← Back to app
PULSE

Privacy Policy

Pulse Social Command Center · Effective date: July 8, 2026

This Privacy Policy explains how Pulse Payments LLC (dba Pulse Technologies) ("Pulse", "we", "us") collects, uses, and protects information in connection with the Pulse Social Command Center (the "Service") — a multi-tenant software service that lets customer organizations ("Customers") draft, schedule, and publish social media content to social accounts they own or are authorized to manage across supported networks, send and receive business text messages (Pulse SMS), build on the Service through a public API and webhooks, and access the Service through our web app and native mobile apps.

1. Who we are and our role

The Service is provided by Pulse to Customers and their authorized users. Our role depends on the data:

2. Information we collect

CategoryExamples
Account informationName, email address, role, organization membership, and a securely hashed password.
Content you createDraft and scheduled posts, captions, hashtags, and any images, media, or files you upload — including images or documents you give the AI assistant to draft posts from (these are processed by our AI provider; see Sub-processors).
AI assistant (PiP) memoryTo personalize the in-app AI assistant, we store a small per-user profile of work-style preferences it infers from your conversations with it — for example your preferred tone, goals, and recurring topics. It is designed to exclude sensitive personal data (such as passwords or payment details), is private to your own account, and you can view, edit, or clear it at any time from the assistant's "What I remember about you" panel.
Connected social accountsAccess tokens and identifiers for the social networks you connect (e.g. LinkedIn, Facebook Pages, Instagram business accounts, X, TikTok, YouTube, Pinterest, Threads, Google Business Profile, Bluesky, Mastodon, Reddit, Telegram, Tumblr), so the Service can publish on your behalf.
Mobile & messaging information (Pulse SMS)Phone numbers and names of the contacts a Customer adds, optional contact notes, the content and media of messages sent and received over SMS, MMS, WhatsApp, and RCS, message delivery status, opt-out status, a consent-event log (opt-ins/opt-outs with source and timestamp), and the dedicated phone number provisioned for the organization.
Email marketing information (Pulse Email)The email addresses, names, and tags of the contacts a Customer adds, imports, or who subscribe through a Customer's hosted signup form; each contact's subscription status; the content of campaigns, automations, and templates a Customer creates; the Customer's verified sending domain; and per-message engagement (sent, delivered, opened, clicked, bounced, unsubscribed). A do-not-email suppression list of unsubscribes, bounces, and complaints is maintained and enforced on every send.
Ecommerce store data (Shopify)If a Customer connects a Shopify store, we receive its orders and checkouts via Shopify webhooks — the buyer's email and (for abandoned-checkout recovery) name, the order/checkout total and currency, the line items (product titles, quantities, prices, image URLs), timestamps, and Shopify's recovery link. This powers ecommerce automations, revenue attribution, and customer segmentation. Shopify is the Customer's own platform (the Customer is the controller); we process this data on the Customer's behalf and store the connection credentials securely (never shown back). Card/payment details are handled by Shopify and are never received by Pulse.
Voice / call data (Pulse Voice)When a Customer adds an AI voice call to a journey, we place outbound calls to the phone numbers on the Customer's list and process the call audio, a transcript, the AI agent's summary and disposition (answered / voicemail / no-answer), the call duration, and the calling/called numbers. This powers the Customer's voice-engagement campaigns and post-call follow-up (including logging the outcome to a connected CRM). Pulse Voice is used solely to deliver the calling the Customer configures; the Customer is the controller and is responsible for obtaining prior express written consent from the individuals it calls and for complying with the TCPA and applicable calling-time and do-not-call rules (see the Terms). No card or payment details are collected on these calls.
Blog posts & CMS publishingThe blog posts a Customer drafts in the Service — title, SEO metadata, and body (Customer Content). Drafting uses our AI sub-processor (Anthropic) and, where the Customer enables it, live web search for research. If a Customer connects a content management system to publish to (WordPress, Webflow, Ghost, Hygraph, or Medium), we store that connection's credentials securely (write-only, never shown back) and, on the Customer's instruction, send the post to that CMS. The CMS is the Customer's own platform — we publish on the Customer's behalf and are not the CMS provider.
Text-to-pay requestsFor payment requests a Customer sends by text, we store the amount, description, recipient name/number, and the payment status. Card details are entered only on the gateway's hosted page and are never received or stored by Pulse.
Mobile app dataIf you install our native app, a device push token (via our push provider) so we can deliver notifications you enable. The app loads the same hosted Service over a secure connection.
Developer data (API & webhooks)API keys you generate (stored only as a hash) and the webhook endpoint URLs and signing secrets you configure.
Billing informationYour organization's plan, subscription status, and a payment-gateway customer/subscription reference. Card details are entered on the payment gateway's hosted page — Pulse does not receive or store full card numbers.
Support requestsWhen you contact support, the content of your tickets and live chats — your messages, our replies, and any PiP assistant exchange you attach — plus the status and category of the request.
Usage & product analyticsIn-product activity — which screens are used and for how long, by user and organization — used to power the admin Usage dashboards and to help us understand engagement and improve the Service. This is first-party only (stored in our own database); we use no third-party advertising or analytics SDKs.
Operational dataSign-in timestamps, publishing job status, audit-log entries for sensitive actions, rate-limiting counters, and error logs needed to operate and secure the Service.

