Pulsytics / 2026-09-24-draft-1

Privacy Notice

This notice explains Pulsytics account data and data collected through customer-installed analytics. It is a notice, not a blanket request for consent. Customers must separately inform their own website and app visitors.

1. Who handles the data

For the purposes explained in this notice, the service operator is Orlikon, LLC. Business address supplied in its Stripe account: 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Privacy requests: hello@pulsytics.app. Its legal registration details and this address's status as a registered/business address require confirmation against official records before final publication.

For account, payment administration, support and Pulsytics' own site, the operator determines the purposes of processing. For visitor analytics collected on a customer's site/app, that customer normally decides what to collect and why; Pulsytics processes it on the customer's instructions. The precise roles and instructions must be covered by a reviewed DPA where required.

2. Categories and sources

Account: Google-provided account identifier, email, display name, avatar, session/authentication metadata, billing/customer references, plan, support messages and legal acknowledgment time/version.

Customer analytics: random visitor/session identifiers, normalized page paths, page titles, referral sources and UTM parameters, event names and caller-provided properties, timestamps, device/browser class, goal and revenue events. Optional features can add diagnostic endpoint metadata, site-simulation positions, pseudonymous user keys, GA4 imports, integration tokens and opted-in mobile screen frames.

The web tracker is designed not to persist IP addresses, record web DOM/screens, capture form values or keystrokes, automatically collect email fields or fingerprint browsers. However, custom values supplied by a customer may still contain personal data; masking is not infallible. Networks and infrastructure may transiently process IP addresses in standard request logs independently of the product database.

3. Purposes and lawful grounds

Account and service delivery: authentication, project management, analytics reporting, payment administration, customer support, security, fraud prevention and maintenance. Depending on applicable law, these rely on performance of a contract, legitimate interests where lawful, or legal obligations such as tax/accounting.

Optional tracking on our own marketing site uses a separate analytics preference. Customer-installed tracking requires the customer to determine and document an appropriate lawful basis and to provide its own notice; where consent is needed it must be obtained before tracking. Marketing messages or optional integrations require an appropriate separate basis or choice; accepting Terms is not consent to all personal-data processing.

4. Sharing and service providers

Data may be processed by infrastructure, authentication, payment and communication providers used to deliver the service, including Supabase, Vercel, Google authentication, Stripe and email delivery where enabled. Optional integrations such as Google Analytics, Slack, Cloudflare R2 or third-party AI endpoints only apply where configured and used. We do not claim that every listed provider receives every category of data. Detailed subprocessors, locations and contracts must be verified before publication.

We may disclose information where legally required or to protect users and service security within applicable law. We do not sell customer analytics data to advertisers.

5. International processing and transfers

Processing can involve providers outside your country. Exact storage regions, recipient countries and applicable GDPR/KVKK transfer mechanisms have not yet been verified for publication; they must be documented before offering a conclusive transfer notice. Do not assume data stays within Türkiye, the EEA or any particular region.

6. Retention, export and deletion

Account and billing records are kept as needed for service delivery and legally required accounting or disputes. Project deletion removes associated database records; replay objects have a separate queued deletion process. A user-identification deletion request removes linkable session data and linked detail where available; anonymous data may not be searchable by real-world identity.

Raw event/session retention has candidate thresholds of 90 days (Free) and 400 days (Pro), while Business requires a contract-specific period. Crucially, automatic physical deletion is dry-run by default until an enforcement setting and advance-announced date are active. Dashboard history limits are NOT deletion periods. No automatic deletion deadline is promised until production enforcement is verified and the published policy is updated. Mobile replay is designed for a seven-day expiry with asynchronous object cleanup; optional diagnostics have plan-specific retention. Backup retention still requires operational confirmation.

7. Choices and consent

Our own optional site analytics should not load until you opt in; you can later change that preference. Necessary authentication and security storage may remain. The Pulsytics SDK exposes consent and pause controls to customer sites; each customer is responsible for correct implementation and for honoring withdrawal, browser choices and local requirements. Google and Stripe manage their own cookies and notices.

Where data processing is based on consent, withdrawing it affects future consent-based processing, not prior lawful processing or legally required records. A Terms acknowledgment is not general consent for marketing or analytics.

8. Security

Controls implemented in the product include account authentication, project-level database row-level security, restricted API access, selected client/server redaction, short-lived replay tickets, private replay storage, data export and deletion flows, and access logging for specified sensitive actions. No security method can guarantee zero risk. We do not assert ISO 27001 or SOC 2 certification.

9. Your rights and requests

Depending on the law applicable to you, you may request access, correction, deletion, restriction, portability, objection or withdrawal of consent, and complain to a competent supervisory authority. Contact hello@pulsytics.app. We may need to verify your identity before sharing or changing data. For events collected by a customer's site or app, contact that customer first; we assist them where legally required.

Residents of Türkiye can invoke applicable rights under KVKK Article 11. Rights and response periods may differ by location and processing role. We will not condition service on consent for processing that is not necessary to provide it.

10. Children, changes and contact

The service is not intended for children. Customers must not knowingly send children's personal data or sensitive categories through analytics. Material changes to this notice will be dated and communicated as appropriate. Privacy requests: hello@pulsytics.app. This is a pre-publication draft pending verification of the legal entity, provider transfers and actual retention settings.