pullsy

Privacy Policy

Effective 11 September 2026 · Last updated 11 September 2026

This policy explains what personal data Pullsy collects, why, and what you can do about it. Pullsy is operated by Acasa Labs (OPC) Private Limited, a company incorporated in India (“we”, “us”). It applies to getpullsy.com, the Pullsy dashboard and the Pullsy API.

1.Two roles, and why the difference matters

We handle two different kinds of data, under two different responsibilities. Nearly every question about your rights depends on which one is involved.

Your account data — we are the controller

The information you give us to have an account and a subscription: your name, email address, password, workspace and billing details. We decide how this is used, so we are the data controller (the “Data Fiduciary” under India’s DPDP Act).

Connected Instagram data — we are the processor

When you connect an Instagram Business or Creator account, we pull profile details, media and insights and store them for you. We do that on your instructions and use it only to provide the service. For that data you are the controller and we are the processor, so requests about it go to you first, not to us.

If you are an Instagram user whose data appears in Pullsy because a business connected an account, contact that business. Write to privacy@getpullsy.com and we will help route the request, but we cannot act on their data without them.

2.What we collect

Account information

  • Name, email address and workspace name.
  • A password, stored only as a one-way hash. We never store or see the password itself.
  • Whether your email address has been verified, and your role in the workspace.

If you sign in with Google

We receive your name, email address, whether Google considers that address verified, and your profile picture URL. We do not receive your Google password, and we ask for no permission beyond your basic profile and email.

Billing information

Payments are processed by Razorpay. Card numbers and bank details go to Razorpay directly and never reach our servers. We keep your plan, billing currency, subscription status and the payment references Razorpay returns, which we need for invoicing and support.

Technical and security information

  • Session records: an opaque session token, your IP address, your browser’s user agent, and when the session was created and expires.
  • Security audit entries: actions such as sign-in, connecting an account or creating an API key, with the IP address they came from.
  • API usage counts per day, used for rate limiting and plan enforcement.
  • Server logs. Access tokens, API keys and passwords are redacted before anything is written.

Analytics

We use Google Analytics 4 to understand how the site is used. It runs only after you accept analytics cookies, and never before. Decline and no analytics cookies are set and no data goes to Google.

Instagram data you ask us to sync

Under your instructions we store, for each connected account: the Instagram account ID, username, display name, profile picture URL, account type, biography, website, follower and following counts, media items with their captions, media URLs, permalinks and timestamps, and daily snapshots of the insight metrics Meta exposes. Access tokens from Meta are encrypted before storage.

We use Meta’s official Instagram API with Instagram Login. We do not scrape, and we never ask for or accept Instagram passwords.

4.Cookies

Strictly necessary

A single session cookie keeps you signed in. It is HttpOnly, restricted to our own site, and cannot be read by JavaScript. Without it the dashboard cannot work, so it is set without asking — this is what “strictly necessary” means in law.

Analytics

Google Analytics 4 cookies are set only after you accept them in the cookie banner. Choose “Cookie preferences” in the footer of any page to change your mind. If you withdraw consent we stop setting them and delete the ones already on your device.

The analytics cookies are Google’s _ga and _ga_<id>, which distinguish one browser from another and expire after two years. We use no advertising or cross-site tracking cookies at all, and we have turned off Google’s advertising features and enabled IP anonymisation.

5.Who we share it with

We share personal data only with the providers below, only as far as each needs to do its job, and under contract. They are our sub-processors.

ProviderWhat it doesWhere
NeonManaged PostgreSQL: all application dataUnited States (us-east-2)
RailwayAPI, sync worker, scheduler and Redis queueUnited States (us-east4)
CloudflareDashboard hosting, CDN, DNS and edge protectionGlobal edge network
Meta PlatformsSource of Instagram data you ask us to syncUnited States / global
RazorpaySubscription payments and invoicingIndia
ResendTransactional email (verification, password reset)United States
GoogleGoogle sign-in, and Google Analytics 4 where you consentUnited States / global

We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever party to a merger or acquisition, personal data may transfer with the business; we will say so before it does, and this policy continues to apply until replaced.

6.Where your data goes

We are based in India and our infrastructure runs in the United States. Personal data is therefore transferred outside India, the EEA and the UK.

For transfers out of the EEA and the UK we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures in section 8. For India, transfers are made to countries not restricted under the DPDP Act.

7.How long we keep it

DataKept for
Account and workspace recordsWhile your account is open, then 30 days after deletion
Connected Instagram dataUntil you disconnect the account or delete your workspace
Sessions30 days, or until you sign out; expired records are pruned daily
Email verification and password-reset tokensOne hour, then pruned
Security audit entries24 months
Invoices and payment records8 years, as Indian tax law requires
Analytics14 months in Google Analytics

Deleting your workspace deletes your users, connections, synced Instagram data, sync history and API keys. Records we must keep by law, such as invoices, are retained for the period above and nothing more.

8.How we protect it

  • All traffic runs over TLS.
  • Passwords are stored as one-way hashes; API keys are stored as SHA-256 hashes with only a short display prefix in clear.
  • Instagram access tokens are encrypted at rest with rotatable keys.
  • Every request is scoped to one workspace, so one customer cannot reach another’s data.
  • Sign-in, sign-up and password-reset endpoints are rate limited, and cookie-based writes carry an origin check.
  • The database role used by the sign-in service can reach only the authentication tables, not your synced data.
  • Tokens, keys and passwords are redacted from logs.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the deadlines the law sets — 72 hours under GDPR, and without delay under the DPDP Act.

9.Your rights

Everyone

  • Ask what we hold about you, and get a copy.
  • Correct anything wrong or incomplete.
  • Delete your account and the data tied to it.
  • Withdraw consent for analytics, without affecting anything else.

If the GDPR applies to you (EEA and UK)

You also have the right to restrict or object to processing, the right to portability in a machine-readable format, and the right to complain to your supervisory authority. You do not have to come to us first, though we would rather you did.

If the DPDP Act applies to you (India)

You may nominate another person to exercise your rights if you die or become incapacitated, and you may raise a grievance with our grievance officer, named in section 12. If unresolved, you may approach the Data Protection Board of India.

If you are in California

You may request the specific pieces and categories of personal information we have collected, the purposes, and the categories of third parties involved; request deletion or correction; and not be discriminated against for asking. We do not sell or share personal information as the CCPA defines those terms, so there is nothing to opt out of.

Write to privacy@getpullsy.com. We answer within 30 days and will tell you if we need longer. We may ask you to confirm who you are before acting.

10.Children

Pullsy is a business tool and is not for children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, write to privacy@getpullsy.com and we will delete it.

11.Changes

When this policy changes we update the date at the top. If a change materially affects your rights we will email you at least 14 days beforehand, and where the law requires consent we will ask for it rather than assume it.

12.Contact us

Acasa Labs (OPC) Private Limited

Grievance Officer (DPDP Act, 2023): privacy@getpullsy.com.