Pulset is a website membership for local service businesses: we build your website and keep improving it every month. This policy explains what personal data we collect through pulset.co, how and why we use it, who we share it with, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018). It applies to visitors to this site and to people who join Pulset.
Pulset ("we", "us", "our") is the data controller for the personal data described here. Pulset is operated as a sole trader based in the United Kingdom. You can contact us about anything in this policy, or exercise any of your rights, at hello@pulset.co.
| Data | When | Why |
|---|---|---|
| Your email address | When you start the sign-up flow and accept the terms, or when you contact us | To respond to you, to confirm your place, and (with your consent) to send you news about Pulset |
| Your name, and your phone number if you give one | At the same point, when you accept the terms and start payment. The phone number is optional. | To know who we are working with, to put the right name on your invoices and receipts, and to reach you quickly if something needs a conversation |
| Your billing address | When you enter your card details | Required for card payments and used by our payment provider to check the payment is genuine. It is entered into Stripe's own form and reaches us only as part of your billing record. |
| Your plan choice and the price shown to you (monthly or annual) | If you complete the sign-up flow | To understand demand and to process your membership |
| Messages you send us (support or contact) and any feedback you choose to give | Only if you write to us or fill in the short optional survey | To help you and to improve Pulset. Only what you type; the survey can be skipped entirely. |
| Your cookie-consent choice and its timestamp | When you respond to the cookie banner | To honour your choice and keep a record that consent was given |
| Anonymous page-visit count (which page, and when) | On every visit | To count total visits. No cookie, no IP address, no device details, nothing that identifies you. |
| Usage and device data via the Meta pixel | Only if you choose "Accept all" | To measure interest and the effectiveness of our ads. See our Cookie Policy. |
We do not ask for or store payment card numbers, bank details or other payment information on this site. Card payments, when they apply, are handled entirely by our payment provider (see below). We do not store your email, name or phone number until you have accepted the terms; if you leave the sign-up flow before that point, nothing about you is saved.
If you join, we also collect what we need to build and run your website: your business details, brand assets, images and content you provide; the information needed to set up services you ask us to manage (for example your Google Business Profile, or a CRM or booking tool you connect); your billing details (handled by our payment provider, Stripe, which shares a limited record with us such as the last four digits of your card, billing status and renewal dates, never the full card number); and, if you book a call, the details you give to Calendly. We also process the personal data of your customers only where you ask us to (for example enquiries submitted through your website); for that data you are the controller and we act as your processor under the data processing terms in our membership agreement.
Onboarding is how we learn enough about your business to build for it. We ask for:
We use this to design and build your website, to write content for it, and to manage the services included in your membership. We save a draft as you go, so you can leave the form and come back to it.
We rely on the following legal bases under UK GDPR:
For our standard client website forms, enquiry contents pass through the website handler and Amazon SES to the inbox chosen by that business. We do not keep a separate database of those enquiries or intentionally record their contents in application logs. The business’s inbox provider stores the delivered correspondence. This is separate from Pulset’s own support and membership emails, which we keep as described in this policy.
We keep setup details, such as the website domain, destination inbox, service provider and verification status, to operate the membership. Where a client expressly asks us to connect an existing mailing list, we process the necessary subscriber details and consent evidence on its instructions. These records belong in the agreed marketing system, not a separate Pulset subscriber database. We do not add enquirers to marketing simply because they contacted a client, and we do not use client mailing lists to promote Pulset. Any future managed marketing service will have its own agreed scope before processing begins.
The business whose website you used is your contact for questions about its enquiries and marketing. Its privacy notice explains the services enabled on its website, provider retention, international processing and your rights. We assist that business with requests concerning information we process for it.
We use a small number of trusted providers, who act only on our instructions. This list is generated from our code, so it cannot fall out of date with what we actually use.
| Provider | What they do | What they receive | Where |
|---|---|---|---|
| Vercel | Hosts our client websites and delivers the pages you see. | IP address (transient, in server logs) | United States and global edge network |
| Supabase | The database behind the site and your account, and the sign-in that protects it. | Email address Account and membership records Onboarding answers Messages Consent records |
European Union |
| Stripe | Takes payments and manages memberships. Your card details go straight to Stripe and never reach us. | Name Email address Billing details Payment records |
European Union and United States |
| Resend | Sends the emails we send you, including sign-in links and receipts. | Email address The content of emails we send you |
European Union and United States |
| Amazon Web Services | Delivers enquiries from client websites to the inbox chosen by that business. | The contact details and message entered in a client website enquiry form | United Kingdom and United States |
| Anthropic | Helps write a short summary of your onboarding answers back to you, and drafts content for your website. | Business details you give us: industry, services, areas, pricing and positioning | United States |
| Sentry | Tells us when something breaks, so we can fix it before you have to report it. | Technical error details. We remove cookies, sign-in tokens and account identifiers before sending. | European Union |
| Our email provider. A script reads replies sent to our support address so they appear against your record. | Email address The content of emails you send us |
European Union and United States | |
| Domain registries (RDAP) | Checks whether a domain name you are considering is already taken. Only the domain you type is sent. | The domain name you enter, which may be your business name | United Kingdom and United States |
| QuiverAI | Turns your logo into a vector file, so it stays sharp at any size from a favicon to a van. | Your logo image | United States |
| OpenAI | Writes the description of each brand direction we draw for you, from your answers and the artwork itself. | Business details you give us: trade, services, who you want to reach and how you want to come across The logo artwork drawn for you |
United States |
Declared but not currently in use: Cloudflare and Google public DNS (checks how a domain is currently pointed, so we can tell you what needs changing before launch), Calendly (books introduction calls. loads only if you open the scheduler), Meta (measures whether our advertising works. loads only if you accept analytics and advertising cookies). If we switch any of these on, this page changes first.
We do not sell your personal data, and we do not use it to train AI models. Where we use AI to help write content, your details are sent as instructions for that piece of work and are not used to train anything.
What sets something in your browser:
Your email, plan choice, messages and consent record are stored in the European Union. Transfers between the UK and EU are covered by the UK's adequacy regulations. Where a provider processes data outside the UK/EU (for example Meta, Calendly or Stripe in the United States), that transfer is protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework and/or the International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses.
We use encryption in transit (HTTPS), access controls, a database with row-level security, and reputable providers. Only the minimum data needed is collected, and only authorised people can access it. No method of transmission or storage is completely secure, but we take reasonable steps to protect your information and will notify you and the ICO of a personal data breach where the law requires.
Under UK GDPR you have the right to:
To exercise any of these, email hello@pulset.co. We will respond within one month. You also have the right to complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to help first.
We use a minimal set of cookies and similar technologies, and load nothing non-essential without your consent. See our Cookie Policy for the full list and to change your choice.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. This site is intended for businesses and people aged 18 or over; it is not directed at children, and we do not knowingly collect their data.
We may update this policy as Pulset develops. We will change the date at the top when we do, and for significant changes we will make this clear on the site.
Questions or requests: hello@pulset.co.