|---|
| Account record | Until you delete your account, then 30 days for compliance |
| Campaigns + pitches | Until you delete them, or 24 months after last activity |
| Server logs | 30 days |
| Stripe billing records | 7 years (Canadian tax law) |
| Suppression list (unsubscribes) | Permanent, by design |
5. Your rights
Under CASL, GDPR, PIPEDA, and CCPA, you have the right to:
- Access a copy of your data — request via email, delivered within 30 days
- Correct inaccurate data — edit in Settings or email us
- Delete your account and all associated data — one-click in Settings
- Export your campaigns + contacts — JSON download from the app
- Object to processing for marketing — opt-out anytime
- Withdraw consent for any optional processing
6. Sub-processors we use
| Service | What it does | Data shared |
|---|---|---|
| Stripe | Payment processing | Email, subscription tier |
| Anthropic Claude | AI pitch generation | Brand profile, recipient name + role (no PII training) |
| Resend | Email sending + tracking | From/to, subject, body, opens/bounces |
| Apollo.io | Verified contact sourcing | Search queries (org name, titles) |
| NocoDB on a private DigitalOcean instance | Database | All app data |
| DigitalOcean | Cloud hosting (Toronto region) | All app data at rest |
7. International transfers
All app data is stored in Canada (DigitalOcean Toronto). When you use AI features, prompts are processed by Anthropic in the United States. By using the service, you consent to this processing.
8. Cookies
We use one cookie: a session token (rpa_token) for authentication. We do not use tracking, advertising, or analytics cookies. No consent banner is required because we don't use trackable cookies.
9. Children
Pitch2Retail is a B2B product not intended for individuals under 18. We do not knowingly collect data from children.
10. Changes
We'll email account holders at least 14 days before any material change. Continued use after the change date constitutes acceptance.
Questions? Email hello@pitch2retail.com. For data-protection requests in the EU/UK, address as "Data Protection Request" in the subject line.