Legal
Privacy policy
Last updated 6 September 2026. This is the policy for Pulse Analytics at getpulseanalytics.com. The shorter product explainer is in the knowledge base.
Pulse is operated from the United Kingdom. This is not a substitute for legal advice. Have a solicitor review it before you rely on it for a paid contract.
Two kinds of people
- Site visitors — people who load a website that has our snippet. We do not know who they are.
- Dashboard users — you, logging in with an email to see stats for sites you own.
Site visitors
Our collector is cookieless. It runs even if the visitor rejects a cookie bar. We do not set a tracking cookie, and we do not write localStorage or sessionStorage identifiers for analytics. We do not sell a fingerprint across sites. We do not do session replay, heatmaps, or individual person profiles.
For each event we typically store: event name, path, title, referrer domain/path, UTM fields when present, coarse geo (country, optional region/city/lat/lon), locale, browser, OS, device type, a daily anonymous hash, and optional event properties. Query strings are stripped from URLs and referrers except allowlisted UTM keys, which are stored as their own fields.
The visitor IP is used in memory to look up coarse geo (from the host’s edge headers, or a local geo database). The IP is not stored. We also use IP in memory for a daily hash: SHA-256 of IP + user agent + site + UTC date + a secret. That hash changes every UTC day, so a person cannot be followed across days. Unique visitors, sessions and bounce are estimates from that hash.
pulse.identify is not written to our anonymous event tables. It is only used if the site owner enabled a destination that needs an email (for example HubSpot).
If the site owner turns on our cookie banner, a first-party cookie named pulse_consent is set on their domain. That records Accept/Reject for extra scripts they pasted (GA4, GTM, HubSpot, custom). It is not an analytics id. Reject does not stop our pageviews.
Visitors of a customer site should contact that site’s owner for privacy requests. We cannot identify a visitor in our tables.
Dashboard users
We store your email, a session cookie pulse_session on getpulseanalytics.com (httpOnly, for the logged-in app only), hashed login tokens, and the sites and settings you create (name, domain, banner copy, destination ids you paste). We email a magic link and a 6-digit code when you log in.
To access, correct, or delete your account data, write to us from the email on the account. We will not invent a public inbox here — use that login address so we can match the account.
Who else sees data
We host the app on Vercel. Production data lives in Neon (Postgres). Login email is sent with Resend when that is configured. Optional destinations (GA4 Measurement Protocol, HubSpot) only receive events if you switched them on for that site. We do not send visitor emails to those tools unless you called identify and enabled the destination.
Legal basis (UK GDPR)
Dashboard accounts: we process your email to provide the service (contract / steps to a contract) and to keep the product secure (legitimate interests). Site visitor analytics: the site owner is the controller of their site; we process events as their processor, for aggregated analytics without identifying the visitor. The owner must have their own lawful basis. Our cookieless collector is designed so it can run without a consent cookie; extra scripts they paste are their responsibility and should sit behind their banner.
Retention
Events stay until the site owner deletes the site (which cascades events) or asks us to delete the account. Login challenges expire in minutes. Sessions last 30 days unless you log out.
Related: Terms.
