Privacy Policy

Last updated: September 14, 2026

1. Introduction

Bug HQ ("we," "us," or "our") operates a software-as-a-service platform for pest control and wood-destroying organism (WDO) inspection companies. This Privacy Policy explains what information we collect, how we use it, the parties to whom we disclose it, the methods by which we disclose it, and the security practices we use to safeguard it when you use our platform at bug-hq.com (the "Service").

By using the Service, you agree to the collection and use of information as described in this policy.

2. Information We Collect

2.1 Account Information

When you register, we collect your name, email address, company name, and password. Company administrators may also provide a business address, phone number, state license number (e.g. CA SPCB license number), and branch certifications. We also record whether you accepted our Terms of Service, the timestamp of acceptance, the version of the Terms you agreed to, and your IP address and browser user agent at the time of acceptance.

2.2 Customer and Property Data

As part of normal operations, your account stores information about your end customers, including names, phone numbers, email addresses, property addresses, billing addresses, and lead source. This data is entered by you or your staff. We process this data on your behalf as described in Section 6 (Controller vs. Processor).

2.3 Inspection and Service Data

Your account may store WDO inspection findings, pest control job records, chemical application records, work orders, invoices, contracts, and e-signed documents. This data constitutes regulated business records and is processed on your behalf.

2.4 Usage Data

We automatically collect information about how you interact with the Service, including IP addresses, browser type, pages visited, and timestamps. This data is used for security, debugging, and improving the Service. Google Analytics collects page-view data and anonymized interaction events; see Section 5.

2.5 Payment Information

Subscription payments are processed by Stripe. We do not store credit card numbers or payment details on our servers. Stripe's privacy policy governs the handling of your payment information.

2.6 Photos and Files

Photos uploaded during inspections or jobs are stored securely in our cloud storage (Supabase Storage). Photo metadata may include GPS coordinates if your device provides them. These files are associated with your company account.

2.7 Cookies and Similar Technologies

bug-hq.com sets the following cookies:

  • _ga and _ga_36FHY5HE6X — first-party analytics cookies set by Google Analytics. They distinguish unique visitors and sessions so we can understand how the site is used. These are analytics cookies, not advertising or retargeting cookies. See §5.1 for what data Google Analytics receives.
  • Supabase auth session cookie — a strictly necessary cookie that maintains your login session. It is required for the Service to function and cannot be declined.

You can opt out of analytics cookies using the "Your Privacy Choices" link in the site footer. Declining analytics cookies does not affect your use of the Service. Bug HQ does not set advertising, retargeting, or cross-context behavioral tracking cookies. See §10.3.

3. Email Notifications

Our platform sends transactional and automated emails to your customers and staff using Resend. These include appointment confirmations, reminders, arrival notifications, document delivery, and review requests. By using this feature, you confirm that:

  • You have obtained appropriate consent from recipients before sending email communications through the platform.
  • You will only send messages related to scheduled services and customer communications for your pest control business.
  • You will not use the email feature to send spam or unsolicited commercial messages.

We log emails sent through the platform (recipient address, subject, delivery status, and timestamp) for troubleshooting purposes. Email logs are visible only to your company account.

4. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process subscription payments and send billing communications
  • Send transactional emails (inspection reports, invoices, password resets)
  • Power AI-assisted features such as report writing, schedule optimization, and photo analysis (see Section 5.2)
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Analyze usage patterns via Google Analytics to improve the Service
  • Comply with legal obligations

We do not sell your data or your customers' data to third parties.

5. Data Sharing and Disclosure

5.1 Sub-Processors and Service Providers

We disclose information to the following service providers via encrypted API calls (HTTPS/TLS) as necessary to operate the Service. Each provider processes data only for the purpose described and is bound by its own privacy policy and data processing terms.

