PulseLink

PulseLink  /  Privacy Policy

Privacy Policy

Effective date: July 1, 2026  ·  Last updated: August 20, 2026  ·  App: PulseLink: Links & Affiliates (Shopify App Store)

Plain-language summaryPulseLink collects only the minimum data necessary to run a short link, affiliate tracking, and analytics service. We do not sell your data or use it for advertising. Merchant data and storefront visitor data are kept separate. You can request deletion of your data at any time.

This Privacy Policy explains how PulseLink ("we", "us", "our") collects, uses, and protects information when you install and use the PulseLink: Links & Affiliates Shopify app (the "App"). It also describes the data practices that apply to storefront visitors who click tracked short links on Shopify stores running PulseLink.

By installing the App, you (the Shopify merchant) agree to this Privacy Policy. By visiting a storefront that uses PulseLink, storefront visitors consent to the data practices described in the Cookies & Tracking section below.

1. Who We Are

PulseLink is a Shopify app developed and operated as an independent software product. For privacy inquiries, contact us at the email address in the Contact section of this policy. We act as a data processor on behalf of merchants (who are data controllers) with respect to storefront visitor data collected through the App.

2. Data We Collect

PulseLink collects data in four categories:

2.1 Merchant Data

When you install PulseLink, we receive from Shopify and store the following:

  • Your Shopify store domain and shop ID
  • Your Shopify access token (encrypted, used to make API calls on your behalf)
  • Short links you create (title, slug, destination URL, UTM parameters)
  • Affiliate profiles you add (first name, last name, email address, commission settings, internal notes)
  • Campaign configurations (name, description, type, status, goals)
  • QR Code Profiles (styling preferences — no personal data)
  • App configuration settings (custom domain, attribution model, cookie duration, commission qualification)
  • Subscription and billing status (plan name, activation date, status — billing amounts are managed by Shopify)

2.2 Storefront Visitor Data

When a visitor clicks a short link on a PulseLink-enabled store, we record the following non-personally-identifiable data:

Data pointPurposeStored as PII?
Click timestampAnalytics, conversion window calculationNo
Country (derived from IP)Geographic analyticsNo — IP is not stored
Device type (Desktop / Mobile / Tablet)Device breakdown analyticsNo
Browser & operating systemDevice analyticsNo
Referrer URL / traffic sourceSource attribution analyticsNo
Anonymous session ID (cookie)Affiliate attribution, conversion trackingNo — not linked to identity
Short link ID clickedLink-level analyticsNo
Add-to-cart, checkout, and order eventsFunnel analytics, commission attributionNo

IP addresses are used solely for country-level geo-resolution and are never stored in identifiable form in our database. We do not track visitors across different websites. We do not build individual visitor profiles.

2.3 Order Data

When a Shopify order is attributed to a tracked link (via webhook), we receive and store:

  • Shopify order ID and order number
  • Order financial totals (revenue, subtotal, shipping, tax, discount amounts)
  • The discount codes used on the order
  • Order fulfilment status and payment status
  • The country of the order and device used
  • The short link and affiliate attributed to the order

We do not store: customer names, customer email addresses, customer postal addresses, or payment card information from order data.

2.4 Affiliate Contact Data

Merchant-entered affiliate profiles include first name, last name, and email address. This data is entered by the merchant and used solely to:

  • Send the affiliate their portal access link
  • Identify the affiliate in the merchant's PulseLink dashboard
  • Authenticate the affiliate when they log into the portal

3. How We Use Data

We use data collected through PulseLink exclusively to:

  • Provide the service — create and redirect short links, track clicks, attribute orders to affiliates and campaigns, calculate commissions.
  • Display analytics — show merchants click rates, funnel metrics, conversion data, geographic breakdowns, and revenue attribution.
  • Manage affiliate programs — track commission earnings, manage payout records, send affiliate portal access links.
  • Operate the affiliate portal — authenticate affiliates and show them their own performance data.
  • Improve the service — analyse aggregate, anonymised usage patterns to improve app performance and features. We do not use individual merchant data for this purpose.
  • Customer support — diagnose issues and respond to support requests.

We do not use data for advertising, profiling, or any purpose unrelated to providing the PulseLink service.

4. Data Sharing & Third Parties

We do not sell, rent, or trade your data to any third party. Data is shared only in the following limited circumstances:

4.1 Shopify

PulseLink is built on and integrated with the Shopify platform. Shopify receives data according to their own Privacy Policy. PulseLink uses Shopify's APIs to read orders, manage discounts, create storefront pages, and install theme blocks. We operate within Shopify's Partner Data Processing Agreement.

4.2 Infrastructure Providers

PulseLink is hosted on cloud infrastructure providers (including but not limited to Amazon Web Services or similar providers). These providers process data on our behalf under contractual data processing agreements and do not have access to data for their own purposes. Data is encrypted at rest and in transit.

4.3 Email Service

If email notifications are enabled, affiliate email addresses are passed to a transactional email provider (such as Resend) solely to deliver the portal access email. The provider acts as a data processor and does not use email addresses for marketing or profiling.

4.4 Legal Obligations

We may disclose data if required by applicable law, regulation, court order, or governmental authority. We will notify affected merchants to the extent permitted by law before doing so.

4.5 Website Analytics (Google Analytics)

This website (pulselink.mgapps.dev) — including this Documentation and FAQ — uses Google Analytics 4 to understand how visitors find and use our marketing and support pages. This is separate from the affiliate tracking cookie described in Cookies & Tracking Technology, which operates only on merchant storefronts running the PulseLink app.