3. How we use information

4. Multi-tenancy & data isolation

Each organization is a separate tenant. A Customer's content, connected accounts, members, and queue are segregated by organization and are not shared with or accessible to other Customers. Pulse platform administrators may access organization records for support, billing, and operating the Service, and — to troubleshoot an issue — may start a time-limited support session that acts within a Customer's workspace. Every such session is recorded in the audit log (who, when, and which organization).

5. Sub-processors

We use a small number of trusted service providers to run the Service, sharing only what each needs to perform its function:

ProviderPurpose
VercelApplication hosting and serverless functions; media storage (Vercel Blob).
NeonManaged PostgreSQL database where accounts, content, and connection tokens are stored.
AnthropicAI generation and the in-app assistant (PiP). Brand context and prompts (and, for alt text, the relevant image) are sent to Anthropic to produce draft copy, to power the assistant that plans, drafts, triages, and personalizes within your workspace, and to surface live trend context using web search. Inputs are not used to train models.
fal.ai (if enabled)AI image generation. Prompts and brand-kit details are sent to produce images you request.
ElevenLabs (if enabled)AI voiceover/text-to-speech for video. The text you provide is sent to generate audio.
Connected social networksWhen you connect an account and publish, your content and media are sent to that network's API to create the post — e.g. Meta (Facebook, Instagram), LinkedIn, X, TikTok, YouTube, Pinterest, Threads, Google Business Profile, Bluesky, Mastodon, Reddit, Telegram, and Tumblr. Each is governed by its own terms and privacy policy.
Twilio (Pulse SMS)Provisioning phone numbers and sending/receiving SMS, MMS, WhatsApp, and RCS messages. Contact phone numbers and message content are processed by Twilio solely to deliver the messaging service. Mobile information is not shared for Twilio's own marketing.
PulseVoice (Pulse Voice, if enabled)Placing the outbound AI voice calls a Customer configures in a journey and running the AI agent. Recipient phone numbers, the call audio, and its transcript are processed — through PulseVoice's telephony carrier and its speech-to-text, language-model, and text-to-speech providers — solely to complete the call on the Customer's behalf. Not used for PulseVoice's own marketing.
Meta / WhatsApp (if enabled)Delivering WhatsApp Business messages (via Twilio) when a Customer enables WhatsApp. Recipient numbers and message content are processed to deliver the message, governed by WhatsApp's terms.
Google (if enabled)Delivering RCS Business Messaging (via Twilio) when a Customer enables RCS. Recipient numbers and message content are processed to deliver the message.
Customer's archiving / supervision system (if enabled)If a Customer turns on compliance capture, a copy of its communications is forwarded to the archiving, supervision, or eDiscovery system the Customer configures and controls — e.g. a webhook/HTTPS endpoint, an SMTP journaling address, a Microsoft 365 / Purview mailbox, Proofpoint, or SFTP to Smarsh / Global Relay. This is the Customer's own system or vendor, not a Pulse sub-processor.
OneSignal (mobile app)Delivering push notifications to the native app. Receives a device push token and the notification content for notifications you enable.
Sentry (if enabled)Application error monitoring. Receives technical error details (and may include limited request context) to help us diagnose and fix problems.
Atlassian (Jira Service Management)Our support help desk. When you open a support ticket or live chat, its content (and our replies) are processed in Atlassian's service desk so our team can help you.
Apollo (if enabled)Contact enrichment. When an admin enriches a contact, that contact's name (and any known email or company) is sent to Apollo to return professional data — title, company, work email, LinkedIn — which is saved to the contact. Not used for Apollo's own marketing.
Connected CMS (if enabled)When you connect a CMS and publish a blog post, the post's title, body, and metadata are sent to that CMS's API to create the entry — e.g. Hygraph, WordPress, Ghost, Webflow, or Medium. Each is the Customer's own system, governed by its own terms.
PulseTech payment gatewayProcessing subscription payments via a hosted payment page (card data is handled by the gateway).
Resend (if enabled)Sending account invitation, verification, password-reset, and report emails; and delivering the opted-in marketing email a Customer sends through Pulse Email (campaigns, automations, signup-form confirmations). Contact email addresses and message content are processed by Resend solely to deliver the email on the Customer's behalf, and are not used for Resend's own marketing.

