Privacy Policy

Last Updated: January 18, 2026 (v1.1)

ArkPulse, LLC ("ArkPulse," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and safeguard your information when you use the ArkPulse platform ("Service").

By using our Service, you consent to this Privacy Policy.

1. Information We Collect

We collect information in the following categories:

1.1 Information You Provide Directly

When you create an account, we collect:

  • Business name and verified Google Business Profile ID
  • Primary contact email address
  • Business category/industry
  • Stripe customer ID and payment method tokens
  • Google OAuth access/refresh tokens
  • Review approval preferences (auto/manual approval mode)

We NEVER store:

  • Full credit card numbers or CVV
  • Google passwords
  • SMS one-time codes

1.2 Automatically Collected Information

When you use ArkPulse, we automatically collect:

  • IP address and geolocation
  • Browser/device information
  • Login timestamps
  • Dashboard usage patterns
  • Feature access logs
  • Error reports

1.3 Google Business Profile Data

Through Google OAuth integration, we access:

  • Business locations you own/manage
  • Review data (text, rating, date, reviewer info)
  • Reply permissions/status

This data is cached temporarily (24-48 hours) for nightly processing only.

1.4 Payment Information

Stripe handles all payment processing. ArkPulse only receives:

  • Last 4 digits of card
  • Expiration date
  • Payment success/failure status
  • Subscription status

2. How We Use Your Information

We use collected information to:

  • Connect to your verified Google Business Profile
  • Generate AI replies using your custom prompts
  • Post approved replies nightly via Google API
  • Process Stripe subscriptions
  • Send reply summary email notifications
  • Send review approval notification emails (when manual approval is enabled)
  • Monitor system security and abuse
  • Provide technical support

3. How We Store and Protect Information

ArkPulse uses enterprise-grade security:

3.1 Encryption Everywhere

  • Google OAuth tokens: AWS Secrets Manager (KMS encrypted)
  • Database: PostgreSQL with TLS + at-rest encryption
  • Data transmission: HTTPS/TLS 1.3 only
  • Static assets: AWS CloudFront + ACM certificates

3.2 Access Controls

  • Zero-knowledge passwords: Hashed with Argon2id
  • Role-based access: Staff-only via AWS IAM roles
  • Audit logging: All admin access tracked
  • 2FA required: Email or SMS for all users

3.3 Data Minimization

  • Review data deleted after 7 days (unless required for disputes)
  • No unnecessary PII collected
  • Temporary processing only

4. How We Share Information

ArkPulse NEVER sells your data.

We share only what's required with:

4.1 Required Service Providers

Provider Purpose Data Shared
Stripe Payments Payment tokens only
Google Review posting OAuth tokens
AWS Infrastructure Encrypted data only
SendGrid/AWS SES Email alerts & approval notifications Email + reply summaries + approval requests
AI Providers Reply generation Review text only (no PII)

4.2 Legal Disclosures

We only disclose if required by:

  • Subpoena/court order
  • Law enforcement with valid warrant
  • Google Business Profile violations
  • Stripe payment disputes

5. Cookies & Tracking

ArkPulse uses essential cookies only:

  • Session authentication
  • CSRF protection
  • Feature flags

No advertising cookies. No cross-site tracking.

6. Email & Notifications

You consent to receive:

  • Account verification codes
  • Reply summary emails (nightly)
  • Review approval request emails (when manual approval is enabled)
  • Billing receipts
  • Service alerts

Unsubscribe anytime from non-essential emails.

7. Your Privacy Rights (Texas + CCPA)

You can:

  • Access your data: support@arkpulse.com
  • Delete your account (7-day hold for billing)
  • Correct inaccurate info
  • Opt-out of analytics

Response within 45 days (legal maximum).

8. Children's Privacy

COPPA compliant: No users under 13. Accounts discovered will be terminated.

9. International Data Transfers

US-only servers (AWS US-East/US-West). Non-US users consent to US data processing.

10. Data Retention

Data Type Retention
Google OAuth tokens Account lifetime
Review data 7 days post-processing
Payment records 7 years (IRS requirement)
Login logs 90 days
Account data Until deletion request

11. Data Security Incident Response

In case of breach:

  1. Notify affected users within 72 hours (if PII compromised)
  2. Texas AG notification within 30 days
  3. Fix root cause before resuming service

12. Changes to This Policy

Posted updates take effect immediately.
Material changes emailed to all users.

13. Governing Law

Texas law applies. Disputes in Dallas County courts.

14. Contact Information

ArkPulse, LLC
Texas, USA
Email: support@arkpulse.com

Website: Contact Form