Privacy Policy

Last updated: 30 July 2026

The short version

We use two tracking tools. We use them to run SuperPulse, not to sell you to anyone.

Nothing runs in your browser until you say yes. Before you answer the cookie banner, neither tool is loaded. No script, no request, no analytics cookie. If you say no, they stay off in your browser.

One exception, stated up front rather than buried: if you buy from us, or start a checkout, our servers tell Meta that a sale (or a checkout) happened, whatever you answered on the banner. That is us measuring whether the money we spend on our own ads pays, it happens server to server using details you gave us to take the payment, and the section "What our servers send to Meta" spells out exactly what is in it and how to object.

One thing runs regardless, and it is not tracking: when something breaks on the site we record an anonymous technical error report (what failed and on which page, never who you are) so we can fix it. It sets no cookie, stores nothing in your browser, and is not linked to you. This is not analytics; it is how we keep the site working.

PostHog is our analytics. It tells us which pages work and where people get stuck. It runs on servers in the EU, and it is set to discard your IP address.

The Meta pixel tells us which of our own ads brought you here, and whether they were worth the money. Our servers send Meta a copy of the same events, with your email, phone and first name hashed.

We do not sell your data, and we do not hand it to data brokers or ad networks. It does go to the companies that run the tools and the plumbing underneath SuperPulse (analytics, payments, email, hosting), and every one of them is named further down.

One more thing worth knowing up front: if you say yes, PostHog records sessions. Mouse movement, clicks, scrolling and what was on the page. Anything you type into a form is masked before it leaves your browser, so we never see passwords, card numbers or what you typed. Recordings are deleted after 30 days.

Changed your mind? There is a Cookie settings button at the bottom of this page, the pricing page, the terms page, the homepage, the waitlist pages and your dashboard. One click takes the answer back and asks you again, and it stops the tracking in your browser on the spot. If you are signed in, it also clears the copy saved against your account, which is the copy the parts of our system that run without your browser read. There is one thing it still does not reach, and we have spelled that out under Your rights rather than let you find it later.

The rest of this page is the honest long version, for anyone who wants it.


Who we are

SuperPulse is run by Huddle Duck Ltd, a UK company (number 11837993), registered at 22 Ventnor Road, Solihull B92 9BU. We are the data controller for everything on this page.

SuperPulse boosts a local business's Instagram posts to people nearby, using the business's own Instagram account and their own Meta ad account.

Questions, or want your data gone: asad@huddleduck.co.uk

Why we are allowed to hold your data

Under UK GDPR we need a lawful basis for each thing we do. Ours are:

  • Contract. If you are a customer, we need your account details, your Instagram data and your billing details to actually run the service you paid for. No way around it.
  • Consent. PostHog and the Meta pixel are optional, and they only run because you clicked "Accept" on the banner. Until then they do not run at all, and you can take the answer back whenever you like (see Your rights).
  • Legitimate interests. Keeping the service up, stopping fraud, alerting ourselves when something breaks, and measuring whether our own advertising pays: when you buy or start a checkout, our servers report that sale to Meta (details and your right to object under "What our servers send to Meta"). We keep this to the minimum that does the job.
  • Legal obligation. We keep billing and tax records for as long as HMRC requires (six years).

What we collect if you are just visiting

Only if you accepted the banner:

  • Pages you viewed, clicks, scrolls, roughly where you came from, what device you are on. Via PostHog. PostHog is set to discard your IP address, so it never stores it.
  • A session recording. A reconstruction of your visit: mouse movement, clicks, scrolling, the content of the page, your browser's console messages, and the timing of the requests the page made (their timing, not what was inside them). Every form input is masked, so what you type never leaves your browser. Recordings are kept for 30 days and then deleted.
  • Which of our ads you clicked. Via the Meta pixel and via our servers (see the next section).

Before you answer the banner, none of that happens. The Meta pixel is not on the page, so nothing is requested from Facebook and no Meta cookie is created. PostHog is not started, so not a single request goes to it. "Has not answered yet" counts as a no.

