PipelinePulse — Privacy Policy

Effective date: 2026-08-23

Last updated: 2026-09-09

This Privacy Policy explains how PipelinePulse, Inc. ("PipelinePulse," "we," "us")

collects, uses, discloses, and protects personal information in connection with our business

proposal-tracking and electronic-signature service at app.getpipelinepulse.com (the "Service") and

our website at https://www.getpipelinepulse.com.

A note on our two roles. PipelinePulse is a business-to-business service.

- For our customers' account users (the sales professionals who hold accounts), and for

  visitors to our website and people who contact us, we act as a controller of personal

  information.

- For the prospects and recipients whose engagement our customers track through the Service, our

  customer is the controller and PipelinePulse acts as a processor on the customer's behalf and

  documented instructions. Our handling of that data is governed by our

  Data Processing Addendum). If you are a prospect and want to exercise

  rights over your data, the business that sent you the proposal is your first point of contact; we will

  assist that business as described below and in the DPA.

---

1. Information we collect

1.1 Account users (our customers' personnel)

- Identity and profile: name, business email, job title, company, and role within the organization

  (administrator, sales manager, or sales representative).

- Authentication data: login credentials managed through our authentication provider; API keys you

  create are stored only as irreversible hashes.

- Usage data: actions taken in the Service, proposals created, and related activity.

1.2 Prospects and proposal recipients (processed on our customers' behalf)

- Identifying information you provide to view a proposal ("gate" information): name, business email,

  phone number, job title, and company.

- Engagement telemetry: view sessions, time spent and pages viewed within a proposal, whether and to

  whom a proposal was forwarded, device type, and session totals.

- Coarse location: country only, derived at the network level. We do not store IP addresses for

  analytics — viewing analytics are collected without retaining IP addresses, and we do not perform

  device fingerprinting.

- Electronic-signature information (when a recipient signs): a typed or drawn signature, signer name,

  title and email, email-verification status, the consent text and version agreed to, timestamps, a

  cryptographic hash of the signed document, browser user-agent, country/region, and — solely for

  signature audit and legal defensibility — the signer's IP address (which may be masked, full, or

  region-dependent according to the sending organization's configuration). This signature-audit IP is

  the only circumstance in which we retain any IP address.

1.3 Billing information

When you subscribe to a paid plan, our payment processor Stripe, Inc. collects and processes your

payment-card or bank-account details, billing name, address, and any tax identifiers, under Stripe's own

terms and privacy policy. PipelinePulse does not store full card or bank-account numbers. We receive

limited billing metadata (such as plan, status, and billing period) to manage your subscription.

1.4 Website visitors and people who contact us

When you visit https://www.getpipelinepulse.com or contact us (e.g., by emailing support@getpipelinepulse.com

or calling us), we collect the information you provide and basic technical information necessary to

operate and secure the site. Our website uses analytics services — Google Analytics (provided by Google

LLC), Zoho, and PostHog — to understand how visitors use the site and to improve our marketing; these set

cookies and collect usage information as described in Section 4. Where required by law (for example, in

the EEA/UK), we request your consent before setting non-essential analytics cookies.

1.5 We do not knowingly collect special-category data

The Service is not intended to process special categories of personal data (such as health, biometric,

or government-ID data) or data of anyone under 18 (or under 16 in the EU/UK).

2. How we use information, and our legal bases

We use personal information to:

- Provide the Service — host and deliver proposals; track engagement and send real-time viewing

  alerts to the sending organization; capture and seal electronic signatures; and operate the API,

  webhooks, and integrations customers configure. (Legal basis: performance of a contract; and, for

  prospect data, our customer's legitimate interests as controller, or the prospect's own request to

  view a proposal.)

- Bill and manage subscriptions** through Stripe. (Contract; legal obligation.)

- Secure and maintain the Service, prevent abuse, and enforce our Terms. (Legitimate interests.)

- Communicate with you about the Service, including transactional emails such as alerts and

  verification messages, sent through our email provider Postmark. (Contract; legitimate interests.)

