Privacy Policy
Effective 11 September 2026 · Last updated 11 September 2026
This policy explains what personal data Pullsy collects, why, and what you can do about it. Pullsy is operated by Acasa Labs (OPC) Private Limited, a company incorporated in India (“we”, “us”). It applies to getpullsy.com, the Pullsy dashboard and the Pullsy API.
1.Two roles, and why the difference matters
We handle two different kinds of data, under two different responsibilities. Nearly every question about your rights depends on which one is involved.
Your account data — we are the controller
The information you give us to have an account and a subscription: your name, email address, password, workspace and billing details. We decide how this is used, so we are the data controller (the “Data Fiduciary” under India’s DPDP Act).
Connected Instagram data — we are the processor
When you connect an Instagram Business or Creator account, we pull profile details, media and insights and store them for you. We do that on your instructions and use it only to provide the service. For that data you are the controller and we are the processor, so requests about it go to you first, not to us.
2.What we collect
Account information
- Name, email address and workspace name.
- A password, stored only as a one-way hash. We never store or see the password itself.
- Whether your email address has been verified, and your role in the workspace.
If you sign in with Google
We receive your name, email address, whether Google considers that address verified, and your profile picture URL. We do not receive your Google password, and we ask for no permission beyond your basic profile and email.
Billing information
Payments are processed by Razorpay. Card numbers and bank details go to Razorpay directly and never reach our servers. We keep your plan, billing currency, subscription status and the payment references Razorpay returns, which we need for invoicing and support.
Technical and security information
- Session records: an opaque session token, your IP address, your browser’s user agent, and when the session was created and expires.
- Security audit entries: actions such as sign-in, connecting an account or creating an API key, with the IP address they came from.
- API usage counts per day, used for rate limiting and plan enforcement.
- Server logs. Access tokens, API keys and passwords are redacted before anything is written.
Analytics
We use Google Analytics 4 to understand how the site is used. It runs only after you accept analytics cookies, and never before. Decline and no analytics cookies are set and no data goes to Google.
Instagram data you ask us to sync
Under your instructions we store, for each connected account: the Instagram account ID, username, display name, profile picture URL, account type, biography, website, follower and following counts, media items with their captions, media URLs, permalinks and timestamps, and daily snapshots of the insight metrics Meta exposes. Access tokens from Meta are encrypted before storage.
We use Meta’s official Instagram API with Instagram Login. We do not scrape, and we never ask for or accept Instagram passwords.
3.Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and run your account | You cannot use Pullsy without one | Performance of a contract |
| Sync and serve your Instagram data | It is the service you bought | Performance of a contract |
| Verification and password-reset email | Proving you own the address, and account recovery | Performance of a contract |
| Billing and invoicing | Collecting payment and meeting tax obligations | Contract; legal obligation |
| Rate limiting, audit logs, abuse prevention | Keeping accounts and the platform secure | Legitimate interests |
| Analytics | Understanding how the site is used | Consent |
| Service notices about outages or changes | You need to know when something affects you | Legitimate interests |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to train machine-learning models.
6.Where your data goes
We are based in India and our infrastructure runs in the United States. Personal data is therefore transferred outside India, the EEA and the UK.
For transfers out of the EEA and the UK we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures in section 8. For India, transfers are made to countries not restricted under the DPDP Act.
7.How long we keep it
| Data | Kept for |
|---|---|
| Account and workspace records | While your account is open, then 30 days after deletion |
| Connected Instagram data | Until you disconnect the account or delete your workspace |
| Sessions | 30 days, or until you sign out; expired records are pruned daily |
| Email verification and password-reset tokens | One hour, then pruned |
| Security audit entries | 24 months |
| Invoices and payment records | 8 years, as Indian tax law requires |
| Analytics | 14 months in Google Analytics |
Deleting your workspace deletes your users, connections, synced Instagram data, sync history and API keys. Records we must keep by law, such as invoices, are retained for the period above and nothing more.
8.How we protect it
- All traffic runs over TLS.
- Passwords are stored as one-way hashes; API keys are stored as SHA-256 hashes with only a short display prefix in clear.
- Instagram access tokens are encrypted at rest with rotatable keys.
- Every request is scoped to one workspace, so one customer cannot reach another’s data.
- Sign-in, sign-up and password-reset endpoints are rate limited, and cookie-based writes carry an origin check.
- The database role used by the sign-in service can reach only the authentication tables, not your synced data.
- Tokens, keys and passwords are redacted from logs.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the deadlines the law sets — 72 hours under GDPR, and without delay under the DPDP Act.
9.Your rights
Everyone
- Ask what we hold about you, and get a copy.
- Correct anything wrong or incomplete.
- Delete your account and the data tied to it.
- Withdraw consent for analytics, without affecting anything else.
If the GDPR applies to you (EEA and UK)
You also have the right to restrict or object to processing, the right to portability in a machine-readable format, and the right to complain to your supervisory authority. You do not have to come to us first, though we would rather you did.
If the DPDP Act applies to you (India)
You may nominate another person to exercise your rights if you die or become incapacitated, and you may raise a grievance with our grievance officer, named in section 12. If unresolved, you may approach the Data Protection Board of India.
If you are in California
You may request the specific pieces and categories of personal information we have collected, the purposes, and the categories of third parties involved; request deletion or correction; and not be discriminated against for asking. We do not sell or share personal information as the CCPA defines those terms, so there is nothing to opt out of.
Write to privacy@getpullsy.com. We answer within 30 days and will tell you if we need longer. We may ask you to confirm who you are before acting.
10.Children
Pullsy is a business tool and is not for children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, write to privacy@getpullsy.com and we will delete it.
11.Changes
When this policy changes we update the date at the top. If a change materially affects your rights we will email you at least 14 days beforehand, and where the law requires consent we will ask for it rather than assume it.
12.Contact us
Acasa Labs (OPC) Private Limited
- Privacy and data requests: privacy@getpullsy.com
- Legal notices: legal@getpullsy.com
- Everything else: support@getpullsy.com
Grievance Officer (DPDP Act, 2023): privacy@getpullsy.com.