If you say no, here is what still happens, because it is the thing you came for and not tracking:

  • What you typed into our forms (name, email, phone, Instagram handle, quiz answers) is saved in our own database.
  • You still get the emails you signed up for, and you can unsubscribe from any of them.
  • The boring functional cookies still work, so the site can keep you signed in and not lose your payment halfway through.
  • We store the fact that you said no, so that everything downstream knows to stay quiet.

Small thing we would rather say than hide: if PostHog is running, its requests leave your browser via superpulse.io/ingest rather than a posthog.com address. That is so ad blockers do not eat our own numbers. The data still lands at PostHog, on their EU servers. A first-party proxy should not be a secret.

What our servers send to Meta

This is the part most policies do not admit to, so here it is plainly.

Alongside the pixel in your browser, our servers send conversion events straight to Meta's Conversions API. There are six: joining the waitlist, finishing the qualifying quiz, booking or asking for a call, starting a checkout, paying, and connecting your Instagram at signup.

What goes in one of those events:

  • Your email, phone number and first name, hashed. They are run through SHA-256 first, so Meta receives a fingerprint rather than the plain text. Meta matches that fingerprint against accounts it already has.
  • Your IP address and your browser's user agent, not hashed. Meta needs them to match the event to a person. We are telling you because "hashed" is often used to make this sound gentler than it is.
  • The Meta cookie values (_fbp / _fbc), if you have them, and, on a purchase, the click id from the ad link that brought you here, your Stripe customer reference (hashed) and the town, region, postcode and country from your billing address (hashed).
  • What happened and what it was worth (for example: a purchase, and the amount).

The two money events are sent whatever you answered. When you start a checkout, and when Stripe tells our server you paid, our servers report that to Meta. This is not the banner being ignored: nothing extra runs in your browser and no cookie is read to do it. It is our servers passing on details you gave us to take the payment, so we can see which of our own ads pay for themselves, and our lawful basis for it is legitimate interests, not consent. If you object to your purchase being counted this way, email asad@huddleduck.co.uk and we will exclude you, no questions.

The other four still check your answer first, and no answer means nothing is sent. Joining the waitlist, the quiz, booking or asking for a call, and connecting your Instagram at signup are sent only on a recorded yes. When Cal.com tells our server you booked a call, that message carries nothing of yours, so we do not guess: your answer was written down while you were still in your own browser, and the server reads it back before it sends anything. If it says no, or there is nothing on file, Meta gets nothing.

Everything else about paying and booking is unaffected either way. The payment goes through, the receipt arrives, the call lands in the calendar, your account gets set up.

The gap in that, which we would rather tell you about. For the consent-gated events, the answer we saved is the one you were giving at the time. If you accepted the banner, filled in one of our forms, and only changed your mind afterwards, the copy saved against your email still says yes until you next submit a form. So a call you book after that can still send Meta the hashed email, phone and first name on the strength of the older yes. Clicking "Cookie settings" stops the tracking in your browser immediately, and if you are signed in it clears the copy saved against your account. It cannot reach the copy saved against your email, because we would have to know it was you. Email asad@huddleduck.co.uk and we will wipe that one the same day. Making the button do it for you is still on our list.

Our background jobs send Meta almost nothing. When the system launches an ad for a customer or turns one off, that is between us, the database and Meta's ad platform. One exception: the first time a customer's first ad goes live, we send Meta a single milestone event carrying that customer's hashed email, and only for customers with a recorded yes on their account. No answer, or a no, and it is not sent.

What we collect if you are a customer

When you create a SuperPulse account, we collect your email address and store a secure hash of your password. Your name and phone number are optional. If you give us a phone number, we may use it to call when direct account support would be useful, or to tell you about an account-specific free improvement. Giving us a phone number does not opt you into WhatsApp or general marketing messages.

