Legal
Privacy Policy
Last updated: September 19, 2026
Operated by Pulsar Digital / PulsarCLT. Questions: support@transitcrm.com.
This Privacy Policy describes how Pulsar Digital (also known as PulsarCLT) (“Pulsar,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with Transit CRM (“Transit,” the “Service”).
Transit is offered through two related surfaces:
- Marketing site: transitcrm.com — product information, marketing content, and trial / interest signup flows.
- Application: app.transitcrm.com — the authenticated CRM product and account administration.
By using the Service, you agree to this Privacy Policy. If you do not agree, do not use Transit.
Who we are
Transit CRM is operated by Pulsar Digital / PulsarCLT.
Contact for privacy matters: support@transitcrm.com
Pulsar is a highly ethical software company. We build tools that businesses rely on every day. We price our products affordably because we believe overcharging for necessities is wrong. That ethos also guides how we treat customer data: with restraint, transparency, and respect.
Our commitments (read these first)
We want the following commitments to be unmistakable:
- We do not sell customer data. Pulsar does not and will never sell customer data.
- No advertising or data-brokerage sharing. Pulsar does not sell, rent, or share personal data for advertising, marketing networks, or data brokerage — ever, whether or not money changes hands, and regardless of any “monetary value” or similar legal framing.
- Card data never touches our servers. When you pay with a card, Transit uses Stripe-hosted Checkout only. We do not collect, store, process, or transmit raw card numbers (PAN), CVV/CVC, or full track data on Pulsar systems. This is intentional for a PCI SAQ A path.
- Your CRM data stays in your tenant. Customer CRM data is scoped to that customer’s account (tenant isolation). We design the product so one customer’s operational CRM records are not mixed into another customer’s workspace.
- Ethics over extraction. We do not run a business model that depends on monetizing your customers’ personal information.
These commitments apply to Transit CRM as operated by Pulsar Digital / PulsarCLT. If a future product change would conflict with them, we will update this Policy and communicate material changes — we will not quietly convert your data into an advertising or brokerage asset.
Scope of this Policy
This Policy applies to personal information processed in connection with:
- the marketing site at transitcrm.com;
- the application at app.transitcrm.com;
- trial signup and email verification flows;
- billing and subscription administration for Transit;
- support communications with us; and
- related operational emails (for example, verification codes or account notices).
This Policy does not control how your organization uses Transit to process your end customers’, leads’, or contacts’ data. When you use Transit as a customer, you are responsible for that processing under your own privacy notices, contracts, and applicable law. Pulsar provides the software platform; you control the content you put into your CRM account (subject to our terms and acceptable-use rules).
We do not claim that Pulsar is “SOC 2 certified,” “ISO certified,” or similarly audited in this Policy. We take security and privacy seriously and describe our practices honestly below; certification status, if any, will be stated only when true and current.
Information we collect
The information we collect depends on how you interact with Transit.
Account and trial information
When you start a trial or create an account, we may collect:
- name;
- email address;
- company / organization name;
- password (hashed on the application; we do not store plaintext passwords);
- account identifiers (such as customer / account numbers used for tenancy); and
- email one-time passcode (OTP) verification status and related timestamps.
Trial signup may occur via the marketing site with verification and account creation completed in coordination with the application host.
Billing and subscription information
For paid plans, we may collect:
- billing contact details (name, email, company);
- plan, seat, and subscription status;
- invoices, receipts, and payment history metadata; and
- Stripe customer / subscription identifiers needed to administer billing.
Card payments: Payment card details are entered on Stripe’s hosted Checkout. Pulsar does not receive raw PAN or CVV. We may receive limited payment outcome metadata from Stripe (for example, that a payment succeeded, the last four digits if Stripe provides them, brand, and billing status) solely to run the subscription.
CRM content you and your users enter
Within a tenant account, users may enter business CRM data such as companies, contacts, deals, notes, forms, emails, files, and similar records. That content is your customer data. We process it to provide the Service to your account and as otherwise described in this Policy and our agreements with you.
Usage, device, and log information
We may automatically collect:
- IP address and approximate location derived from IP;
- browser type, device type, and operating system;
- pages or screens viewed, feature usage, and referral URLs;
- timestamps, request IDs, and diagnostic logs; and
- cookies or similar technologies (see Cookies and similar technologies).
Communications
If you email us or contact support, we collect the content of your message and any contact details you provide.
Information we do not seek from children
Transit is built for business use. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies). See Children’s privacy.
