Legal
Privacy Policy
Effective July 27, 2026 · Calgary, Alberta, Canada
Pulse Appointments is operated by Idowu Ayeni. This policy explains how Pulse collects, uses, discloses, protects, and retains personal information when businesses and clients use our website, mobile applications, booking pages, and related services.
1. Information we collect
Account and business information: names, business details, email addresses, phone numbers, locations, staff profiles, login and security settings.
Booking and client information: appointment details, services, notes, intake answers, contact details, preferences, messages, reviews, invoices, and transaction references entered by a business or client.
Technical information: IP address, browser or app type, device information, timezone, login events, cookies, diagnostics, and security logs.
Payment information: Stripe collects card and banking details directly. Pulse receives limited identifiers, status, amount, and transaction records, but does not store complete card numbers or security codes.
2. How we use information
- Provide accounts, online booking, scheduling, reminders, messaging, payments, reporting, support, and related platform functions.
- Authenticate users, prevent fraud and abuse, investigate incidents, and protect the platform.
- Process subscriptions and transactions, maintain financial records, and meet legal obligations.
- Improve reliability and usability using diagnostics and aggregated information.
- Send service communications. Marketing email or SMS is sent only where permitted by Canada's anti-spam legislation, and includes an unsubscribe method where required.
3. Business and platform responsibilities
Pulse Appointments is built with privacy-conscious workflows for service businesses. Compliance responsibilities may vary by country, region, industry, and business use case.
Pulse operates from Alberta and handles personal information under applicable Canadian privacy laws, including Alberta's Personal Information Protection Act (PIPA) and, where applicable, the federal Personal Information Protection and Electronic Documents Act (PIPEDA).
Businesses using Pulse decide what client information to collect and why. Each business is responsible for its notices, consents, lawful use, staff access, retention requirements, and any industry-specific obligations. Pulse processes that information to provide the services requested by the business.
Pulse is not a health-information custodian merely because a business enters appointment or intake information. Regulated providers remain responsible for determining whether health-sector laws apply and for entering any required information-management agreement.
4. Service providers and disclosure
We do not sell personal information. We disclose information only as needed to operate Pulse, complete a user's request, protect rights and safety, complete a business transaction, or comply with law.
Providers may include Stripe for payments, Twilio for SMS, Resend for email, Expo and device-platform services for push notifications, Railway and other infrastructure providers for hosting, Sentry for error monitoring, and OpenAI for the support agent described below. These providers may process information outside Alberta or Canada, where it may be subject to foreign law.
AI support agent. When you use the in-app help chat (Pulse Business mobile app), the text you type — along with the related appointment's details where applicable (e.g. the business name and the subject of your request) — is sent to OpenAI to generate a reply. We do not use this information to train OpenAI's models or for advertising. An in-app notice discloses this, and you must give explicit consent before your first message is sent; you may instead email privacy@pulseappointments.com directly at any time. Conversations are retained in our own systems only as long as needed to resolve your request and for audit purposes, then deleted on our normal retention schedule.
Businesses and their authorized staff can access their own client records. Clients should contact the relevant business first about records controlled by that business.
5. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encrypted network connections, password hashing, access controls, monitoring, backups, and optional two-factor authentication.
No internet service can guarantee absolute security. Users must protect credentials, enable two-factor authentication, restrict staff access, and notify us promptly of suspected unauthorized use.
Where a privacy breach creates a real risk of significant harm or otherwise requires notice, we will investigate, keep required records, and notify affected people and regulators as required by applicable law.
6. Retention, access, and deletion
We retain information only as long as reasonably needed for the purposes described here, an active account, backup and dispute cycles, fraud prevention, and legal, tax, accounting, or regulatory requirements. Retention periods vary by record type.
You may ask to access or correct personal information held by Pulse, withdraw consent where processing depends on consent, or request deletion. Some information cannot be deleted immediately where retention is legally required, needed to complete a transaction, protect legal rights, or contained in secured backups pending normal deletion.
Requests may require identity verification. We aim to respond within the period required by applicable law. Client-record requests may be referred to the business that controls those records.
