Pulse360

Privacy Policy

Last updated: July 13, 2026

Overview

This policy describes how Pulse360 ("we", "us") collects, uses, and protects data when a Customer Success team (a "workspace") uses the product to manage account health, and when their own customers' account data flows through it via connected integrations.

Data we collect

We collect and process:

  • Account information you create directly — workspace name, team member emails, account names, contacts, touchpoints, and notes.
  • Data synced from tools you connect (Zendesk, Intercom, Salesforce, HubSpot, Pipedrive, Metabase, Stripe, or a generic webhook) — only for the specific accounts a workspace admin confirms should be mapped, and only if that connector is configured.
  • Connector credentials (API keys/tokens) — encrypted at rest and never displayed back to the browser once saved.
  • Authentication data (email address) via Supabase Auth.

How we use it

Data is used to calculate account health scores, generate AI-written insights and QBR briefs, surface renewal and churn-risk alerts, and otherwise run the features you use inside your workspace. We do not sell workspace or account data.

AI processing

When you request an AI-generated insight or QBR brief, relevant account data is sent to Anthropic's Claude API to generate that response. This happens on request, server-side only, and is processed under Anthropic's API terms.

Subprocessors

Pulse360 relies on the following subprocessors to operate:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting.
  • Anthropic — AI processing for insights and QBR briefs.
  • Upstash — rate limiting for public webhook and read-token endpoints.

If a workspace admin configures a connector, that provider also processes data on the workspace's behalf — only for the providers actually configured:

Data retention

Workspace and account data is retained until a workspace admin deletes it or deletes the workspace. Raw integration event logs (webhook and billing-event delivery logs, kept for debugging and audit purposes) are retained for up to 90 days and then automatically purged.

Cookies

We use only strictly necessary cookies to keep you signed in (via Supabase Auth session cookies). We do not use advertising or third-party tracking cookies. We also store a small flag in your browser's local storage to remember that you've seen the cookie notice below, so it doesn't reappear on every visit.

Security

All traffic is encrypted in transit (TLS). Connector credentials are additionally encrypted at the application layer, on top of standard at-rest database encryption. Every workspace's data is isolated from every other workspace at the database level.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you. Workspace admins can delete their account and workspace at any time from Settings. For any other request, contact us using the details below.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy: [privacy@yourdomain.com — replace with a real contact before this page is used with real customer data].