PipelinePulse — Privacy Policy
Effective date: 2026-08-23
Last updated: 2026-09-09
This Privacy Policy explains how PipelinePulse, Inc. ("PipelinePulse," "we," "us")
collects, uses, discloses, and protects personal information in connection with our business
proposal-tracking and electronic-signature service at app.getpipelinepulse.com (the "Service") and
our website at https://www.getpipelinepulse.com.
A note on our two roles. PipelinePulse is a business-to-business service.
- For our customers' account users (the sales professionals who hold accounts), and for
visitors to our website and people who contact us, we act as a controller of personal
information.
- For the prospects and recipients whose engagement our customers track through the Service, our
customer is the controller and PipelinePulse acts as a processor on the customer's behalf and
documented instructions. Our handling of that data is governed by our
Data Processing Addendum). If you are a prospect and want to exercise
rights over your data, the business that sent you the proposal is your first point of contact; we will
assist that business as described below and in the DPA.
---
1. Information we collect
1.1 Account users (our customers' personnel)
- Identity and profile: name, business email, job title, company, and role within the organization
(administrator, sales manager, or sales representative).
- Authentication data: login credentials managed through our authentication provider; API keys you
create are stored only as irreversible hashes.
- Usage data: actions taken in the Service, proposals created, and related activity.
1.2 Prospects and proposal recipients (processed on our customers' behalf)
- Identifying information you provide to view a proposal ("gate" information): name, business email,
phone number, job title, and company.
- Engagement telemetry: view sessions, time spent and pages viewed within a proposal, whether and to
whom a proposal was forwarded, device type, and session totals.
- Coarse location: country only, derived at the network level. We do not store IP addresses for
analytics — viewing analytics are collected without retaining IP addresses, and we do not perform
device fingerprinting.
- Electronic-signature information (when a recipient signs): a typed or drawn signature, signer name,
title and email, email-verification status, the consent text and version agreed to, timestamps, a
cryptographic hash of the signed document, browser user-agent, country/region, and — solely for
signature audit and legal defensibility — the signer's IP address (which may be masked, full, or
region-dependent according to the sending organization's configuration). This signature-audit IP is
the only circumstance in which we retain any IP address.
1.3 Billing information
When you subscribe to a paid plan, our payment processor Stripe, Inc. collects and processes your
payment-card or bank-account details, billing name, address, and any tax identifiers, under Stripe's own
terms and privacy policy. PipelinePulse does not store full card or bank-account numbers. We receive
limited billing metadata (such as plan, status, and billing period) to manage your subscription.
1.4 Website visitors and people who contact us
When you visit https://www.getpipelinepulse.com or contact us (e.g., by emailing support@getpipelinepulse.com
or calling us), we collect the information you provide and basic technical information necessary to
operate and secure the site. Our website uses analytics services — Google Analytics (provided by Google
LLC), Zoho, and PostHog — to understand how visitors use the site and to improve our marketing; these set
cookies and collect usage information as described in Section 4. Where required by law (for example, in
the EEA/UK), we request your consent before setting non-essential analytics cookies.
1.5 We do not knowingly collect special-category data
The Service is not intended to process special categories of personal data (such as health, biometric,
or government-ID data) or data of anyone under 18 (or under 16 in the EU/UK).
2. How we use information, and our legal bases
We use personal information to:
- Provide the Service — host and deliver proposals; track engagement and send real-time viewing
alerts to the sending organization; capture and seal electronic signatures; and operate the API,
webhooks, and integrations customers configure. (Legal basis: performance of a contract; and, for
prospect data, our customer's legitimate interests as controller, or the prospect's own request to
view a proposal.)
- Bill and manage subscriptions** through Stripe. (Contract; legal obligation.)
- Secure and maintain the Service, prevent abuse, and enforce our Terms. (Legitimate interests.)
- Communicate with you about the Service, including transactional emails such as alerts and
verification messages, sent through our email provider Postmark. (Contract; legitimate interests.)
