Bullseye

United States · bullseye.so · 7 vendors

Bullseye provides a person-level website visitor identification platform that helps businesses identify anonymous website visitors. It delivers visitor intelligence, including names, work emails, job titles, and company details, directly to CRMs or other tools to help sales teams boost conversions.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 7 sub-vendors.

Insights

Last updated 2026-07-06 · revision 1

7 direct vendors, 146 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Bullseye demonstrates a relatively high migration readiness, largely driven by its modern and API-centric technology stack. The use of Next.js, coupled with extensive API capabilities such as 'Identity API' and 'Webhook & REST API', suggests a modular and flexible architecture that is well-suited for migration to cloud-native environments. The existing 'GDPR & CCPA Compliance Framework' is a significant strength, as it indicates a foundational understanding and implementation of data governance, which is crucial for navigating compliance requirements during a migration. However, a primary challenge to migration readiness is the unknown financial stability, as critical data on revenue concentration and growth history is missing, making it difficult to ascertain the company's capacity to fund a potentially costly migration. While the 'Vendor Relationships' data is inconsistent, assuming Cloudflare Turnstile, Stripe, and PayPal as key vendors, these are widely adopted SaaS platforms with well-documented APIs, suggesting moderate rather than high vendor lock-in. Nevertheless, the 'Vendor Lock-in Risk' is explicitly unknown. The geographic concentration of these assumed vendors in the United States could simplify migration to a US-based cloud provider but might introduce complexities if a global or non-US cloud strategy is pursued. Data residency requirements are also not specified, which could become a factor during migration planning.

Compliance

7 in-scope frameworks identified; showing 3.

CPRA — Partially Compliant

Bullseye explicitly claims CCPA compliance on its homepage and Privacy Statement. However, the core business — collecting and selling/sharing personal information of California residents (website visitors identified without direct consent) — is a high-risk activity under CCPA/CPRA. Risk is High because: (1) The service processes personal information of California consumers at scale without their direct knowledge; (2) CPRA (effective 2023) introduced the California Privacy Protection Agency (CPPA) with active enforcement authority and fines up to $7,500 per intentional violation; (3) The 'sensitive personal information' provisions of CPRA may apply to precise identification data; (4) No evidence of a formal CCPA compliance audit, privacy impact assessment, or CPPA registration is publicly available; (5) The opt-out mechanism (a Google Form) may not meet CCPA's 'Do Not Sell or Share My Personal Information' button/link requirements.

Evidence: https://www.bullseye.so, https://www.bullseye.so/legal/privacy, https://forms.gle/3DySUcvbqyddYDDf8

GDPR (source) — Partially Compliant

Bullseye operates a person-level website visitor identification platform that processes personal data (names, emails, job titles, company details) of individuals who may include EU/EEA residents visiting customer websites. The Privacy Statement explicitly acknowledges GDPR applicability and the DPA references standard contractual clauses (SCCs) for international transfers. However, several high-risk factors elevate this to High: (1) The core business model — de-anonymizing website visitors without their direct consent — is inherently high-risk under GDPR's lawful basis and transparency requirements (Articles 6, 13, 14); (2) Data is stored exclusively in the US (AWS us-east-1, DigitalOcean NYC), requiring SCCs for EU data transfers, but no evidence of executed SCCs or Transfer Impact Assessments (TIAs) is publicly available; (3) No Data Protection Officer (DPO) appointment is disclosed; (4) No GDPR-specific audit or certification (e.g., ISO 27701) has been found; (5) The opt-out mechanism relies on a Google Form rather than a structured GDPR-compliant rights management system; (6) GDPR fines can reach €20M or 4% of global annual turnover. The company self-declares GDPR compliance on its homepage but lacks verifiable third-party evidence.

Evidence: https://www.bullseye.so, https://www.bullseye.so/legal/privacy, https://www.bullseye.so/legal/dpa

CASL — Assessment Required

If Bullseye's customers use identified visitor data to send commercial electronic messages (CEMs) to Canadian recipients, CASL applies. CASL requires express or implied consent before sending CEMs, which is stricter than CAN-SPAM. Risk is Medium because: (1) Bullseye's Privacy Statement focuses on US web traffic but does not explicitly exclude Canadian visitors; (2) CASL penalties can reach CAD $10M per violation for organizations; (3) No CASL compliance documentation is publicly available.

Evidence: https://www.bullseye.so/legal/privacy

Financials

Three-year financials

Financial Resilience Score: 4/10

Bullseye is a small, private, early-stage U.S. B2B SaaS company in the website visitor identification category with no publicly disclosed financials. The company operates on a recurring subscription model starting at $99/month, which typically provides predictable MRR and high gross margins (70-85% typical for comparable SaaS). Multiple monetization channels including direct SaaS, agency plans, whitelabel, and affiliate programs help diversify revenue streams. Product integrations with HubSpot, Salesforce, and Slack create moderate switching costs. However, the company faces substantial risks including likely bootstrapped or lightly funded status with limited runway buffer versus well-capitalized competitors like RB2B, Clearbit/HubSpot Breeze, Warmly, Vector, Koala, and Leadfeeder/Dealfront. The category is highly competitive with freemium and better-known incumbents creating price competition and feature commoditization risks. Dependence on third-party identity data providers exposes margins to upstream pricing changes, and regulatory risk from GDPR, CCPA/CPRA, and emerging state privacy laws could materially reduce match rates and TAM. Small SMB-heavy customer bases in this pricing tier typically show high churn (5-10%/month), pressuring net revenue retention. Zero public transparency with no audited statements, no disclosed investors, and no disclosed leadership team makes counterparty diligence difficult. The score reflects the inherent fragility of an early-stage bootstrapped SaaS company operating in a competitive, regulation-exposed niche without visible capital backing.

Key strengths: Recurring SaaS revenue model with predictable MRR starting at $99/month, Low variable cost structure with typically high gross margins (70-85%), Multiple monetization channels (direct, agency, whitelabel, affiliate), Sticky product placement via HubSpot, Salesforce, and Slack integrations, Growing market category for B2B visitor identification

Risk factors: Small/early-stage with no publicly announced institutional funding, Highly competitive category with freemium and incumbent competitors, Dependence on third-party identity data providers, Regulatory risk from GDPR, CCPA/CPRA and emerging privacy laws, High customer churn risk typical of SMB-heavy customer bases (5-10%/month), Zero public transparency and no disclosed audited statements or leadership team

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report