  • Supabase (database and file storage): Stores all account data, customer records, inspection data, photos, and application data. Hosted in AWS us-west-2.
  • Vercel (hosting and edge network): Serves the application and processes HTTP requests. Server-side code executes on Vercel's infrastructure.
  • Stripe (payment processing): Receives operator name, email, and company name to process subscription payments. We do not transmit end-customer payment data to Stripe.
  • Resend (transactional email): Receives recipient email addresses, subject lines, and email body content for transactional emails sent on your behalf (appointment confirmations, report delivery, invoices, review requests).
  • Anthropic (AI processing): Receives data necessary to power AI features as described in Section 5.2 below.
  • Google Maps Platform (mapping and satellite imagery): Receives property addresses to generate satellite images used in inspection diagrams. Google processes these requests under its Maps Platform terms.
  • Google Analytics (website analytics): Collects page-view data, anonymized interaction events, IP addresses, and browser metadata from visitors. Google may use this data as described in its privacy policy. No customer names, addresses, or business data are sent to Google Analytics.
  • Intuit QuickBooks (accounting integration, optional): When you connect your QuickBooks account, we transmit customer names, email addresses, phone numbers, billing addresses, and invoice details (line items, amounts, due dates) to Intuit for accounting synchronization.
  • Google Business Profile (review management, optional): When you connect your Google Business Profile, we sync customer reviews and transmit review replies you compose. No end-customer personal data is sent to Google through this integration.

5.2 AI Processing (Anthropic)

Bug HQ offers AI-powered features that send data to Anthropic's Claude API for processing. The following data is transmitted depending on which feature you use:

  • Report Writer: Property addresses, inspector names, inspection dates, property types, and inspection findings (area, type, severity, notes) are sent to generate report narratives.
  • Schedule Optimizer: End-customer names, property addresses, cities, service types, and technician names are sent to optimize service routes.
  • Customer Summary: End-customer first and last names, billing addresses, billing cities, service history (types and dates), and invoice totals are sent to generate customer summaries.
  • Invoice Generator: Property addresses, service types, findings descriptions, treatments, and chemical application details are sent to generate invoice line items.
  • Photo Analysis: Inspection photos are sent as images for pest and damage identification.
  • Diagram Analysis: Hand-drawn property diagram images are sent for structural analysis.
  • Findings Assistant: Inspection area descriptions, observations, property types, and state are sent to assist with WDO finding descriptions.
  • Chat Assistant (BugBot): Company name, user role, and conversation messages are sent. The content of your messages determines what data reaches Anthropic through this feature.
  • Business Insights: Aggregated business metrics (job counts, revenue totals, completion rates) are sent. No customer names or addresses are included.

Anthropic's API data usage policy states that data sent through the API is not used to train Anthropic's models. Anthropic deletes API inputs and outputs within 30 days by default. Content flagged by Anthropic's automated trust-and-safety systems may be retained for up to 2 years, and classification scores may be retained for up to 7 years. For details, see Anthropic's privacy documentation at privacy.claude.com.

5.3 Method of Disclosure

All data shared with the service providers listed above is transmitted via encrypted API calls over HTTPS/TLS. We do not share data through bulk data exports, data brokers, public listings, or any other disclosure mechanism. Access to each provider is authenticated with API keys or OAuth tokens scoped to the minimum permissions required.

5.4 Other Disclosures

  • Legal Requirements: We may disclose information if required by law, regulation, or valid legal process (e.g. subpoena, court order).
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

6. Controller vs. Processor

6.1 Operator Account Data (Bug HQ as Controller)

Bug HQ is the data controller for information we collect directly from operators (pest control companies) who use the Service: account registration data, billing information, license credentials, usage data, and communications with our support team. We determine the purposes and means of processing this data as described in this policy.

6.2 End-Customer Data (Bug HQ as Processor)

When operators use the Service to store information about their end customers — including customer names, addresses, phone numbers, email addresses, inspection findings, WDO reports, chemical use records, invoices, and e-signed documents — Bug HQ acts as a data processor. The operator is the data controller for this information.

