Privacy Policy

Last updated: 25 September 2026. See also our terms, the data processing addendum and our cookie policy.

1. Who we are (data controller)

LocalPulse (localpulse.digitalizer.uk) is a product of Digitalizer Ltd, registered in England and Wales, company no. 15267581. Registered office: 2nd Floor, Unicorn House, Station Close, Potters Bar, Hertfordshire, EN6 1TL. Not VAT registered. ICO data protection registration ZC253283. Digitalizer Ltd is the data controller for the personal data described in this policy, except where noted in section 3.

If you have questions about this policy or your personal data, contact us at support@digitalizer.uk.

2. What we collect

Account data - agency name, email address, and password for the account owner and any team members the owner invites. Authentication is handled by Supabase; passwords are stored in hashed form and are never visible to us.

Signup attribution - when you create an agency we record the campaign parameters (utm_*), the referring site and the landing page of your first visit, if your browser still holds them, and the country your signup request came from. This tells us which marketing brought you here. It is stored once on your agency record and is not used to profile you.

Client business data entered by agencies - business name, address or location, website URL, keywords, and Google Business Profile identity for each tracked property, plus the contact name and email address an agency nominates to receive the monthly client report.

Scan and result data - rank check results, Google Maps grid scan results, AI search visibility results, website audit scores, the personalised fix plan, and client reports.

Report share links - when someone opens a client report share link we record the time and the browser identifier (user agent) of the visit against the property, so the agency can see whether its client opened the report. We do not store the viewer's IP address with the open record; it appears only in short-lived server logs. Share pages carry no LocalPulse analytics or advertising tags.

Demo requests - if you ask for a free white-label report on the sample or comparison pages we store your email address and the page you asked from as soon as you enter the email (so we can follow up if the form is not finished), then your agency website and the client business URL when you complete the form. We use it to produce the report and to follow up about LocalPulse.

Free Google Maps rank checker - the business name, address, Google Place ID and keyword you check, and the results. To enforce the daily limit we keep a counter keyed on your IP address for 26 hours. Finished checks are kept for 30 days so that the same business is not scanned twice in that time; they contain no visitor identity.

Google account connection - if an agency connects Google (section 10), the email address of the connected Google account and an encrypted refresh token.

Payment metadata - Stripe customer and subscription identifiers and invoice history. Payments are processed by Stripe; we never store card numbers.

Usage data - server logs, request metadata used for security and rate limiting, and (with consent) marketing-site analytics data.

3. Agencies and their clients' data

Where an agency enters data about its clients into LocalPulse, or nominates a client contact to receive reports, the agency is the controller of that data and Digitalizer Ltd is its processor. We process that data solely to provide the reporting service to the agency, on the terms of the data processing addendum in section 14 of our terms. Individuals whose data has been entered by an agency should direct requests to that agency in the first instance; we will assist as required and forward any request we receive to the agency within five business days.

4. Lawful bases (UK GDPR)

Contract - providing the service you signed up for (accounts, scans, reports, billing, transactional email), and taking the steps you ask for before a contract (a demo request or a free rank check).

Legitimate interests - securing the platform, preventing fraud and abuse, rate limiting, recording which marketing brought a signup, following up demo requests, and improving the service.

Consent - marketing and analytics cookies on the marketing site (see section 6).

Legal obligation - keeping payment records for tax and accounting purposes.

5. Subprocessors and third-party services

Supabase - Postgres database and authentication. Hosted in London, UK.

Vercel - web application hosting, London region.

DigitalOcean - hosts the scanning worker that runs the monthly scans, the website audits and the PDF rendering. Frankfurt, Germany (EU).

Stripe - payment processing. We store only Stripe customer and subscription IDs.

Resend - transactional email, including the monthly client report email.

Upstash - Redis, rate limiting and the free rank checker's job store.

Google - Analytics 4 (marketing site, consent only); Maps JavaScript API and Static Maps API (map imagery in the console and reports); Places API (business listing lookups and Business Profile checks); PageSpeed Insights API (each audited website URL is submitted to it for the website health scores); and the Business Profile API for agencies that connect Google (section 10). Map and business listing data is provided by Google and is subject to the Google Privacy Policy. Business listing details we hold from Google Places (address, map coordinates, listing name and website) are refreshed monthly by each property's scan and removed within 30 days when a property stops being tracked (it is archived, or the agency's subscription lapses); only the Google place identifier is kept so tracking can resume. Maps and listing data shown in the product carry Google's attribution.

Meta - Meta Pixel (marketing site, consent only).

DataForSEO - live Google results used for rank data at scan time.

OpenAI - AI search visibility checks (ChatGPT).

Anthropic - AI search visibility checks (Claude), business categorisation when a property is added, and automated analysis of crawled website data.

Perplexity - AI search visibility checks.

We share with these providers only what each needs to perform its function. We do not sell personal data. Fonts on our public pages are served from our own domain, with no font requests to Google. The map view in the agency console loads the Google Maps JavaScript API, which makes requests to Google (including for fonts).