- Analyze and improve the Service, including aggregated and de-identified engagement and won/loss

  analytics derived from an append-only activity ledger. (Legitimate interests.)

- Comply with law and establish, exercise, or defend legal claims. (Legal obligation; legitimate

  interests.)

We do not sell personal information, do not use it for third-party advertising, and do not

use it to profile individuals beyond the Service's engagement analytics.

3. Electronic signatures

Where our customer enables signing, the Service captures the elements needed for a legally attributable

electronic signature under ESIGN/UETA and eIDAS (simple electronic signature): intent, consent, verified

attribution, association to the exact document (via cryptographic hash), and a retained audit record,

sealed into a stamped PDF with an integrity ledger. Because signature records may be needed to establish

or defend legal claims, we retain them and generally exclude them from deletion/anonymization requests

(consistent with GDPR Article 17(3)(e)); we can still provide a copy in response to an access request.

4. Cookies and local storage

We use minimal client-side storage:

- Authenticated app users have a session cookie from our authentication provider, necessary to keep

  you logged in.

- Returning proposal viewers may have a first-party browser storage entry (a "viewer pass") that lets

  a returning viewer be recognized on the proposal they were invited to, according to the sending

  organization's configuration (which may be automatic-with-notice or opt-in). This is functional, is

  scoped to a single proposal link, and expires (by default after 30 days).

- The authenticated application uses PostHog for product analytics — to understand how account

  users use features and to improve the Service. PostHog sets cookies and/or local storage for this

  purpose.

- We do not use device fingerprinting or third-party advertising cookies, and we do not use the

  returning-viewer pass for cross-site tracking.

- Our marketing website (https://www.getpipelinepulse.com) uses strictly necessary cookies plus non-essential

  analytics cookies from Google Analytics (Google LLC), Zoho, and PostHog to measure site usage and improve our

  marketing. Where required by law (EEA/UK), we obtain consent through a cookie banner before setting them,

  and you may decline or withdraw consent; we do not use them for cross-context behavioral advertising.

5. How we share information; subprocessors

We share personal information only as needed to provide the Service:

- With the sending organization. Prospect engagement and signature data is made available to the

  business that sent the proposal (our customer), who is the controller of that data.

- With subprocessors who process data on our behalf under contract. Our current subprocessors are:

  | Subprocessor | Purpose | Location |

  | Vercel, Inc. | Application hosting | United States |

  | Supabase, Inc. (on AWS) | Database, authentication, file storage, realtime | United States (AWS US-East) |

  | Stripe, Inc. | Payment processing and subscription billing | United States |

  | Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |

  | PostHog, Inc. | Product analytics (in-app and marketing site) | European Union (Germany) — PostHog EU Cloud |

| Zoho (Zoho Corporation)| Marketing and CRM | United States |

  We require subprocessors to protect personal data and to process it only for the purposes we specify. We

  maintain the current list and will give at least 30 days' advance notice of a new subprocessor, so a

  customer may object on data-protection grounds. The current subprocessor list is maintained in

  our [Data Processing Addendum](https://www.getpipelinepulse.com/dpa)..

- For legal reasons — to comply with law, respond to lawful requests, or protect rights, safety, and

  the security of the Service.

- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to

  this Policy.

We do not sell personal information or share it for cross-context behavioral advertising.

6. International data transfers

We host and process most personal data in the United States (Vercel, Supabase/AWS US-East, Stripe, and

Postmark are US-based). Our product-analytics provider, PostHog, processes data in the European Union

(Germany) on PostHog EU Cloud. If we transfer personal data of individuals in the EEA, UK, or

Switzerland to the United States, we will do so under an appropriate transfer mechanism, such as the

Standard Contractual Clauses (and the UK Addendum), which we will execute before EU/UK personal data

comes into scope.

