PulseGrid
DocsPricingLog inSign up

Privacy Policy

Last updated: 1 September 2026 · Version 1.0

1. Who we are

PulseGrid ("PulseGrid", "we", "us") is operated by RED BEAR TECHNOLOGY S.R.L., registered at Str. Lungă nr. 149, ap. P3, Mun. Brașov, jud. Brașov, Romania (Trade Register No. J08/249/2023, CUI RO47523219). For any privacy question, or to exercise the rights in section 8, contact [email protected].

2. Two different roles

PulseGrid handles two distinct kinds of data, and our responsibilities differ for each. This distinction matters, so we state it up front:

  • Account data — we are the controller. Information about you as a PulseGrid user and about your organisation. We decide how it's used, and this policy governs it.
  • Device event data — we are a processor. The transactions, heartbeats and errors your devices send to our ingest API. Your organisation decides what to send and why; we store and display it on your behalf, under your instructions. If you are an end customer of one of our customers, their privacy policy governs that data, not this one.

3. What we collect

3.1 Account data

  • Your name and email address.
  • A password, stored only as a salted hash — never in a form we can read or recover.
  • If you sign in with Google or Microsoft: the account identifier they return, plus your name, email and avatar URL. We never receive your Google or Microsoft password.
  • Your organisation's name, and its billing identifier at Stripe.
  • Your role in the organisation, and who invited you.

3.2 Device event data

  • Transactions: amount, currency, status, payment type (e.g. "card"), product name, quantity and timestamps.
  • Heartbeats: battery level, firmware version, reported status and any free-text note.
  • Errors: error code, message, severity, timestamps.
  • Charging sessions (EV chargers): connector, energy and meter readings, charging power, battery state of charge, duration, price, and the RFID/authorisation tag (the OCPP idTag) the charger reports for a session. The tag identifies a charge card, not a named person; we store it on your instructions as your processor.
  • A free-form metadata field on transactions, whose contents you control. We never require personal data in it and we don't inspect it. Please don't put personal data of your end customers there unless you have a lawful basis to — anything you send, we store.

We do not receive or store payment card numbers. The ingest API records that a payment happened and for how much — never the instrument used.

3.3 Technical data

  • IP address and request metadata in our web-server logs, kept for security and abuse prevention.
  • Session tokens stored in your browser's local storage to keep you signed in (see section 9).

4. Why we use it, and on what basis

  • To provide the service — creating your account, authenticating you, and displaying your devices' data. Basis: performance of a contract.
  • To email you service messages: email verification, password resets, team invitations, and the alert digests you've enabled. Basis: performance of a contract.
  • To take payment for paid plans. Basis: performance of a contract.
  • To keep the service secure — rate limiting, account lockout after repeated failed sign-ins, and abuse investigation. Basis: legitimate interests.

We do not sell your data, we do not share it with advertisers, and we do not use it to train machine-learning models.

5. Who we share it with

We use a small number of subprocessors. Each receives only what it needs to do its job:

ProviderPurposeWhat it receives
StripePayments and subscriptionsBilling details you enter with Stripe directly, and your organisation's Stripe customer ID
ResendTransactional emailYour email address and the message content
Google / MicrosoftOptional single sign-onOnly engaged if you choose to sign in with them
MapboxMap tiles on the Map pageYour browser requests tiles directly from Mapbox, which means it sees your IP address and the map area viewed
CrispLive chat support (only if enabled and only when you open the chat)Your name, email address and the messages you send, plus — like any embedded widget — your IP address and basic browser/device information
DigitalOceanServers and database hostingHosts all data described in this policy

We may also disclose data where legally required, or to establish or defend legal claims.

6. How long we keep it

Device event data is retained according to your plan, and then permanently deleted:

  • Free — 7 days
  • Starter — 90 days
  • Pro — 1 year

Past that window the data stops being visible in the product immediately. Actual deletion runs on a recurring background sweep and deliberately lags the window by a short grace period (currently around 30 days) so that an accidental plan change — for example a failed payment briefly downgrading an account — doesn't irreversibly destroy your history. Aggregated daily totals (revenue per terminal per day) are not personal data and are kept beyond that.

Account data is kept while your account exists. Server logs are kept for 90 days. On deletion of your organisation, associated data is removed, except where we must retain records to meet a legal obligation (for example, invoices for tax purposes).

7. Where it's stored

Our servers and database are hosted in Frankfurt, Germany (European Union). Some subprocessors listed in section 5 may process data outside your country; where that involves a transfer out of the EEA or UK, it relies on the safeguards in the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where the UK applies).

8. Your rights

Subject to your local law, you may have the right to access, correct, delete, export, or restrict our use of your personal data, and to object to processing based on legitimate interests. To exercise any of these, email [email protected]; we'll respond within the period required by applicable law.

If you're in the EEA or UK and think we've handled your data improperly, you can complain to your local supervisory authority. We'd appreciate the chance to address it first.

If your data reached us as device event data submitted by one of our customers, please direct your request to that organisation — we act on their instructions and will support them in responding.

9. Cookies and local storage

PulseGrid uses no advertising or analytics trackers, and sets no third-party marketing cookies. We use only what's needed to run the service:

  • Local storage holds your session tokens and basic profile so you stay signed in. Cleared when you log out.
  • A short-lived cookie during sign-in if you use Google or Microsoft, to correlate the login round trip.
  • Functional cookies from our live-chat widget (Crisp), set only when the chat loads in the signed-in app, to keep your conversation together as you move between pages. These are functional — not advertising or analytics — cookies.

10. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Each organisation's data is isolated and every request is scoped to the organisation on your session. Repeated failed sign-ins lock an account temporarily, and our APIs are rate limited. No system is perfectly secure, but if a breach affects your personal data we'll notify you and any regulator as required by law.

11. Children

PulseGrid is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16.

12. Changes

We'll update this policy as the service changes. Material changes will be communicated by email or an in-product notice before taking effect. The "last updated" date above always reflects the current version.

13. Contact

RED BEAR TECHNOLOGY S.R.L. · Str. Lungă nr. 149, ap. P3, Mun. Brașov, jud. Brașov, Romania · Trade Register No. J08/249/2023 · CUI RO47523219 · [email protected]

See also our Terms of Service.

PulseGrid

Real-time monitoring for unattended devices.

Monitoring

Self-service kiosksVendingEFT / POS terminals

Product

PricingIntegration guideAPI reference

Account

Log inSign upContact

Legal

TermsPrivacy