From 58083aa3e0901f5ff76a46b2fd2e5b05983f9636 Mon Sep 17 00:00:00 2001 From: Tony Balascio Date: Sun, 9 Aug 2026 19:05:15 +0000 Subject: [PATCH] Full Bizl.com competitive research extraction - homepage, pricing, FAQ, tools, all industries, services, compare, case studies, guides --- research/bizl-com/67-privacy.md | 39 +++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 research/bizl-com/67-privacy.md diff --git a/research/bizl-com/67-privacy.md b/research/bizl-com/67-privacy.md new file mode 100644 index 0000000..e672e5f --- /dev/null +++ b/research/bizl-com/67-privacy.md @@ -0,0 +1,39 @@ +# Privacy Policy +URL: https://bizl.com/privacy +Extracted: 2026-08-09 + +## Core Messaging / Positioning +- Operates "an AI-powered local visibility platform that helps local businesses get found in ChatGPT, Gemini, Perplexity, Google, and other AI search engines." +- Application scope: all visitors to bizl.com, users of free tools, and subscribers to paid services. +- Hardline promise: "We do not sell your personal data. Ever." +- No advertising tracking: "We do not use advertising cookies, retargeting pixels, or third-party tracking cookies for ad networks. We do not serve ads on bizl.com and do not share browsing data with ad networks." + +## Key Claims & Stats +- Data collected: name/email; business name, website URL, business address; phone; payment info (card processed by Stripe — "we do not store card numbers"); intake form responses (category, target keywords, competitors, service area); communications. +- Free tools named: AI Visibility Scanner, Schema Generator, Citation Audit Preview, Competitor Gap Preview — email collected to deliver results, may be used for follow-up "You can opt out ... using the unsubscribe link." +- Business data processed on behalf: "handling data about your business, not about you as an individual" — name/address/phone/website content, GBP data, citations, schema, competitor info. Not shared with other clients; not used beyond service delivery. +- **"We do not use your personal data for automated decision-making or profiling that has legal or significant effects on you."** +- Sub-processor list declared (third-party services) but the actual list is not populated in the scrape. +- Security claims: HTTPS/TLS 1.2+, AES-256 at rest, hashed+salted passwords, JWT auth with token expiration, role-based access control, regular security reviews, no storage of card data (Stripe). +- Rights/compliance: 30-day response for general privacy requests; CCPA/CPRA (45-day response, categories disclosed); GDPR/UK GDPR legal bases (contract, legitimate interests, legal obligation, consent); children's data (<18 deletion); international transfers (EU-US Data Privacy Framework + SCCs); California: no sale/sharing for cross-context behavioral advertising. +- Flag (evidence quality): security measures are strong-sounding but **unsupported assertions → Tier 3**; the sub-processor list and cookie-type list are header-only (not populated). No retention/holding periods stated numerically (holds are qualitative). + +## Offer / Pricing Details (if applicable) +- Not on this page (legal doc). References paid services and free tools. + +## Process / How It Works +- Privacy-facing disclosure of how the platform treats personal vs business data, cookies, retention, security, and user rights. Free-tool email capture clearly disclosed ("may use it to follow up"; opt-out available). +- White-label/agency data visibility disclosed: "If you are using bizl.com as an end-client of a white-label agency partner, your data may be visible to that agency partner." + +## Notable Strengths or Patterns +- Clear "we don't sell data, ever" and "no ads / no ad cookies" privacy stances — deliberate trust signals. +- Explicit separation of personal data vs business data processed (a subtle differentiator for a B2B done-for-you provider). +- Concrete security detail (TLS 1.2+, AES-256, JWT, RBAC) reads professionally. +- CCPA/CPRA and GDPR coverage present (structured compliance). + +## Notes for Digital Operations Partner +- **Evidence quality / honesty**: Security/privacy assurances are categorical and largely **unverifiable (Tier 3)** here. DOP can differentiate by publishing verified compliance artifacts (SOC/pen-test summaries, processor list) where claims are made. +- **Human supervision vs black-box**: Notable — the platform explicitly disclaims automated decision-making with significant effects; still, execution is done-for-you. DOP's human-supervised + agent-assisted model makes human accountability explicit and should be matched in privacy/clarity tone. +- **PoC-style entry**: Discloses free-tool email capture + follow-up — the free-scan→paid funnel is codified in the privacy policy. DOP can pair its Cold Audit with clear disclosure of what measured data is retained. +- **Silent Customer Loss**: N/A directly; policy reveals the data model behind the loss-detection service (business data, competitor intelligence) — relevant to how DOP would frame its own data practices. + \ No newline at end of file