7. Security

We protect personal data with measures including: encryption in transit (TLS) and at rest;

database row-level security enforcing strict tenant isolation so each organization can access only its

own data; private file storage served only through short-lived signed URLs; **API keys stored only as

hashes and rate-limited; encrypted webhook secrets and signed webhook deliveries; role-based

access with invite-only, email-verified accounts; multi-factor authentication for our privileged

operational access to hosting, database, email, and DNS; append-only audit logging; automated

daily backups with a 7-day rolling retention; and internal security audits on a fixed quarterly

schedule. No method of transmission or storage is completely secure, and we cannot guarantee absolute

security. In-product multi-factor authentication for end users is not currently offered; accounts are

invite-only with mandatory email verification. We do not currently hold SOC 2 or ISO 27001 certification.

8. Data retention

We retain personal data for as long as needed to provide the Service and for the periods below, then

delete or anonymize it:

| Data | Retention |

| Customer content (proposals, revisions, executed contracts) and account/engagement data | Life of the account; deleted or anonymized within 30 days of account termination or a verified deletion request |

| Backups | 7-day rolling window (deleted data ages out within 7 days of primary deletion) |

| Operational/hosting logs | ≤ 30 days |

| Email verification codes | ~15 minutes (single-use) |

| Privacy/signature confirmation links | ~60 minutes (single-use) |

| Returning-viewer "pass" (local storage) | default 30 days, sliding |

| Executed electronic-signature records | Retained as immutable legal records; excluded from deletion where retention is required for legal claims |

Where a legal hold or active dispute applies, deletion is suspended until it is resolved.

9. Your privacy rights

Depending on where you live and your relationship to the data, you may have rights to access, obtain

a copy/portability, correct, delete/erase, restrict or object to processing, and

withdraw consent, and to be free from unlawful discrimination for exercising these rights.

9.1 Prospects (data processed for our customers). If a business sent you a proposal, that business is

the controller of your data — contact them first. If a customer has enabled self-service requests, you may

also submit an access or deletion request directly from the proposal you were sent; we verify the request

through a signed, single-use email confirmation link before acting, and respond with a generic

acknowledgment that does not confirm or deny whether we hold your data. Otherwise, we act on data-subject

requests on the sending organization's instructions, as described in our DPA.

9.2 Account users and others (data we control). Contact legal@getpipelinepulse.com to exercise

your rights. We will verify your identity and respond within the time required by law — generally within

one month under GDPR/UK GDPR (extendable where permitted) and within 45 days under CCPA/CPRA

(extendable by 45 days).

9.3 EEA/UK residents (GDPR / UK GDPR). Our legal bases are described in Section 2. You have the right

to lodge a complaint with your local supervisory authority (in the UK, the ICO). We do not make decisions

producing legal or similarly significant effects about you based solely on automated processing;

engagement analytics inform the sending organization but are not used by us for automated decisions about

individuals under Article 22.

9.4 California residents (CCPA/CPRA). In the last 12 months we have collected the categories of

personal information described in Section 1 for the business purposes in Section 2. **We do not sell or

share (for cross-context behavioral advertising) personal information, and have not in the preceding 12

months.** When we handle personal information on a customer's behalf, we act as that customer's **service

provider** and process it only for the specified business purpose. You have rights to know, access,

delete, and correct, and to non-discrimination; we honor Global Privacy Control and similar opt-out

signals where required by law. Authorized agents may submit requests with proof of authorization.

9.5 How to reach us. For any privacy request or question: legal@getpipelinepulse.com.

10. Children's privacy

The Service is for businesses and is not directed to, and we do not knowingly collect personal

information from, anyone under 18 (or under 16 in the EU/UK). If you believe a minor's information has

been provided to us, contact legal@getpipelinepulse.com and we will delete it if we cannot confirm their

age is 18 years or older.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version at

https://www.getpipelinepulse.com/privacy with a new "Last updated" date and, for material changes, provide

additional notice (such as by email or in-app). Your continued use after the effective date constitutes

acceptance.

12. Contact us

Business customers acting as controllers can request our Data Processing Addendum.)

PipelinePulse, Inc.

145 Coffee Bluff Lane, Holly Springs, NC 27540

Privacy: legal@getpipelinepulse.com · Legal: legal@getpipelinepulse.com

Support: support@getpipelinepulse.com · (833) 743-8785