Some sub-processors are engaged only when a Customer enables the related feature (for example, image or voice generation, the mobile app, or error monitoring). The current list is available on request.

YouTube API Services

When you connect a YouTube channel, the Service uses YouTube API Services to upload the videos you create and to read your channel's name (so we can show which channel is connected). By connecting YouTube you agree to the YouTube Terms of Service, and your use of Google and YouTube data is also governed by the Google Privacy Policy. We access your YouTube data solely to provide the publishing features you request — we do not use it for advertising, do not sell it, and do not share it with third parties except as needed to operate the Service. We store your YouTube access and refresh tokens only while your channel is connected, and we delete them when you disconnect. You can revoke the Service's access to your YouTube and Google data at any time from the Google security settings page at https://security.google.com/settings/security/permissions (also reachable at myaccount.google.com/permissions), and you can disconnect the channel at any time in Pulse under Admin → Connections.

6. Mobile information & SMS (Pulse SMS)

When a Customer uses Pulse SMS, the Service processes mobile phone numbers and message content to send and receive texts on the Customer's behalf. As with other Customer Content, the Customer is the controller of its contacts' information and Pulse acts as a processor.

7. Platform data use & limitations

8. Cookies

We use a single, strictly necessary session cookie to keep you signed in. It is httpOnly and used only for authentication. We do not use advertising or third-party tracking cookies.

9. Data retention

We retain account and content data for as long as the relevant organization account is active or as needed to operate the Service. Invitation and password-reset tokens are short-lived and expire automatically. On termination of a Customer's account, we delete or return Customer content as described in the Data Processing Addendum.

10. Your data rights — export & deletion

You can exercise core data rights yourself from Security in the app:

Organization administrators can also remove a member, disconnect connected accounts, and delete content directly in the Service. To request export or deletion of an organization and its associated data, or to exercise other rights under applicable law, contact pulselegal@pulsetechnologies.ai. We action verified requests within 30 days. Content already published to a third-party platform must be removed on that platform.

11. Security

We protect data with industry-standard measures: encrypted transport (HTTPS), passwords stored only as salted hashes, one-time tokens stored only as hashes, httpOnly + Secure session cookies, optional two-factor authentication and single sign-on, role-based access control with tenant isolation, rate limiting on sign-in and AI endpoints, an audit log of sensitive actions (including support sessions), pre-publish screening for sensitive data, and social access tokens kept server-side. No method of transmission or storage is 100% secure, but we work to protect your information.

12. International users & children

The Service is intended for business use by adults and is not directed to children. If you access the Service from outside the United States, understand that your information may be processed in the United States.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, notifying account holders.

14. Contact

Pulse Payments LLC (dba Pulse Technologies)
9160 Forum Corporate Pkwy, Suite 350, Fort Myers, FL 33905
Email: pulselegal@pulsetechnologies.ai

Questions about this policy? Contact pulselegal@pulsetechnologies.ai.