PulseGrid
PricingLog inSign up

Privacy Policy

Last updated: [EFFECTIVE DATE] · Version [X]

Draft — not yet in force. This document is being prepared and has not been finalised or legally reviewed. Bracketed values are placeholders. Please contact us at [CONTACT EMAIL] with any questions in the meantime.

1. Who we are

PulseGrid ("PulseGrid", "we", "us") is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] ([COMPANY REGISTRATION NUMBER]). For any privacy question, or to exercise the rights in section 8, contact [CONTACT EMAIL].

2. Two different roles

PulseGrid handles two distinct kinds of data, and our responsibilities differ for each. This distinction matters, so we state it up front:

  • Account data — we are the controller. Information about you as a PulseGrid user and about your organisation. We decide how it's used, and this policy governs it.
  • Device event data — we are a processor. The transactions, heartbeats and errors your devices send to our ingest API. Your organisation decides what to send and why; we store and display it on your behalf, under your instructions. If you are an end customer of one of our customers, their privacy policy governs that data, not this one.

3. What we collect

3.1 Account data

  • Your name and email address.
  • A password, stored only as a salted hash — never in a form we can read or recover.
  • If you sign in with Google or Microsoft: the account identifier they return, plus your name, email and avatar URL. We never receive your Google or Microsoft password.
  • Your organisation's name, and its billing identifier at Stripe.
  • Your role in the organisation, and who invited you.

3.2 Device event data

  • Transactions: amount, currency, status, payment type (e.g. "card"), product name, quantity and timestamps.
  • Heartbeats: battery level, firmware version, reported status and any free-text note.
  • Errors: error code, message, severity, timestamps.
  • A free-form metadata field on transactions, whose contents you control. We never require personal data in it and we don't inspect it. Please don't put personal data of your end customers there unless you have a lawful basis to — anything you send, we store.

We do not receive or store payment card numbers. The ingest API records that a payment happened and for how much — never the instrument used.

3.3 Technical data

  • IP address and request metadata in our web-server logs, kept for security and abuse prevention.
  • Session tokens stored in your browser's local storage to keep you signed in (see section 9).

4. Why we use it, and on what basis

  • To provide the service — creating your account, authenticating you, and displaying your devices' data. Basis: performance of a contract.
  • To email you service messages: email verification, password resets, team invitations, and the alert digests you've enabled. Basis: performance of a contract.
  • To take payment for paid plans. Basis: performance of a contract.
  • To keep the service secure — rate limiting, account lockout after repeated failed sign-ins, and abuse investigation. Basis: legitimate interests.

We do not sell your data, we do not share it with advertisers, and we do not use it to train machine-learning models.

5. Who we share it with

We use a small number of subprocessors. Each receives only what it needs to do its job:

ProviderPurposeWhat it receives
StripePayments and subscriptionsBilling details you enter with Stripe directly, and your organisation's Stripe customer ID
ResendTransactional emailYour email address and the message content
Google / MicrosoftOptional single sign-onOnly engaged if you choose to sign in with them
MapboxMap tiles on the Map pageYour browser requests tiles directly from Mapbox, which means it sees your IP address and the map area viewed
[HOSTING PROVIDER]Servers and database hostingHosts all data described in this policy

We may also disclose data where legally required, or to establish or defend legal claims.

6. How long we keep it

Device event data is retained according to your plan, and then permanently deleted:

  • Free — 7 days
  • Starter — 90 days
  • Pro — 1 year

Past that window the data stops being visible in the product immediately. Actual deletion runs on a recurring background sweep and deliberately lags the window by a short grace period (currently around 30 days) so that an accidental plan change — for example a failed payment briefly downgrading an account — doesn't irreversibly destroy your history. Aggregated daily totals (revenue per terminal per day) are not personal data and are kept beyond that.

Account data is kept while your account exists. Server logs are kept for [LOG RETENTION PERIOD]. On deletion of your organisation, associated data is removed, except where we must retain records to meet a legal obligation (for example, invoices for tax purposes).

7. Where it's stored

Our servers and database are hosted in [HOSTING REGION]. Some subprocessors listed in section 5 may process data outside your country; where that involves a transfer out of the EEA or UK, it relies on the safeguards in [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].

8. Your rights

Subject to your local law, you may have the right to access, correct, delete, export, or restrict our use of your personal data, and to object to processing based on legitimate interests. To exercise any of these, email [CONTACT EMAIL]; we'll respond within the period required by applicable law.

If you're in the EEA or UK and think we've handled your data improperly, you can complain to your local supervisory authority. We'd appreciate the chance to address it first.

If your data reached us as device event data submitted by one of our customers, please direct your request to that organisation — we act on their instructions and will support them in responding.

9. Cookies and local storage

PulseGrid uses no advertising or analytics trackers, and sets no third-party marketing cookies. We use only what's needed to run the service:

  • Local storage holds your session tokens and basic profile so you stay signed in. Cleared when you log out.
  • A short-lived cookie during sign-in if you use Google or Microsoft, to correlate the login round trip.

10. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Each organisation's data is isolated and every request is scoped to the organisation on your session. Repeated failed sign-ins lock an account temporarily, and our APIs are rate limited. No system is perfectly secure, but if a breach affects your personal data we'll notify you and any regulator as required by law.

11. Children

PulseGrid is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16.

12. Changes

We'll update this policy as the service changes. Material changes will be communicated by email or an in-product notice before taking effect. The "last updated" date above always reflects the current version.

13. Contact

[LEGAL ENTITY NAME] · [REGISTERED ADDRESS] · [CONTACT EMAIL]

See also our Terms of Service.

PulseGrid
PricingTermsPrivacyLog inSign up