Legal
Privacy Policy
Effective 1 October 2026.
1. Who we are
Pricepulse is operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“Altix Code”, “we”, “us”). For the personal data described in Section 3 of this policy, Altix Code is the data controller. For the catalogue and price data described in Section 4, Altix Code acts as a processor on your behalf — see that section for the split.
Questions about this policy or your data: privacy@altixcode.com. Questions about our Terms of Service: legal@altixcode.com.
2. Scope, and the two kinds of data this service holds
Pricepulse is a B2B tool a merchant uses to compute the Article 6a reference price and the percentage a price reduction may lawfully be advertised at. Running it involves two genuinely different categories of data, and this policy treats them differently:
- Your account data — who you are, how we bill you, who else on your team has access, and what they did. We are the controller of this data. See Section 3.
- Your catalogue and price data — the products, SKUs and prices you track through the service. This is your business data, about your own shop; we process it only on your instructions, as your processor. See Section 4.
3. Account data — we are the controller
We collect, as controller:
- Identity and access: your name, email address, and a salted, hashed password (bcrypt) — we never store or can recover your plaintext password.
- Organisation data: your organisation’s name, a generated slug, currency, locale and other display settings, and the list of members and their roles (OWNER, ADMIN, or MEMBER), including pending invite email addresses before they are accepted.
- Billing data: your plan tier and subscription status. Card numbers and other payment instrument details are collected and held by Stripe, our payment processor (Section 5) — we never see or store your card number. We do receive your billing name, email, VAT/tax ID (for EU B2B invoicing) and billing address from Stripe, and the resulting invoice records.
- API credentials: a SHA-256 digest and a short preview of each API key you generate, never the plaintext key itself, which is shown once at creation and cannot be recovered by us or anyone else.
- Security and audit records: a log of membership and account-security events — invitations sent, roles changed, members removed, and organisation-deletion requests — each recording who performed the action, what it was, and when.
- Support and correspondence: anything you send us at the addresses in Section 1, and our replies.
- Basic technical data: IP address, user agent and timestamps on requests to our sign-in and API endpoints, kept briefly for abuse prevention and debugging.
Legal basis. Processing account data is necessary to perform our contract with you (Art. 6(1)(b) GDPR) — you cannot have an account, invite a team, or be billed without it — or is in our legitimate interest in keeping the service secure and working (Art. 6(1)(f)), such as the technical and audit logs above.
4. Catalogue and price data — you are the controller, we are your processor
The data this product exists to track — your variants’ external IDs, SKUs, titles, currencies, prices and the moment each price took effect — describes your own catalogue, not a third party’s website or business. We want to be precise about this, because it is not what every “price monitoring” product does:
- Pricepulse does not scrape, crawl, or independently monitor any website — ours, yours, or a competitor’s. Every price point in the system is put there by you: either sent directly to our API (authenticated with your API key) or delivered by your own Shopify store through a webhook you configure, signed with a secret generated in your dashboard and encrypted at rest (AES-256-GCM) on our side. No Shopify OAuth grant or access token is ever involved — we never connect to your Shopify admin or read anything from it beyond the webhook payloads your store chooses to send.
- We do not collect data about any third party’s products, prices, or website through this service, and have no mechanism to.
For this data, you — the organisation using Pricepulse— are the data controller, and Altix Code is your processor, acting only on your documented instructions (principally: “store the price points we send you, and compute the reference price and percentage from them when asked”). This split matters because catalogue data may itself contain personal data if you choose to put it there — for example a product title that names a person — in which case you remain responsible, as controller, for having a lawful basis to process it. We do not inspect catalogue content for this; it is treated as opaque business data.
A Data Processing Addendum covering the processor relationship for this data is available on request at legal@altixcode.com.
5. Sub-processors
We use a short, deliberately small list of sub-processors to run the service. Each is bound by its own data-protection terms with us:
- Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) — payment processing, invoicing, VAT/tax ID collection, and the customer billing portal. Stripe is PCI-DSS Level 1 certified. We never receive or store your full card number.
- Resend — delivery of transactional email (sign-up verification, password resets, team invitations, billing receipts).
- Cloudflare, Inc. (Turnstile) — bot and abuse prevention on our sign-in and sign-up forms. Processes your IP address and device/browser signals to verify you are not an automated script; we do not use Cloudflare for analytics or advertising.
