Pulse360

Privacy Policy

Last updated: August 6, 2026

Overview

This policy describes how Pulse360 ("we", "us") collects, uses, and protects data when a Customer Success team (a "workspace") uses the product to manage account health, and when their own customers' account data flows through it via connected integrations.

Data we collect

We collect and process:

  • Account information you create directly — workspace name, team member emails, account names, contacts, touchpoints, and notes.
  • Data synced from tools you connect (Zendesk, Intercom, Salesforce, HubSpot, Pipedrive, Metabase, Stripe, or a generic webhook) — only for the specific accounts a workspace admin confirms should be mapped, and only if that connector is configured.
  • If a CSM connects Slack, their Slack user ID — used to route account health alerts and a weekly digest to them directly in Slack. This is the one connector that sends data out to a destination rather than syncing data in.
  • Connector credentials (API keys/tokens) — encrypted at rest and never displayed back to the browser once saved.
  • Authentication data (email address) via Supabase Auth.
  • If you subscribe to a paid plan, billing identity and subscription status (name, email, plan) via Stripe, and a one-way fraud-prevention signal derived from your payment method — never your full card number — used only to detect repeated free-trial abuse.
  • Feedback or bug reports submitted through the in-app feedback widget (your message, and an email address if you choose to provide one), and contact-form submissions from /contact (name, email, and your message).

How we use it

Data is used to calculate account health scores, generate AI-written insights and QBR briefs, surface renewal and churn-risk alerts, and otherwise run the features you use inside your workspace. We do not sell workspace or account data.

AI processing

When you request an AI-generated insight or QBR brief, relevant account data is sent to Anthropic's Claude API to generate that response. This happens on request, server-side only, and is processed under Anthropic's API terms.

Subprocessors

Pulse360 relies on the following subprocessors to operate:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting.
  • Anthropic — AI processing for insights and QBR briefs.
  • Upstash — rate limiting for public webhook and read-token endpoints.
  • Resend — delivers feedback, contact-form, and password-reset emails, and internal fraud-review alerts to our own team when automated abuse checks flag a workspace for review.

If a workspace admin configures a connector, that provider also processes data on the workspace's behalf — only for the providers actually configured:

Data retention

Retention periods vary by data category:

  • Workspace and account data — retained until a workspace admin deletes it or deletes the workspace. Disconnecting a connector (e.g. Zendesk, Salesforce) stops it from syncing further data immediately, but does not delete data already synced from it — removing that requires deleting the associated account or the workspace itself.
  • Integration event logs (webhook and connector delivery logs, kept for debugging and audit purposes) — retained for up to 90 days, then automatically purged.
  • Billing processing logs (records of which billing events were received and processed, not payment details or transaction history — Stripe remains the system of record for those) — retained on the same 90-day schedule, then automatically purged.
  • The fraud-prevention signal described above — retained indefinitely, including after a workspace is deleted, since deleting it would defeat its purpose of recognizing a returning bad actor.
  • Feedback and contact-form submissions — retained for up to 2 years, then automatically purged.
  • The Slack sent-alerts record (used to avoid duplicate notifications) — retained for as long as your workspace exists rather than on the 90-day schedule above, since some alert types need it to persist until the underlying condition is resolved. Message content, once delivered to Slack, is retained according to that workspace's own Slack retention settings — outside Pulse360's control.

Cookies

We use only strictly necessary cookies to keep you signed in (via Supabase Auth session cookies). We do not use advertising or third-party tracking cookies. We also store a small flag in your browser's local storage to remember that you've seen the cookie notice below, so it doesn't reappear on every visit.

Security

All traffic is encrypted in transit (TLS). Connector credentials are additionally encrypted at the application layer, on top of standard at-rest database encryption. Every workspace's data is isolated from every other workspace at the database level.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you. Workspace admins can delete their account and workspace at any time from Settings. For any other request, contact us using the details below.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy, or requests to access, export, or correct your data: hello@getpulse360.com.