This Privacy Policy explains how Bearhug It, Inc. (“Bearhug”, “we”, “us”), a Delaware corporation, collects, uses, discloses, and protects personal information.
It covers two things:
- the website at bearhugit.com; and
- the Bearhug application — our web application and our iOS and Android mobile apps (together, the “Service”).
1. Our role: controller and processor
For the website, Bearhug is the controller of personal information you give us.
For the application, Bearhug is generally a processor. The Service is sold to businesses, and your employer (our customer) decides what data goes into it and why. If you use Bearhug through your employer and want your data corrected or deleted, contact them first; we will support their request. Where we determine our own purposes — security, billing, service improvement — we act as a controller.
2. Information we collect
2.1 When you use the website
- Information you submit. If you request a demo or send us a note, we collect your name, company, email address, and any phone number, industry, team size, or message you provide.
- Analytics. We use a privacy-preserving analytics service that does not use cookies and does not build cross-site profiles. It records aggregate data such as page views, referring site, country, and general device type. We do not use it to identify you.
- Server logs. Our hosting provider records standard request logs, including IP address, for security and reliability.
We do not use advertising cookies or tracking pixels on this website, and we do not sell or share personal information for cross-context behavioural advertising.
2.2 When you use the application
The application’s data practices are set out in full in the Bearhug App Privacy Policy — what it collects (work identity, location while in use, barcode scanning, work email and calendar, business records, diagnostics), who else receives it, how long it is kept, and how to ask for it to be removed. Where this page and that one differ about the application, the App Privacy Policy controls.
3. The AI assistant
The Service includes an assistant (“Teddy”). When you ask it a question, your prompt and the relevant business context are sent to a third-party AI provider to generate a response. We do not permit that provider to use your content to train its models. Do not enter information in the assistant that you would not want processed by a third-party provider on our behalf.
4. How we use information
- To provide, secure, support, and improve the Service.
- To respond to demo requests and enquiries.
- To administer accounts, entitlements, and billing.
- To detect and prevent abuse, fraud, and security incidents.
- To comply with legal obligations and enforce our agreements.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract; our legitimate interests in operating and securing the Service; your consent (for example, device location); and compliance with legal obligations.
5. Service providers
We share personal information with vendors who process it on our behalf, under contract, only for the purposes we specify:
- Microsoft Azure — hosting, databases, identity.
- Twilio SendGrid — transactional and notification email.
- Mapbox — map rendering in the application.
- Anthropic — the AI assistant described above.
- Plausible Analytics — cookieless website analytics.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy.
We do not sell personal information.
6. International transfers
We are based in the United States and our infrastructure is operated in the United States. If you access the Service from elsewhere, your information will be transferred to and processed in the United States. Where required, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. Retention
We keep application data for as long as your organisation’s account is active, and afterwards as required to comply with law, resolve disputes, and enforce agreements. On termination, customer data is deleted or returned in line with the customer agreement. Website enquiries are retained for up to 24 months. Aggregate analytics that cannot identify you may be kept indefinitely.
8. Security
We use encryption in transit, encryption at rest, access controls scoped to a user’s role and territory, and audit logging. No system is perfectly secure, but we treat access to customer business data as the thing we are most responsible for.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
To exercise a right, email privacy@bearhugit.com. We will verify your request and respond within the period required by law. If you use Bearhug through an employer, we will refer your request to them as the controller.
10. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
We will update this page when this policy changes and revise the date above. If a change is material, we will give notice through the Service or by email.
12. Contact us
Bearhug It, Inc.
8 The Green, Suite 25629
Dover, DE 19901
United States
Privacy enquiries:
privacy@bearhugit.com
General enquiries:
hello@bearhugit.com
Phone: (302) 313-2971