Privacy Policy

Last updated: 4 July 2026

1. Who we are (data controller)

LocalPulse (localpulse.digitalizer.uk) is a product of Digitalizer Ltd, a company registered in England and Wales (Company No. 15267581). Digitalizer Ltd is the data controller for the personal data described in this policy, except where noted in section 3.

If you have questions about this policy or your personal data, contact us at support@digitalizer.uk.

2. What we collect

Account data - agency name, email address, and password. Authentication is handled by Supabase; passwords are stored in hashed form and are never visible to us.

Client business data entered by agencies - business name, address or location, website URL, keywords, and Google Business Profile identity for each tracked property.

Scan and result data - rank check results, Google Maps grid scan results, AI search visibility results, website audit scores, generated fix plans, and client reports.

Payment metadata - Stripe customer and subscription identifiers and invoice history. Payments are processed by Stripe; we never store card numbers.

Usage data - server logs, request metadata used for security and rate limiting, and (with consent) marketing-site analytics data.

3. Agencies and their clients' data

Where an agency enters data about its clients into LocalPulse, the agency is responsible for having the authority to do so. We process that data solely to provide the reporting service to the agency. Individuals whose data has been entered by an agency should direct requests to that agency in the first instance; we will assist as required.

4. Lawful bases (UK GDPR)

Contract - providing the service you signed up for (accounts, scans, reports, billing, transactional email).

Legitimate interests - securing the platform, preventing fraud and abuse, rate limiting, and improving the service.

Consent - marketing and analytics cookies on the marketing site (see section 6).

5. Subprocessors and third-party services

Supabase - Postgres database and authentication. Hosted in London, UK.

Vercel - application hosting, London region.

Stripe - payment processing. We store only Stripe customer and subscription IDs.

Resend - transactional email.

Upstash - Redis, rate limiting.

Google - Analytics 4 (marketing site, consent only), Static Maps API (map imagery), and Places API (Business Profile checks).

Meta - Meta Pixel (marketing site, consent only).

DataForSEO - live Google results used for rank data at scan time.

OpenAI - AI search visibility checks (ChatGPT).

Anthropic - AI search visibility checks (Claude).

Perplexity - AI search visibility checks.

We share with these providers only what each needs to perform its function. We do not sell personal data.

6. Cookies and analytics

The marketing site uses Google Analytics 4 and the Meta Pixel. These load only after you give cookie consent, implemented with Google Consent Mode v2. Declining consent does not affect use of the product. Strictly necessary cookies (for example authentication session cookies in the agency console) do not require consent. For full details, see our cookie policy.

7. Retention

Account data - retained until you delete your account.

Scan history and reports - retained while the related property is active. Data for deleted properties and deleted agency accounts is removed.

Payment metadata - retained as required for tax and accounting obligations.

8. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Contact support@digitalizer.uk to exercise any of these rights. You also have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk.

9. International transfers

Our primary data storage is in London, UK (Supabase) with hosting in the Vercel London region. Some subprocessors listed in section 5 (for example Stripe, Resend, Google, Meta, DataForSEO, OpenAI, Anthropic, Perplexity, Upstash) may process data outside the UK, including in the United States. Where that happens, transfers are protected by appropriate safeguards such as the UK-US Data Bridge, the UK International Data Transfer Agreement or Addendum, or adequacy regulations.

10. Google user data (planned Connect Google feature)

LocalPulse offers a "Connect Google" feature that lets an agency authorise LocalPulse, via Google OAuth, to read data on the agency's behalf for the client locations it manages.

What we access. With the agency's authorisation, LocalPulse reads Google Business Profile Performance data: calls, website clicks, direction requests, impressions, and monthly search keyword impressions. Later phases will add read-only access to Google Search Console and Google Analytics 4 data.

Scopes requested.

https://www.googleapis.com/auth/business.manage - used in a read-only manner to list the locations the agency manages and to fetch Business Profile Performance metrics for those locations.

https://www.googleapis.com/auth/webmasters.readonly - future: read-only Google Search Console data.

https://www.googleapis.com/auth/analytics.readonly - future: read-only Google Analytics 4 data.

How we use it. Google user data is used only to render the agency's own client reports inside LocalPulse. It is never sold, never used for advertising, never used to build profiles unrelated to the reporting feature, and never shared with third parties beyond the subprocessors listed in section 5 that are necessary to operate the service (for example our database host). Humans do not read this data except with the agency's permission for support, for security purposes, or where required by law.

Limited Use. LocalPulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and security. One OAuth grant is made per agency. Refresh tokens are stored encrypted. Cached Google metrics are stored in our London-hosted database alongside the related property.

Disconnect and deletion. An agency can disconnect Google at any time from its settings, which deletes the stored token. Cached Google metrics are deleted when the related property is deleted or when the agency account is deleted. Agencies can also revoke LocalPulse's access from their Google Account at myaccount.google.com/permissions.

11. Changes to this policy

We will post updates to this page and, for material changes, notify agencies by email or an in-console notice.