- Hetzner Online GmbH(Germany) — infrastructure hosting. Our application and database run on servers we operate on Hetzner’s infrastructure in the EU; your data is not knowingly stored outside the EU/EEA by this sub-processor.
Invoices we issue you are additionally recorded in an in-house invoice ledger we operate ourselves — this is not a third-party sub-processor, it is a separate internal system under our own direct control, kept independent of your Pricepulse organisation for bookkeeping reasons described in Section 7.
Where a sub-processor is based outside the EEA or processes data there (Stripe, Inc. and Cloudflare, Inc. are both US entities), the transfer is safeguarded by that provider’s Standard Contractual Clauses or an equivalent GDPR Art. 46 transfer mechanism. We will update this section, and notify active customers by email, before adding a new sub-processor that materially changes this picture.
6. Cookies
Pricepulse sets only strictly necessary cookies:
- A signed session cookie that keeps you signed in (Auth.js).
- A CSRF-protection cookie paired with the session cookie.
- A short-lived Cloudflare Turnstile challenge cookie, set only on the sign-in and sign-up pages, to tell a human from a script.
We do not set analytics, advertising, or cross-site tracking cookies of any kind. Because every cookie we set is one the ePrivacy rules classify as strictly necessary for a service you have explicitly requested (keeping you signed in; protecting the signup form from abuse), no cookie consent banner is required — but we disclose them here regardless, and will add a consent mechanism if that ever changes.
7. Retention
- Account and organisation data is kept for as long as your organisation exists, and deleted immediately — not after a grace period — when an organisation owner deletes it (Section 8).
- Price historyis retained for up to your plan’s advertised history window (30 days on the Free tier, up to 10 years on the Scale tier), or deleted sooner if you delete your organisation.
- Invoices already issuedsurvive organisation deletion. They are kept in our separate invoicing ledger (Section 5) under Cyprus’s statutory bookkeeping retention period for accounting records (currently up to seven years), independent of anything that happens to your Pricepulse organisation.
- Security and audit log entries(Section 3) are, by design, not deleted when the organisation they describe is — the whole point of recording “deletion was requested” is defeated if deleting the organisation also deletes the record that it happened. We keep these entries for as long as reasonably needed for security recordkeeping and dispute resolution, and purge them on a routine schedule thereafter.
8. Deletion mechanics
Any organisation owner can permanently delete the organisation themselves, at any time, from Settings → Danger zone, by typing the organisation’s name to confirm. Deleting an organisation:
- Cancels any active subscription immediately (you are not billed again, and the cancellation happens before anything else — if it fails, the deletion is blocked entirely rather than leaving you still billed for a deleted organisation).
- Records that deletion was requested, in the audit trail described in Section 7, which survives the deletion.
- Permanently deletes the organisation and everything that belongs to it: memberships, API keys, connected shops, tracked variants and their entire price history, and pending invites. This step is immediate and cannot be undone.
Invoices already issued are unaffected, for the reason given in Section 7. If you need personal data about yourself erased outside of this self-service flow — for example, a team member who was removed from an organisation they no longer have access to — email privacy@altixcode.com.
9. Your rights
Under the GDPR, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have it erased; restrict or object to its processing; receive it in a portable format; and withdraw consent where consent is the basis for processing. To exercise any of these, email privacy@altixcode.com. We will respond within one month, as the GDPR requires.
You also have the right to lodge a complaint with a supervisory authority. As Altix Code Ltd is established in Cyprus, our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus — but you may also complain to the supervisory authority in your own EU member state of residence or work.
10. Security
Passwords are hashed with bcrypt and never stored or logged in plaintext. Shop webhook signing secrets are encrypted at rest with AES-256-GCM. API keys are stored only as a SHA-256 digest with a short, non-sensitive preview. Traffic to the service is encrypted in transit via TLS. Invite tokens and password-reset tokens are single-use, time-limited, and stored only as a salted hash of the token actually emailed to you.
11. Children
Pricepulse is a business tool for merchants and is not directed at, marketed to, or knowingly used by anyone under 18.
12. Changes to this policy
We will update the effective date above whenever this policy changes, and notify active customers by email of any change that materially affects how we handle their data.
13. Contact
Altix Code Ltd (Republic of Cyprus). Data protection and privacy requests: privacy@altixcode.com. Legal and Terms of Service questions: legal@altixcode.com. See also our Terms of Service.