As a processor, we process end-customer data only as instructed by the operator through their use of the Service. Operators are responsible for:

  • Ensuring they have a lawful basis for collecting and storing their customers' personal information
  • Providing any required privacy notices to their own customers
  • Responding to data access, correction, or deletion requests from their customers
  • Complying with all applicable privacy laws in their jurisdiction regarding their customers' data

If we receive a data subject request from an end customer, we will refer them to the relevant operator unless legally required to respond directly.

7. Data Retention

We retain operator account data for as long as the subscription is active. There are two paths to account deletion:

  • Voluntary cancellation: If you cancel your account, we retain your data for 90 days before permanent deletion to allow for data export, unless a shorter retention period is required by law.
  • Payment failure: If payment fails and remains unresolved for seven consecutive days, the account is suspended. If the balance is not resolved within 90 days of suspension, all account data is permanently deleted. See Terms of Service §5.4.

Email delivery logs are retained for troubleshooting purposes and are accessible only to your company account.

AI usage logs (which feature was used, token counts, and timestamps) are retained for billing and analytics. AI-generated responses (report narratives, schedule suggestions) are not stored by Bug HQ after delivery to the client.

8. Your Rights

Regardless of where you are located, you may exercise the following rights with respect to your personal information by contacting us at support@bug-hq.com:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete personal information.
  • Deletion: Request that we delete your personal information, subject to legal retention requirements.

We will verify your identity and respond within a reasonable timeframe. California residents have additional rights described in Section 10.

9. Security

We implement industry-standard security measures to safeguard your information, including:

  • Encryption in transit (TLS/HTTPS) for all data transmissions, including API calls to sub-processors
  • Encrypted storage at rest (Supabase/AWS infrastructure)
  • Row-level security (RLS) policies ensuring each company can only access its own data
  • Role-based access controls within company accounts (admin, office, field roles)
  • OAuth 2.0 and scoped API keys for all third-party integrations
  • Password hashing via Supabase Auth (bcrypt)

However, no system is completely secure and we cannot guarantee absolute security.

10. Your Rights — California (CCPA/CPRA)

Bug HQ is a California business and many of our customers are California businesses. If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

10.1 Notice at Collection

We collect the following categories of personal information, for the business purposes described in Section 4:

  • Identifiers: Name, email address, phone number, company name, SPCB license number
  • Commercial Information: Subscription plan, payment history, invoice records
  • Internet Activity: IP addresses, browser type, pages visited, timestamps, Google Analytics data
  • Professional Information: State pest control license number, branch certifications, years in business

The following is classified as Sensitive Personal Information under CCPA/CPRA:

  • Precise Geolocation: GPS coordinates attached to inspection photos (when provided by device)

Our use of precise geolocation data is limited to performing the services reasonably expected by the consumer (inspection documentation and property mapping), as permitted by Cal. Civ. Code §1798.121(d).

10.2 Right to Know, Right to Correct, and Right to Delete

You have the right to request that we disclose what personal information we have collected about you, the right to request that we correct inaccurate personal information (CPRA §1798.106), and the right to request that we delete your personal information. To exercise these rights, contact us at support@bug-hq.com. We will verify your identity and respond within 45 days.

10.3 No Sale or Sharing of Personal Information

Bug HQ does not sell personal information. Bug HQ does not share personal information for cross-context behavioral advertising as defined by the CPRA. Google Analytics is used for first-party website analytics only; no customer names, addresses, or business data are transmitted to Google Analytics.

10.4 Retention

We retain personal information as described in Section 7. We do not retain personal information longer than reasonably necessary for the disclosed business purpose.

10.5 Non-Discrimination

We will not discriminate against you for exercising your CCPA/CPRA rights.

10.6 End-Customer Data

If you are an end customer of a pest control company that uses Bug HQ, your data is controlled by that company, not by Bug HQ. Please direct any privacy requests to the company that provided your service. See Section 6.2.

11. Children's Privacy

The Service is intended for business use and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify account holders of material changes by email or by a notice within the Service at least 14 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact

For privacy-related questions, data access requests, or deletion requests, contact us at:

Upper Case, Inc. d/b/a Bug HQ
2911 E Miraloma Ave #36
Anaheim, CA 92806
support@bug-hq.com