  • What it collects: Pages viewed, approximate location (city/country level), device and browser type, referral source, and general site interactions. Google Analytics does not collect names, email addresses, or Shopify store data.
  • Who processes it: Google LLC, acting as a data processor. Google's use of this data is governed by the Google Privacy Policy.
  • IP handling: Google Analytics 4 does not log or store full IP addresses.
  • Cookies used: Google Analytics sets first-party cookies on this website to distinguish visitors and sessions.
  • Opt-out: You can opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on, or by using your browser's cookie and tracking controls.
  • Scope: This applies only to pulselink.mgapps.dev. It does not track activity inside the PulseLink Shopify app itself or on merchant storefronts.

5. Data Retention

  • Active merchant data — Retained for as long as the PulseLink app is installed on your Shopify store.
  • After uninstall — Merchant data and associated click/order records are retained for 30 days after app uninstallation, then permanently deleted. This allows you to reinstall without losing data.
  • Upon request — Merchants may request immediate deletion of all their data by contacting us. See Merchant Rights.
  • Shopify GDPR webhooks — We respond to Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Customer redact requests remove any customer-associated data we hold within 30 days.
  • Aggregate analytics data — Click and conversion event data may be retained in anonymised, aggregated form beyond the 30-day deletion window for service analytics, as this data cannot be linked back to individuals or specific merchants.

6. Security

We implement industry-standard security measures including:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • All data at rest is encrypted using AES-256 or equivalent.
  • Shopify access tokens are stored encrypted and never logged.
  • Access to production systems is restricted to authorised personnel and protected by multi-factor authentication.
  • We undergo regular security reviews and promptly address identified vulnerabilities.

No method of transmission or storage is 100% secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

7. Cookies & Tracking Technology

PulseLink sets a first-party cookie in the browser of visitors who click a tracked short link on a PulseLink-enabled Shopify store. This cookie:

  • What it stores: An anonymous session ID, the ID of the affiliate link clicked, and a timestamp. It does not contain names, email addresses, or any personally identifiable information.
  • Why it is set: To attribute a future purchase on the same store to the correct affiliate link, within the cookie duration configured by the merchant (1–180 days).
  • Domain: The cookie is set on the Shopify store's domain (first-party) — not a PulseLink domain. It cannot be read by other websites.
  • Expiry: The cookie expires after the merchant-configured cookie duration (default 30 days).
  • Cross-site tracking: PulseLink does not use third-party cookies, cross-site tracking pixels, or fingerprinting techniques.

PulseLink also uses Shopify's Web Pixel infrastructure to record in-session events (add to cart, checkout, order) on the storefront. The Web Pixel is a sandboxed browser script managed by Shopify's platform — it cannot access or modify page content or other cookies.

This is separate from Google Analytics, which is used only on our marketing and documentation website — see Data Sharing & Third Parties.

Consent

If the Shopify store running PulseLink uses a cookie consent management tool or complies with GDPR/ePrivacy requirements, the store's own cookie policy and consent mechanism governs when the PulseLink tracking cookie is set. PulseLink respects the Shopify platform's consent framework. Merchants are responsible for ensuring their storefront cookie policy accurately discloses affiliate tracking cookies.

8. Merchant Rights

As a merchant (data controller) using PulseLink, you have the following rights with respect to your data:

  • Access — You can access all your data at any time within the PulseLink app (Links, Affiliates, Campaigns, Orders, Payouts, Settings). You can export all data via the Export buttons on each page.
  • Correction — You can update any data (link details, affiliate profiles, settings) directly within the app.
  • Deletion — You can delete individual records (links, affiliates, campaigns, orders) within the app. To delete all your data, uninstall the app and contact us to request immediate deletion rather than waiting the 30-day window.
  • Portability — Use the Export CSV buttons on each page to download all your data in a portable format.
  • Objection / Restriction — Contact us to object to or restrict specific data processing activities.

To exercise any of these rights, contact us at the address in the Contact section.

9. Storefront Visitor Rights (GDPR)

Storefront visitors who believe PulseLink has collected data about them (through clicking a tracked link on a Shopify store) may have rights under the GDPR or similar data protection laws.

Because PulseLink does not collect personally identifiable information from storefront visitors (no name, email, or IP address is stored), we are generally unable to identify and link click event data to a specific individual without additional information.

Visitors who have concerns about data collected by a specific Shopify store using PulseLink should first contact that store's merchant directly. For requests directed to PulseLink specifically, contact us at the address below. We will respond within 30 days.

10. Shopify Partner Data Processing Agreement

PulseLink operates as a Shopify Partner and is bound by Shopify's Partner Data Processing Addendum. This means:

  • We process merchant store data only as directed by the merchant and as necessary to provide the PulseLink service.
  • We respond to mandatory GDPR webhooks from Shopify: customers/data_request, customers/redact, and shop/redact.
  • Data transfers outside the EU/EEA are handled through appropriate safeguards (Standard Contractual Clauses where applicable).

11. Children's Privacy

PulseLink is a business-to-business service intended for Shopify merchants. It is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us immediately and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes that affect how we process your data, we will notify merchants via the PulseLink app or by email (if we have a contact email on file). Your continued use of PulseLink after the effective date of a revised policy constitutes your acceptance of the updated terms.

13. Contact

For privacy questions, data requests, or concerns about this policy, contact us:

PulseLink: Links & Affiliates
📧 Email: privacy@pulselink.app

We aim to respond to all privacy inquiries within 5 business days.

For technical support, go to Settings → Support → Contact Support from within the PulseLink app.