When you connect your Instagram through Facebook Login, you approve a specific set of permissions, and we ask for these:

  • Your Instagram posts and their numbers. Likes, comments, saves, views, reach. This is how we work out which posts are worth putting money behind.
  • Your Facebook Page and the list of Pages you manage. So you can pick the right business during setup, and so ads can run under the right identity.
  • Your ad account. To create and manage the boost campaigns, and to read back how they performed (spend, reach, clicks, profile visits).
  • Your email address. For account emails and performance reports.

We do not ask for Business Manager access. We used to. We removed it in April 2026 because we were not using it.

None of those permissions lets us read your DMs or post to your account, and your posts are never used to train models.

What we actually do with your Instagram and ad data

  • We read your posts and their insights, and score them, so the system knows which ones to boost.
  • We create and manage ads inside your ad account, not ours. The campaigns show up in your Ads Manager and you can see, pause or delete anything at any time.
  • Your ad spend is billed by Meta, directly to you. It never passes through us. Your subscription and your ad budget are two different bills from two different companies.
  • Your business name, account details and optional phone number show up on our internal dashboard so we can support you, including by calling when that would help.
  • Everything the system does for you is written to our own database. Every scan, every ad launched, every ad stopped. That happens whatever you said to the banner, because it is how the product works and how we support you.

If you accepted the banner, two more things happen, and only then:

  • We identify you in PostHog by your account ID and business name once you are signed in. So we can see, for example, that a real business got stuck on the locations screen. Worth saying, because "anonymous analytics" would not be true.
  • Our servers send PostHog the backend milestones for your account: payment taken, Instagram connected, setup finished, an ad went live, an ad was retired. These carry your account ID and business facts (number of locations, currency, amount, ad IDs). They never carry your email, your name or your phone number.

If you have not accepted, both of those stay off. Every customer who bought before the banner existed has no answer on file, so their backend events are off. To put an answer on file, sign in and answer the banner on your dashboard: we save it against your account, and that is what the backend reads. Cookie settings in your dashboard footer clears it again, and the backend goes quiet from the next event onwards.

Cookies, in full

Essential. These are ours, they are first-party, and the site does not work without them. No consent needed and no way to turn them off while using the product.

  • tenant_id: keeps you signed in. 60 days.
  • sp_chk_sid: ties a payment to the browser that made it, so your payment cannot get stranded away from your account. 7 days.
  • sp_oauth: a one-use security token for the Instagram login round trip. Stops someone else's login being pushed into your browser. 10 minutes.
  • sp_gate and sp_gate_oauth: the private beta door. 30 days.
  • sp_ref: remembers which mate referred you, so they get credit. 30 days.
  • sp_join, sp_join_comp, sp_join_magic: invite and sign-in links, so a link we sent you lands where it should.
  • sp_hq, sp_impersonate, sp_admin: staff only, for our own console. These are never set on a customer's browser.
  • sp_consent: your answer to the cookie banner, in one word ("accepted" or "rejected"). 12 months. Our servers read it, which is the whole point of it: the Meta events described above are sent by our servers, not by your browser, so the server has to be able to see the same answer you gave. It is readable by scripts on our own site because the banner is what writes it.
  • sp_fbclid and sp_utm_source / sp_utm_medium / sp_utm_campaign / sp_utm_content / sp_utm_term: which ad or link brought you here, copied off the address you arrived on. 30 days, first-party, set on arrival. They load no tracking script and talk to nobody: if you go on to buy, they tell us which of our own ads earned the sale (and ride the purchase report described above). If you never buy, they expire unread.

Where else that answer lives, so you know. Your browser keeps it in local storage under sp-consent-v1. If you have given us your email, it is saved against your record in our database, so a message arriving later from Stripe or Cal.com can be checked against it. And if you are a customer, it is saved against your account, because the jobs that run your ads have no browser to read a cookie from. Answering the banner while signed in writes that one, and Cookie settings while signed in clears it.

