Legal
Privacy Policy
This Privacy Policy explains how Pulse collects, uses, shares, and protects information when you use our Shopify analytics platform, and describes your rights under applicable U.S. privacy laws, including the California Consumer Privacy Act (CCPA).
1. Who We Are and Scope of This Policy
Pulse ("Pulse," "we," "us," or "our") operates a cloud-based analytics platform that gives Shopify merchants a single, unified view of their store, marketing, and advertising performance. Pulse is currently operated by Ramandeep Ahuja as a sole proprietorship pending incorporation, and we will update this Policy upon incorporation. This Privacy Policy applies to personal information we collect through our website (pulse.fractionalcto.ai), our web application, and any related services (collectively, the "Service").
This Policy does not apply to personal information that our merchant Users collect from their own end customers through Shopify or elsewhere. As described in Section 3A, merchants are independently responsible for their own customers' data and their own privacy practices; we act as a service provider / data processor for that data.
We currently operate and serve users within the United States.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: name, email address, password (hashed), profile photo
- Business information: business name, Shopify store URL, address, phone number
- Communications: messages you send to our support team
2.2 Information Collected Automatically
- Log data: IP address, browser type and version, pages visited, timestamps, referring URLs
- Device information: device type, operating system, unique device identifiers
- Usage data: features used, actions taken, session duration
- Cookies and similar technologies: see Section 7 below
2.3 Information from Connected Third-Party Platforms
See Sections 3A–3C below for a detailed description of the store, analytics, advertising, and email data we access from the third-party platforms you choose to connect.
3. How We Use Your Information
- Provide, operate, and improve the Service
- Build the dashboards, reports, and cross-channel views you request
- Authenticate your identity and secure your account
- Send transactional communications (receipts, password resets, account alerts, integration errors)
- Send product updates and educational content (you may opt out at any time)
- Respond to your support requests and inquiries
- Monitor and analyze usage trends to improve the Service
- Detect, investigate, and prevent fraudulent or illegal activity
- Comply with legal obligations and enforce our Terms of Service
We do not sell your personal information to third parties. We do not use the store, analytics, or advertising data you connect to train AI or machine learning models for commercial sale to third parties.
3A. Shopify Store Data — Data Processing Disclosure
When you connect your Shopify store, Pulse accesses data via the Shopify Admin API using the specific access scopes you approve. Depending on the scopes you grant, this may include:
- Order data: order details, line items, totals, discounts, refunds, and fulfillment status
- Product and inventory data: product catalog, variants, pricing, and stock levels
- Customer data: names, email addresses, order history, and marketing consent status associated with your store's customers
- Store metadata: shop name, domain, currency, and configuration needed to render dashboards correctly
This data is used exclusively to build the analytics, dashboards, and reports you and your team view within the Service. As between you and Pulse, you remain the data controller for your end customers' personal data, and Pulse acts solely as a data processor / service provider on your behalf. We process this data only as necessary to provide the Service, and in accordance with your instructions as reflected in your account configuration.
You may disconnect your Shopify store, or narrow the access scopes granted, at any time from your Shopify admin or your Pulse account settings. Our access and use of Shopify data complies with Shopify's API License and Terms of Use and, where applicable, Shopify's Protected Customer Data requirements.
Shopify GDPR webhooks. Where required for merchants operating in applicable jurisdictions, we support Shopify's mandatory compliance webhooks (customer data request, customer redact, and shop redact) so that end-customer data requests and deletions initiated through Shopify are honored in our systems.
3B. Analytics and Advertising Platform Data
When you connect analytics or advertising accounts, Pulse accesses the following via each provider's official API:
| Source | Data accessed | Purpose |
|---|---|---|
| Google Analytics 4 (GA4) | Aggregated and event-level site traffic, session, and conversion data | Cross-channel attribution and traffic reporting |
| Google Ads | Campaign, spend, impression, click, and conversion data | Marketing performance dashboards and ROAS reporting |
| Meta Ads | Campaign, spend, impression, click, and conversion data | Marketing performance dashboards and ROAS reporting |
We use this data solely to power the dashboards and reports within your Pulse account. We do not use it to serve ads, build audiences, or share it with advertising networks for targeting purposes. You may disconnect any of these integrations at any time from your Pulse account settings; where applicable, our use of Google user data complies with the Google API Services User Data Policy, and our use of Meta user data complies with Meta's Platform Terms.
3C. Social Platform Data
When you connect a social account, currently Instagram or TikTok, Pulse accesses organic post and account performance data via that platform's official API, which may include post reach, impressions, engagement (likes, comments, shares, saves), follower counts, and video view metrics. We do not access private direct messages, and we do not use this data for advertising, audience building, or any purpose other than displaying performance metrics within your dashboards and reports. Our use of Instagram data complies with Meta's Platform Terms, and our use of TikTok data complies with TikTok's Developer Terms of Service. You may disconnect any social integration at any time from your Pulse account settings.
3D. Email Platform Data
When you connect an email platform, currently Mailchimp or Resend, Pulse accesses campaign-level performance data, such as sends, opens, clicks, bounces, unsubscribes, and deliverability metrics, via that provider's API. We do not access the full content of individual customer emails beyond what is needed to compute these performance metrics, and we do not use this data for any purpose other than displaying it within your dashboards and reports. You may disconnect either integration at any time from your Pulse account settings.