How we use information
We use personal information to:
- provide, operate, maintain, and improve Transit;
- create and administer accounts and tenant workspaces;
- verify email addresses (including OTP verification) and secure account access;
- process subscriptions and billing via Stripe;
- provide customer support and respond to inquiries;
- send transactional messages (verification codes, security alerts, billing notices, service updates);
- monitor reliability, prevent abuse, detect fraud, and protect the Service;
- enforce our terms and policies;
- comply with law and respond to lawful requests; and
- understand product usage at an aggregate or operational level so we can fix bugs and improve features.
We may send product or marketing emails about Transit where permitted. You can unsubscribe from non-essential marketing emails using the link in those messages or by contacting support@transitcrm.com. Transactional and security-related messages may still be sent because they are part of operating the account.
We do not use personal data to build advertising profiles for sale, and we do not share personal data with advertisers or data brokers.
Legal bases and practical reasons for processing (US / general)
Privacy laws vary by jurisdiction. Where a “legal basis” concept applies (for example, under GDPR-style frameworks for people in those regions), we typically rely on one or more of the following, as appropriate:
- Contract / performance of a contract — to provide the Service you request (account creation, CRM features, billing administration).
- Legitimate interests — to secure and improve the Service, prevent abuse, understand reliability, and communicate about the product in ways that do not override your rights.
- Consent — where we ask for it (for example, certain cookies or optional marketing), which you may withdraw where applicable.
- Legal obligation — where we must retain or disclose information to comply with law, tax, accounting, or lawful process.
For U.S. state privacy laws that define “sale” or “sharing” of personal information for cross-context behavioral advertising, Pulsar does not sell or share personal information for those purposes. We do not knowingly engage in data brokerage.
If you believe local law gives you additional rights, contact us and we will work with you in good faith.
Tenant isolation and roles
Transit is a multi-tenant SaaS product. Each customer’s CRM data is scoped to their account. Authorization and data access paths are designed so tenant-owned records are queried and displayed only within the correct account context.
Within an account, administrators and users you authorize can access that tenant’s CRM content according to permissions you configure. Pulsar personnel may access tenant data only as needed to operate, secure, or support the Service (for example, troubleshooting a ticket you open), subject to internal access controls and our ethical commitments above.
You are responsible for managing user access inside your tenant and for the lawfulness of the data you store.
Dual-host architecture (marketing vs app)
- transitcrm.com is the public marketing / informational site and may host trial or intake entry points.
- app.transitcrm.com is the CRM application where accounts are authenticated and tenant data is used in the product.
Information may move between these hosts as needed to complete signup, verification, and login (for example, collecting trial details on the marketing site and completing verification or account setup on the app host). Both hosts are operated as part of the Transit service offering described in this Policy.
Cookies and similar technologies
We use cookies and similar technologies to:
- keep you signed in and maintain session security;
- remember preferences;
- understand basic traffic and performance; and
- protect against abuse.
Essential cookies are required for the Service to function. Analytics or preference cookies, if used, are intended to help us operate and improve Transit — not to sell your identity to advertisers.
You can control cookies through your browser settings. Blocking essential cookies may prevent login or core features from working.
We do not use your personal data to participate in third-party advertising networks or data-broker exchanges.
How we share information (and what we refuse to do)
We share information only in limited cases
We may disclose personal information to:
- Service providers (subprocessors) that help us run Transit (hosting, email delivery, payment processing, error monitoring, and similar infrastructure), under contractual obligations to use the data only to provide services to us;
- Professional advisors (legal, accounting) under confidentiality obligations when needed;
- Authorities when required by law, regulation, legal process, or to protect rights, safety, and security; and
- A successor entity in connection with a merger, acquisition, or asset transfer, in which case we will continue to require protections consistent with this Policy, including our no-sale / no advertising-brokerage commitments for the personal data involved, or we will give you notice and choices required by law.
What we will not do
- We will not sell customer data.
- We will not sell, rent, or share personal data for advertising or data brokerage.
- We will not license your CRM contact lists to third parties for their marketing.
- We will not put raw card numbers on Pulsar servers.
If a subprocessor processes data for us, they do so to help deliver Transit — not to turn your customers into an ad audience for Pulsar’s profit.