6. Cookies and analytics

The marketing site uses Google Analytics 4 and the Meta Pixel. Neither loads until you click Accept on the cookie banner; the choice is stored in your browser and implemented with Google Consent Mode v2. Declining consent does not affect use of the product. Strictly necessary cookies (for example authentication session cookies in the agency console) do not require consent. Client report share pages carry none of these tags. For full details, see our cookie policy.

7. Retention, cancellation and account closure

Account data, client business data, scan history and reports - kept while your account is active. Data for archived properties is kept so you can restore them, except the Google business listing details described in section 5, which are removed 30 days after a property is archived or a subscription lapses and fetched again from Google when tracking resumes. Each user can change their own login email and password in the console (Settings, then Login).

After you cancel - cancel your subscription in the billing portal in your console (Settings, then Billing). Your account and its properties are kept for 60 days so you can reactivate or export reports, and the properties are archived after 60 days. The data is then kept until the account owner closes the account or asks us to delete it at support@digitalizer.uk (we confirm within 30 days).

Exporting and closing your account - the account owner can download all of the agency's data as a single file (Settings, then Export your data) and close the agency (Settings, then Close agency). Closing cancels billing straight away, stops scans, client report emails and share links, and removes access for every user of the agency. All of the agency's data, including its users' logins, is deleted automatically 60 days after closing, except payment records (below); until then we can reopen the account if the owner asks. You can also email support@digitalizer.uk from the account owner's address to close your account, request an export or have your data deleted sooner; we confirm within 30 days.

Demo requests and other leads - 12 months from the request.

Free rank checker - IP rate-limit counters expire after 26 hours. Finished checks contain the business and keyword only, no visitor identity, and are kept for 30 days (the limit Google sets for storing business listing data), during which the share link works and the same business is not scanned twice.

Report opens and email link clicks - 24 months.

Google account connection - until you disconnect Google or the account owner closes the agency (closing revokes our access and deletes the stored token straight away).

Payment records - 6 years, as required by UK tax and accounting law.

Backups - encrypted database backups are overwritten in the normal backup cycle; deleted data can persist in a backup until then.

Server logs - kept by our hosting providers for a short period for security and debugging.

8. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Contact support@digitalizer.uk to exercise any of these rights. We respond within one month, or tell you within that month if a complex request needs longer. You also have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk.

9. International transfers

Our database and web application are hosted in London, UK (Supabase and Vercel). The scanning worker that runs the monthly scans, audits and PDF rendering is hosted by DigitalOcean in Frankfurt, Germany, in the EU, which the UK treats as providing adequate protection. Some subprocessors listed in section 5 (for example Stripe, Resend, Google, Meta, DataForSEO, OpenAI, Anthropic, Perplexity, Upstash) may process data outside the UK, including in the United States. Where that happens, transfers are protected by appropriate safeguards such as the UK-US Data Bridge, the UK International Data Transfer Agreement or Addendum, or adequacy regulations.

10. Google user data (Connect Google)

LocalPulse offers a "Connect Google" feature that lets an agency authorise LocalPulse, via Google OAuth, to read data on the agency's behalf for the client locations it manages.

What we access. With the agency's authorisation, LocalPulse reads Google Business Profile Performance data: calls, website clicks, direction requests, impressions, and monthly search keyword impressions. Later phases will add read-only access to Google Search Console and Google Analytics 4 data.

Scopes requested.

openid and email - used only to identify which Google account is connected, so we can show it in the agency's settings. The email address of the connected account is stored with the connection and deleted when the agency disconnects.

https://www.googleapis.com/auth/business.manage - used in a read-only manner to list the locations the agency manages and to fetch Business Profile Performance metrics for those locations.

https://www.googleapis.com/auth/webmasters.readonly - future: read-only Google Search Console data.

https://www.googleapis.com/auth/analytics.readonly - future: read-only Google Analytics 4 data.

How we use it. Google user data is used only to render the agency's own client reports inside LocalPulse. It is never sold, never used for advertising, never used to build profiles unrelated to the reporting feature, and never shared with third parties beyond the subprocessors listed in section 5 that are necessary to operate the service (for example our database host). Humans do not read this data except with the agency's permission for support, for security purposes, or where required by law.

Limited Use. LocalPulse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and security. One OAuth grant is made per agency. Refresh tokens are stored encrypted. The connected account's email address and any cached Google metrics are stored in our London-hosted database alongside the related agency and property.

Disconnect and deletion. An agency can disconnect Google at any time from its settings, which deletes the stored token and the connected account email. Cached Google metrics are deleted when the related property's data is deleted, or with the rest of the agency's data 60 days after the agency account is closed (section 7). Agencies can also revoke LocalPulse's access from their Google Account at myaccount.google.com/permissions.

11. Changes to this policy

We will post updates to this page and, for material changes, notify agencies by email or an in-console notice.