4. How We Share Your Information
We do not sell your personal information. We may share it only in the following circumstances:
4.1 Service Providers (Subprocessors)
We share information with trusted third-party vendors who perform services on our behalf, including:
- Cloud hosting and infrastructure: Vercel (application hosting and delivery) and Supabase (database and backend infrastructure), both operating U.S.-based infrastructure
- Email delivery for transactional and support communications
- Product analytics
- Customer support tooling
These providers are contractually bound to use your information only to perform services for us and in accordance with this Policy. We do not permit subprocessors to use merchant or end-customer data to train their own AI or machine learning models.
4.2 Business Transfers
If we are involved in an incorporation, merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service prior to any such transfer.
4.3 Legal Compliance and Protection
We may disclose your information if required by law, subpoena, or court order, or when we believe in good faith that disclosure is necessary to protect rights, property, or safety.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Data Retention
We retain your personal information and connected store/platform data for as long as your account is active or as necessary to provide the Service. After account deletion or termination:
- Your data is available for export for 30 days
- After 30 days, your data is deleted from production systems
- Backup copies may be retained for up to 90 days before being purged
- Certain records may be retained longer as required by law (e.g., financial and tax records — up to 7 years)
You may request deletion of your personal information at any time by contacting us. We will process your request within 45 days as required by applicable law.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption in transit (TLS 1.2 or higher) via Vercel's edge network, and encryption at rest (AES-256) for data stored in Supabase
- Hashed password storage and Supabase's built-in authentication and row-level access controls
- Scoped, revocable OAuth access tokens for all connected platforms (Shopify, GA4, advertising, social, and email accounts)
- Role-based access controls limiting internal access to personal data
- Regular security review of our infrastructure and dependencies
Despite our efforts, no security system is impenetrable. In the event of a data breach affecting your rights, we will notify you as required by applicable law, and no later than 72 hours after we become aware of the breach.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service:
- Essential cookies: required for authentication and core functionality. Cannot be disabled without impairing the Service.
- Analytics cookies: help us understand how users interact with the Service. These may be disabled.
- Preference cookies: remember your settings and preferences.
You can control cookie settings through your browser preferences. We honor browser-level "Do Not Track" signals for analytics cookies where technically feasible.
8. Children's Privacy (COPPA Compliance)
The Service is a business tool not directed to children, and we do not knowingly collect personal information from children under 13. Users must be at least 18 years old to create an account. If we learn we have inadvertently collected information from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us immediately.
9. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with the following rights:
9.1 Right to Know
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
9.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, legal obligations, or internal uses reasonably aligned with your expectations).
9.3 Right to Correct
You have the right to request correction of inaccurate personal information we maintain about you.
9.4 Right to Opt Out of Sale / Sharing
We do not sell or share personal information for cross-context behavioral advertising. If this changes, we will update this Policy and provide an opt-out mechanism.
9.5 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
9.6 How to Submit a Request
To exercise your rights, you may email us or submit a request through your account settings. We will verify your identity and respond within 45 days (extendable by an additional 45 days with notice). You may designate an authorized agent to make requests on your behalf, subject to verification.
9.7 Categories of Personal Information Collected (CCPA)
In the past 12 months, we have collected: identifiers (name, email, IP address, account username); commercial information (product usage); internet or network activity (log data, usage data, cookie data); geolocation data (approximate location derived from IP address); professional information (business name); and, via connected platforms, your Shopify store's order, product, and customer data, GA4 and advertising performance data, Instagram and TikTok social performance data, and Mailchimp and Resend email campaign performance data as described in Sections 3A–3D. The Service is currently offered free of charge, so we do not currently collect payment information. We do not collect sensitive personal information as defined under CPRA (e.g., Social Security numbers, health data, precise geolocation, racial/ethnic origin).
10. Other U.S. State Privacy Rights
As we expand, we will update this Policy to address rights under additional state privacy laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA). Contact us to inquire about your state-specific rights.
11. International Merchants and End Customers
The Service is currently offered to U.S.-based merchants. If your Shopify store serves customers located outside the United States (including the European Economic Area or United Kingdom), you remain the data controller responsible for ensuring you have a lawful basis to process and export that data, and for providing your own customers with appropriate privacy disclosures. If you access the Service from outside the U.S., be aware that your information may be transferred to, stored, and processed in the United States.
12. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party platforms as described in Sections 3A–3C. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of Shopify, Google, and any advertising or email platforms you connect.
13. Changes to This Privacy Policy
We may update this Policy from time to time. We will notify you of material changes by sending an email to the address associated with your account and/or posting a prominent notice on the Service. Material changes will be effective 30 days after notice. Continued use of the Service after the effective date constitutes acceptance.
14. Contact Us
Pulse
Attn: Privacy
San Francisco, CA
Email: legal@fractionalcto.ai
Support: support@fractionalcto.ai
Website: pulse.fractionalcto.ai
For California residents with unresolved complaints, you may contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov.