Pulset is a website membership for local service businesses: we build your website and keep improving it every month. This policy explains what personal data we collect through pulset.co, how and why we use it, who we share it with, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018). It applies to visitors to this site and to people who join Pulset.
Pulset ("we", "us", "our") is the data controller for the personal data described here. Pulset is operated as a sole trader based in the United Kingdom. You can contact us about anything in this policy, or exercise any of your rights, at hello@pulset.co.
| Data | When | Why |
|---|---|---|
| Your email address | When you start the sign-up flow and accept the terms, or when you contact us | To respond to you, to confirm your place, and (with your consent) to send you news about Pulset |
| Your plan choice and the price shown to you (monthly or annual) | If you complete the sign-up flow | To understand demand and to process your membership |
| Messages you send us (support or contact) and any feedback you choose to give | Only if you write to us or fill in the short optional survey | To help you and to improve Pulset. Only what you type; the survey can be skipped entirely. |
| Your cookie-consent choice and its timestamp | When you respond to the cookie banner | To honour your choice and keep a record that consent was given |
| Anonymous page-visit count (which page, and when) | On every visit | To count total visits. No cookie, no IP address, no device details, nothing that identifies you. |
| Usage and device data via the Meta pixel | Only if you choose "Accept all" | To measure interest and the effectiveness of our ads. See our Cookie Policy. |
We do not ask for or store payment card numbers, bank details or other payment information on this site. Card payments, when they apply, are handled entirely by our payment provider (see below). We do not store your email until you have accepted the terms; if you leave the sign-up flow before that point, nothing about you is saved.
If you join, we also collect what we need to build and run your website: your business details, brand assets, images and content you provide; the information needed to set up services you ask us to manage (for example your Google Business Profile, or a CRM or booking tool you connect); your billing details (handled by our payment provider, Stripe, which shares a limited record with us such as the last four digits of your card, billing status and renewal dates, never the full card number); and, if you book a call, the details you give to Calendly. We also process the personal data of your customers only where you ask us to (for example enquiries submitted through your website); for that data you are the controller and we act as your processor under a separate agreement.
We rely on the following legal bases under UK GDPR:
We use a small number of trusted providers ("processors") who act only on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Netlify | Website hosting and content delivery | US / global |
| Supabase | The database that stores your email, plan choice, messages and consent record | European Union |
| Meta Platforms | The Meta pixel, only if you accept analytics cookies | EU / US |
| Calendly | Call bookings, only if you open the scheduler | US |
| Stripe | Card payments and subscriptions, only if you become a paying member | EU / US |
| Email delivery provider | Sending you transactional and (with consent) marketing email | EU / US |
We may also disclose data if required by law, to establish or defend legal claims, or as part of a business transfer. We do not sell your personal data, and we do not share it for anyone else's independent marketing.
Your email, plan choice, messages and consent record are stored in the European Union. Transfers between the UK and EU are covered by the UK's adequacy regulations. Where a provider processes data outside the UK/EU (for example Meta, Calendly or Stripe in the United States), that transfer is protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework and/or the International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses.
We use encryption in transit (HTTPS), access controls, a database with row-level security, and reputable providers. Only the minimum data needed is collected, and only authorised people can access it. No method of transmission or storage is completely secure, but we take reasonable steps to protect your information and will notify you and the ICO of a personal data breach where the law requires.
Under UK GDPR you have the right to:
To exercise any of these, email hello@pulset.co. We will respond within one month. You also have the right to complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to help first.
We use a minimal set of cookies and similar technologies, and load nothing non-essential without your consent. See our Cookie Policy for the full list and to change your choice.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. This site is intended for businesses and people aged 18 or over; it is not directed at children, and we do not knowingly collect their data.
We may update this policy as Pulset develops. We will change the date at the top when we do, and for significant changes we will make this clear on the site.
Questions or requests: hello@pulset.co.