Privacy Policy
Last updated 4 September 2026
Placeholders to replace before launch: the contact address privacy@example.com and the governing jurisdiction below. This document describes the software accurately, but it is a template, not legal advice — have someone qualified read it if you are collecting at scale or from regulated sectors.
Pulse runs a waitlist. This page explains exactly what we store when you enter your email address, why we store it, and how to get rid of it.
What we collect
When you submit the form on the homepage, we record the following. There is nothing else — no advertising identifiers, no third-party trackers, and no cookies.
| Data | Why |
|---|---|
| Your email address | To confirm your signup and tell you when access opens. |
| Confirmation status and timestamps | To know whether you confirmed, and so we never email an address that has not opted in. |
Referring page and campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) | To understand which channels people arrive from. Only these five named tags are stored; anything else in the URL is discarded. |
| A one-way hash of your IP address | To rate-limit the form against abuse. We salt and hash the address before storing it, so the raw IP is never written to the database and the stored value cannot be reversed back into one. |
| Your browser’s user-agent string | To distinguish real signups from automated ones. |
Confirmation and unsubscribe links
The links in our emails carry a random token. We store only a SHA-256 hash of that token, never the token itself, so someone who obtained a copy of our database still could not confirm or unsubscribe on your behalf. The confirmation token is single-use and is destroyed the moment you click it.
Why we are allowed to hold it
Consent. You gave it by entering your address and clicking the confirmation link we sent. We use double opt-in specifically so that a mistyped or maliciously entered address never ends up on the list — an address that is never confirmed is never emailed again.
Who else sees it
We do not sell your data, share it for advertising, or hand it to anybody for their own purposes. It passes through three service providers who process it on our behalf:
- Supabase — hosts the database the list is stored in.
- Resend — delivers the confirmation email.
- Vercel — hosts the website itself.
How long we keep it
Until you ask us to delete it, or until the waitlist is wound up, whichever comes first. If you unsubscribe we keep a record that the address opted out — that is what stops us from mailing it again by mistake if it is re-entered later. Ask for erasure and that goes too.
Your rights
You can ask us to show you what we hold about you, correct it, delete it, or hand it over in a portable format. You can withdraw consent at any time, and you can complain to your local data protection authority if you think we have handled it badly.
The fastest routes: click unsubscribe in any email we send, or email privacy@example.com. We will respond within 30 days.
Cookies
This site sets none. There is no analytics script and no consent banner, because there is nothing to consent to.
Children
Pulse is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If we change this policy we will update the date at the top. Material changes affecting people already on the list will be sent by email.
Contact
Questions about any of this: privacy@example.com. Governed by the laws of [jurisdiction to be specified].