- Analyze and improve the Service, including aggregated and de-identified engagement and won/loss
analytics derived from an append-only activity ledger. (Legitimate interests.)
- Comply with law and establish, exercise, or defend legal claims. (Legal obligation; legitimate
interests.)
We do not sell personal information, do not use it for third-party advertising, and do not
use it to profile individuals beyond the Service's engagement analytics.
3. Electronic signatures
Where our customer enables signing, the Service captures the elements needed for a legally attributable
electronic signature under ESIGN/UETA and eIDAS (simple electronic signature): intent, consent, verified
attribution, association to the exact document (via cryptographic hash), and a retained audit record,
sealed into a stamped PDF with an integrity ledger. Because signature records may be needed to establish
or defend legal claims, we retain them and generally exclude them from deletion/anonymization requests
(consistent with GDPR Article 17(3)(e)); we can still provide a copy in response to an access request.
4. Cookies and local storage
We use minimal client-side storage:
- Authenticated app users have a session cookie from our authentication provider, necessary to keep
you logged in.
- Returning proposal viewers may have a first-party browser storage entry (a "viewer pass") that lets
a returning viewer be recognized on the proposal they were invited to, according to the sending
organization's configuration (which may be automatic-with-notice or opt-in). This is functional, is
scoped to a single proposal link, and expires (by default after 30 days).
- The authenticated application uses PostHog for product analytics — to understand how account
users use features and to improve the Service. PostHog sets cookies and/or local storage for this
purpose.
- We do not use device fingerprinting or third-party advertising cookies, and we do not use the
returning-viewer pass for cross-site tracking.
- Our marketing website (https://www.getpipelinepulse.com) uses strictly necessary cookies plus non-essential
analytics cookies from Google Analytics (Google LLC), Zoho, and PostHog to measure site usage and improve our
marketing. Where required by law (EEA/UK), we obtain consent through a cookie banner before setting them,
and you may decline or withdraw consent; we do not use them for cross-context behavioral advertising.
5. How we share information; subprocessors
We share personal information only as needed to provide the Service:
- With the sending organization. Prospect engagement and signature data is made available to the
business that sent the proposal (our customer), who is the controller of that data.
- With subprocessors who process data on our behalf under contract. Our current subprocessors are:
| Subprocessor | Purpose | Location |
| Vercel, Inc. | Application hosting | United States |
| Supabase, Inc. (on AWS) | Database, authentication, file storage, realtime | United States (AWS US-East) |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |
| PostHog, Inc. | Product analytics (in-app and marketing site) | European Union (Germany) — PostHog EU Cloud |
| Zoho (Zoho Corporation)| Marketing and CRM | United States |
We require subprocessors to protect personal data and to process it only for the purposes we specify. We
maintain the current list and will give at least 30 days' advance notice of a new subprocessor, so a
customer may object on data-protection grounds. The current subprocessor list is maintained in
our [Data Processing Addendum](https://www.getpipelinepulse.com/dpa)..
- For legal reasons — to comply with law, respond to lawful requests, or protect rights, safety, and
the security of the Service.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to
this Policy.
We do not sell personal information or share it for cross-context behavioral advertising.
6. International data transfers
We host and process most personal data in the United States (Vercel, Supabase/AWS US-East, Stripe, and
Postmark are US-based). Our product-analytics provider, PostHog, processes data in the European Union
(Germany) on PostHog EU Cloud. If we transfer personal data of individuals in the EEA, UK, or
Switzerland to the United States, we will do so under an appropriate transfer mechanism, such as the
Standard Contractual Clauses (and the UK Addendum), which we will execute before EU/UK personal data
comes into scope.
7. Security
We protect personal data with measures including: encryption in transit (TLS) and at rest;
database row-level security enforcing strict tenant isolation so each organization can access only its
own data; private file storage served only through short-lived signed URLs; **API keys stored only as
hashes and rate-limited; encrypted webhook secrets and signed webhook deliveries; role-based
access with invite-only, email-verified accounts; multi-factor authentication for our privileged
operational access to hosting, database, email, and DNS; append-only audit logging; automated
daily backups with a 7-day rolling retention; and internal security audits on a fixed quarterly
schedule. No method of transmission or storage is completely secure, and we cannot guarantee absolute
security. In-product multi-factor authentication for end users is not currently offered; accounts are
invite-only with mandatory email verification. We do not currently hold SOC 2 or ISO 27001 certification.
