Privacy Policy
Pulsar is a marketing-signal management service operated by SmartLabTec ("we", "us"). It lets businesses ("operators") capture browser events from their own websites and forward them to advertising destinations such as Meta Conversions API, Google Analytics, TikTok, and LinkedIn.
This policy explains what Pulsar collects, how it is stored, how long it lives, and how to delete it. It also clarifies which party is the data controller for which data.
1. Roles & Responsibilities
| Data | Controller | Pulsar's Role |
|---|---|---|
| End-user pixel events from operator websites | The operator (their business) | Data processor on the operator's behalf |
| Operator accounts (email + login) | Pulsar (us) | Data controller |
| Data forwarded to Meta / Google / etc. | Operator + destination jointly | Transit only — Pulsar does not retain a copy beyond delivery windows |
2. What Pulsar Collects
2a. From operator end-users
- Pixel events — page views, product views, add-to-cart, purchase, etc. Each event carries: event type, URL, timestamp, session id, referrer, UTM tags, and operator-supplied custom fields.
- Match keys — email and phone (when provided by the operator's checkout / form) are hashed with SHA-256 before storage. The raw values are never persisted by Pulsar.
- Cookies & identifiers — first-party cookies set by the Pulsar snippet (a session id and click-id storage). Meta-pixel cookies (
_fbp,_fbc) are read if present and forwarded. - Device data — user-agent, OS family, browser family. No precise geolocation, biometrics, or device fingerprints.
2b. From operators (account holders)
- Email address, hashed password.
- Encrypted Meta CAPI access token and ad-account id (encrypted with AES-256-GCM; never logged in plain text).
- Pixel configuration (domain, status, send-controls).
3. How Pulsar Uses It
- Deliver pixel events to operator-configured destinations (Meta CAPI, Google, TikTok, LinkedIn).
- Show the operator their own pixel activity, EMQ, delivery health, and conversion funnels in the cockpit.
- Build aggregated cohort + persona views for the operator. Personas are SHA-256-hashed identity clusters — Pulsar cannot reverse them back to a person.
- Operate the service (rate limiting, fraud detection, billing).
Pulsar does not sell, share, or use operator end-user data for advertising on its own behalf. It is a passthrough for the operator's marketing stack.
4. Sharing With Third Parties
Pulsar forwards events to advertising destinations only at the operator's explicit configuration. Each forwarding action is initiated by the operator, scoped to a single pixel, and uses the operator's own credentials. Pulsar's relationship to these destinations is that of a delivery agent, not a data broker.
- Meta Conversions API — server-to-server event delivery on the operator's behalf using the operator's CAPI access token.
- Google Analytics 4, TikTok Events API, LinkedIn Conversions API — same model, per operator.
- Infrastructure — Pulsar runs on Hetzner Cloud (Germany) with MongoDB and Redis. We do not engage subprocessors outside the EU/EEA without a Standard Contractual Clauses arrangement.
5. Retention
| Data class | Retention |
|---|---|
| Raw pixel events | 90 days, then automatically deleted |
| Aggregated metrics (per-day rollups) | 13 months |
| Hashed match keys (personas) | 180 days from last activity |
| Delivery records (to destinations) | 30 days |
| Operator account records | For the life of the account; deleted within 30 days of account closure |
| Encrypted credentials (CAPI tokens) | Until rotated or account closed |
6. Your Rights
If you are an end-user whose data was captured by an operator's Pulsar-instrumented website, contact that operator directly — they are the data controller for your events. We will support their deletion / access requests.
If you are an operator (account holder):
- Access — request a copy of your account + pixel data.
- Erasure — delete your account and all associated event/persona data.
- Portability — export your data in JSON / CSV.
- Object — disable any specific destination at any time from the cockpit.
To exercise these rights, email privacy@smartlabtec.com (or the address listed below).
7. Security
- TLS 1.2+ on all transport. Self-managed Let's Encrypt certificate auto-renewed by Caddy.
- AES-256-GCM encryption-at-rest for all CAPI tokens and other operator secrets.
- Match keys (email, phone) hashed with SHA-256 before persistence. Raw values discarded.
- Role-based access — each operator only sees their own account's pixels and events. Account isolation is enforced at the database query layer.
- Bcrypt password hashing for operator credentials.
- Bot traffic filtered out of all dashboards (Meta crawlers, Google bots, etc.).
8. Cookies set by the Pulsar snippet
_pulsar_session— first-party, http-only, session-scoped session id. 30-minute idle expiry._pulsar_clickid— first-party, captures Meta / Google / TikTok click IDs from URL params for attribution. 90 days.- The Pulsar snippet does not set any third-party cookies. It reads
_fbp/_fbcif Meta's pixel is also on the page, but does not set them.
9. International Data Transfers
Pulsar's primary processing is in Germany (EU/EEA). When the operator configures a destination outside the EU (e.g. Meta in the US, TikTok in Singapore), event data is transmitted there under the operator's own data-protection agreement with that destination, plus Pulsar's transit-only handling.
10. Children
Pulsar is a B2B tool for marketing operators. We do not knowingly collect data from anyone under 16. Operators are responsible for honoring children's privacy laws (COPPA, GDPR-K, etc.) for their own end-users.
11. Changes to This Policy
Material changes are announced in-app to operators and posted here with a new "Last updated" date at the top. Continued use of Pulsar after the effective date constitutes acceptance.
12. Contact
SmartLabTec
Privacy contact: privacy@smartlabtec.com
General: info@smartlabtec.com
Postal: SmartLabTec, Egypt