Subprocessors and third-party services
We use reputable third-party providers to operate Transit. Categories include:
| Category | Examples / notes | | --- | --- | | Payments | Stripe — hosted Checkout and subscription billing. Card data is handled by Stripe under Stripe’s terms and privacy notice. | | Email delivery | Transactional and verification email (for example, providers such as Resend, or equivalent). Used for OTP codes, notices, and support-related mail. | | Hosting / infrastructure | Cloud or server hosting where the application and databases run. | | Other operations tools | May include monitoring, logging, or support tooling as needed to keep the Service reliable. |
We keep this list intentionally high-level where provider choices may change. We select providers we believe are appropriate for security and confidentiality. Payment card data specifically remains on the Stripe-hosted path described above.
Third-party sites linked from Transit have their own privacy practices. This Policy does not cover those sites.
Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including:
- as long as your account remains active;
- for a reasonable period afterward for backups, dispute resolution, security, and legal compliance;
- for billing and tax records as required by law; and
- for support correspondence as needed to complete your request and maintain an accurate history of the issue.
When CRM content is deleted by you (or your account is closed), we take steps to remove or de-identify tenant data from active systems within a commercially reasonable time, subject to residual copies in encrypted backups that rotate out on a normal backup schedule, and subject to legal holds where applicable.
If you want deletion of a specific account or personal data we hold about you as an individual (for example, a trial registrant), contact support@transitcrm.com.
Your rights and choices
Depending on where you live and your relationship with Pulsar, you may have rights to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete personal information, subject to legal exceptions;
- Export / port a copy of certain information in a usable format;
- Object to or restrict certain processing, where applicable;
- Withdraw consent where processing is based on consent; and
- Opt out of marketing emails (transactional messages may continue).
How to exercise rights: email support@transitcrm.com with the subject line “Privacy Request” and enough detail for us to verify your identity and locate the relevant records. We may need to confirm you control the email address or account associated with the request.
Customer / tenant data: If you are an end contact stored inside a Transit customer’s CRM, please contact that customer first. Pulsar generally processes that content on behalf of the customer account. We can help route or evaluate requests when appropriate, but the customer often is the right first point of contact.
We will not discriminate against you for exercising privacy rights recognized by applicable law.
Security
We implement technical and organizational measures designed to protect personal information, including:
- password hashing for credentials stored by the application;
- HTTPS / TLS for data in transit on our sites and app;
- tenant-scoped data access patterns in the product;
- access controls for operational systems; and
- Stripe-hosted Checkout so raw card data is not processed on Pulsar servers.
No method of transmission or storage is 100% secure. We work to protect your information, but we cannot guarantee absolute security. Please use strong unique passwords and protect your account credentials.
We do not claim SOC 2, ISO 27001, or similar certifications in this Policy unless and until such a statement is accurate. Security maturity is an ongoing practice, not a slogan.
International transfers
Pulsar is based in the United States. If you access Transit from outside the United States, your information may be processed in the United States and other countries where we or our subprocessors operate. Those countries may have privacy laws different from those in your jurisdiction.
Where required, we use appropriate contractual and organizational safeguards with providers. This section is intentionally high-level; it is not a claim that Pulsar maintains an EU “data controller establishment” or specific adequacy arrangements beyond what our operational reality supports.
Children’s privacy
Transit is intended for business and professional users. We do not knowingly collect personal information from children under 13 years of age (or the minimum age required in your jurisdiction if higher). If you believe a child has provided us personal information, contact support@transitcrm.com and we will take appropriate steps to delete it.
Do Not Track and automated decision-making
Some browsers offer “Do Not Track” signals. There is no consistent industry standard for responding to these signals. Our practices are described in this Policy.
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about individuals without meaningful human involvement in the ordinary course of providing Transit.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top. For material changes, we may provide additional notice (for example, by email to account owners or a notice in the application).
Continued use of Transit after an update becomes effective means you acknowledge the revised Policy. If you do not agree, stop using the Service and request account closure.
Our core commitments — no sale of customer data, no advertising / brokerage sharing of personal data, Stripe-hosted card handling, and tenant isolation — are foundational. We will not use a Policy update to silently introduce those practices.
Contact us
For privacy questions, requests, or concerns:
Pulsar Digital / PulsarCLT
Email: support@transitcrm.com
Product: Transit CRM
Sites: transitcrm.com · app.transitcrm.com
We aim to respond to privacy requests in a timely manner consistent with applicable law.
Summary (plain language)
| Topic | Our position | | --- | --- | | Selling your data | Never. | | Ads / data brokers | Never share personal data for that. | | Card numbers | Stripe Checkout only — not on our servers. | | Your CRM records | Isolated to your account. | | Ethics & pricing | We build ethical software and price necessities fairly. | | Questions | support@transitcrm.com |
If anything in this Policy is unclear, email us. We would rather answer a hard question than hide behind vague language.