8. Data retention
We retain personal data for as long as needed to provide the Service and for the periods below, then
delete or anonymize it:
| Data | Retention |
| Customer content (proposals, revisions, executed contracts) and account/engagement data | Life of the account; deleted or anonymized within 30 days of account termination or a verified deletion request |
| Backups | 7-day rolling window (deleted data ages out within 7 days of primary deletion) |
| Operational/hosting logs | ≤ 30 days |
| Email verification codes | ~15 minutes (single-use) |
| Privacy/signature confirmation links | ~60 minutes (single-use) |
| Returning-viewer "pass" (local storage) | default 30 days, sliding |
| Executed electronic-signature records | Retained as immutable legal records; excluded from deletion where retention is required for legal claims |
Where a legal hold or active dispute applies, deletion is suspended until it is resolved.
9. Your privacy rights
Depending on where you live and your relationship to the data, you may have rights to access, obtain
a copy/portability, correct, delete/erase, restrict or object to processing, and
withdraw consent, and to be free from unlawful discrimination for exercising these rights.
9.1 Prospects (data processed for our customers). If a business sent you a proposal, that business is
the controller of your data — contact them first. If a customer has enabled self-service requests, you may
also submit an access or deletion request directly from the proposal you were sent; we verify the request
through a signed, single-use email confirmation link before acting, and respond with a generic
acknowledgment that does not confirm or deny whether we hold your data. Otherwise, we act on data-subject
requests on the sending organization's instructions, as described in our DPA.
9.2 Account users and others (data we control). Contact legal@getpipelinepulse.com to exercise
your rights. We will verify your identity and respond within the time required by law — generally within
one month under GDPR/UK GDPR (extendable where permitted) and within 45 days under CCPA/CPRA
(extendable by 45 days).
9.3 EEA/UK residents (GDPR / UK GDPR). Our legal bases are described in Section 2. You have the right
to lodge a complaint with your local supervisory authority (in the UK, the ICO). We do not make decisions
producing legal or similarly significant effects about you based solely on automated processing;
engagement analytics inform the sending organization but are not used by us for automated decisions about
individuals under Article 22.
9.4 California residents (CCPA/CPRA). In the last 12 months we have collected the categories of
personal information described in Section 1 for the business purposes in Section 2. **We do not sell or
share (for cross-context behavioral advertising) personal information, and have not in the preceding 12
months.** When we handle personal information on a customer's behalf, we act as that customer's **service
provider** and process it only for the specified business purpose. You have rights to know, access,
delete, and correct, and to non-discrimination; we honor Global Privacy Control and similar opt-out
signals where required by law. Authorized agents may submit requests with proof of authorization.
9.5 How to reach us. For any privacy request or question: legal@getpipelinepulse.com.
10. Children's privacy
The Service is for businesses and is not directed to, and we do not knowingly collect personal
information from, anyone under 18 (or under 16 in the EU/UK). If you believe a minor's information has
been provided to us, contact legal@getpipelinepulse.com and we will delete it if we cannot confirm their
age is 18 years or older.
11. Changes to this Policy
We may update this Policy from time to time. We will post the updated version at
https://www.getpipelinepulse.com/privacy with a new "Last updated" date and, for material changes, provide
additional notice (such as by email or in-app). Your continued use after the effective date constitutes
acceptance.
12. Contact us
Business customers acting as controllers can request our Data Processing Addendum.)
PipelinePulse, Inc.
145 Coffee Bluff Lane, Holly Springs, NC 27540
Privacy: legal@getpipelinepulse.com · Legal: legal@getpipelinepulse.com
Support: support@getpipelinepulse.com · (833) 743-8785