7. Cookies, communications, and choices
Pulse uses necessary cookies for authentication, security, preferences, and core operation. Optional analytics — Google Analytics, Microsoft Clarity, the Meta Pixel and Conversions API, and the TikTok Pixel and Events API — are used only according to the consent choices presented on the site: if you choose “Necessary only” or don't respond, none of this data (including the calls our servers make to Meta and TikTok) is sent. See our subprocessors list for full detail.
Appointment confirmations, receipts, security alerts, and account notices are service messages. You can change optional business notifications in settings, use the unsubscribe link in marketing messages, or contact the sender. Device push notifications can be disabled in device settings.
If you sign up for our newsletter (booking tips, guides), your email address is added to a separate mailing list hosted by Resend — distinct from the transactional email described above — only after you opt in. Every newsletter includes an unsubscribe link, and you can also unsubscribe by emailing privacy@pulseappointments.com.
8. Google services and Google Calendar data
Data Pulse accesses. When you choose to connect Google Calendar, Pulse receives the connected Google account email address, OAuth authorization tokens, and access to the selected primary calendar. To check availability, Pulse reads event start and end dates and times, busy/free status, cancellation status, and technical event identifiers. Pulse does not read external-event titles, descriptions, notes, locations, or attendees when checking availability. For appointments created by Pulse, we process the Google event identifier and status to synchronize changes and deletions.
How we use it. We use this data only to show accurate availability, prevent double-booking, and create, update, reschedule, or cancel Google Calendar events for appointments requested by the user. The event sent to Google may include the service and client name, date, time, timezone, appointment notes, location or meeting link, and, where provided, the attendee's email address. That information comes from the Pulse account and is sent to Google to provide the requested synchronization.
Storage and retention. External-event data used to calculate busy periods is processed transiently and is not copied into our application database. While the connection remains active, we retain the connected email address, encrypted OAuth tokens, calendar identifier, synchronization cursors, and channel identifiers needed to operate the integration. A Google identifier for an event created by Pulse may be retained with the appointment record for that record's retention period. OAuth tokens and connection metadata are retained only until you disconnect Google Calendar, delete the relevant account, or Google revokes access.
Sharing and service providers. Pulse does not sell Google user data, use it for advertising, or transfer it to data brokers. It may be processed only by Google and by our hosting, database, security, and infrastructure providers acting on our behalf under confidentiality and security obligations. We do not permit those providers to use Google data for their own purposes.
AI and Limited Use. Pulse does not send data obtained from Google Calendar to OpenAI or any other AI provider, and does not use it to develop, improve, or train generalized AI or machine-learning models. If this practice changes, we will first update this policy and obtain any required consent. Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Security. We transmit Google data over encrypted TLS connections. OAuth tokens are encrypted at rest, protected by role-based access controls, and available only to authorized components that provide calendar synchronization. We use short-lived, single-use OAuth state values and authenticated webhook secrets to reduce unauthorized access.
Disconnecting and deletion. An authorized owner or staff member can open Settings → Calendar in Pulse and select Disconnect Google Calendar. This stops synchronization and deletes OAuth tokens and connection metadata from Pulse's active systems. You may also remove access through your Google Account security settings. To request account deletion or deletion of other associated Google data, email privacy@pulseappointments.com. Residual copies may remain temporarily in protected backups until normal rotation and are not used for other purposes.
9. Children and international users
Business accounts are not intended for anyone under 18. A business may accept bookings for a minor where the parent, guardian, or business has the authority and consent required by law.
Users outside Canada understand that information may be processed in Canada and other countries where our providers operate. Local rights may also apply.
10. Changes and contact
We may update this policy as Pulse, our providers, or legal requirements change. Material changes will be communicated through the service or by email where appropriate. The effective date above identifies the current version.
Privacy Officer: Idowu Ayeni
Pulse Appointments
3 St. SE, Calgary, Alberta T2G 0T9, Canada
For privacy or data-related requests, contact privacy@pulseappointments.com.
For account, billing, booking, or product support, contact support@pulseappointments.com.
If we cannot resolve a privacy concern, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, as applicable.