Not essential. These only appear after you click "Accept" on the banner, and they never appear if you do not.

  • _fbp and _fbc: set by Meta. They connect your visit to one of our ads.
  • The PostHog cookies (their names all start with ph_): set by PostHog. They tell a returning visitor apart from a new one and stitch your pageviews into one session.

Who else touches your data

Every company below is a supplier we pay to run a piece of SuperPulse. They process data on our instructions and they are not allowed to use it for their own purposes.

  • PostHog (EU cloud): analytics and session recording. Only if you accepted.
  • Meta: the pixel and the Conversions API (only if you accepted), and the ad platform your campaigns actually run on (that part is the service you bought).
  • Stripe: subscriptions and payments. Stripe takes your card details directly. We never see or store a card number.
  • Cal.com: if you book a call with us, your name, email and slot.
  • Resend: sends our emails.
  • Turso: the database your data sits in. Turso hosts it, not Vercel and not us on a laptop.
  • Vercel: hosts the app itself.
  • Slack and Notion: our own internal alerts. When you pay, cancel, or something breaks on your account, a message with your name, email and what happened lands in our team channel and our task list, so a human actually picks it up.
  • Anthropic: campaign numbers (budgets, impressions, clicks, spend) go to Claude to help decide where to shift budget. If the address you typed at setup is messy, the address text goes too. No contact details, no post content.
  • OpenStreetMap (Nominatim) and postcodes.io: turning your address into a map pin so we can target the right radius. They receive the address, nothing else.

That is the list. If it changes, this page changes.

Where your data lives and how it is protected

  • Your account data sits in an encrypted Turso (LibSQL) database.
  • Your Meta access token is encrypted at rest. It is the keys to your ad account, and we treat it that way.
  • Everything moves over HTTPS.
  • Access is limited to the systems that need it and the people who run SuperPulse.

How long we keep things

  • Session recordings: 30 days, then PostHog deletes them.
  • Analytics events: up to 84 months. That is longer than the recordings, so we would rather say it than let "deleted after 30 days" cover the lot. It does not.
  • Your account and campaign data: for as long as you are a customer, then 30 days after you cancel (in case you come back), then deleted.
  • Billing records: six years, because tax law says so.
  • Waitlist details, if you never became a customer: until you ask us to delete them. Email us and we will.

Your rights

  • See what we hold. Most of it is on your dashboard. Ask us for the rest.
  • Get a copy. Email us and we will export it.
  • Have it deleted. Email asad@huddleduck.co.uk. We will delete it within 30 days.
  • Correct anything wrong.
  • Withdraw your consent to tracking, at any time. There is a Cookie settings button in the footer of this page, the terms page, the pricing page, the marketing site, the waitlist pages, and your dashboard once you are signed in. One click and it: deletes your answer from your browser (both the sp-consent-v1 entry and the sp_consent cookie), stops PostHog capturing on the spot along with any recording in progress, drops PostHog's own storage, and puts the banner back up so you can decide again. If you are signed in, it also clears the copy saved against your account, so the consent-based events our servers send about you stop as well. If the Meta pixel was running, the page also reloads, because a pixel script that has already run cannot be pulled back out of a live page and a fresh page is the only honest way to guarantee it stops. Withdrawing does not undo what was already collected, and it is the same button whether you said yes or no. The one thing this button does not govern is the purchase report described under "What our servers send to Meta", because that runs on legitimate interests, not consent; to object to that one, email asad@huddleduck.co.uk.
  • What that button does not reach, said plainly. There is a second copy of your answer, saved against your email rather than your account, because Stripe and Cal.com talk to our servers without your browser in the middle and an email is all those messages carry. On a page where you are not signed in we cannot tell whose email to clear, so the button leaves it alone. If you accepted, and only changed your mind later, a call you book afterwards or a payment you had already started at Stripe can still be sent to Meta on the strength of the older yes. Email asad@huddleduck.co.uk and we will clear it the same day. Making the button do it for you is still on our list.
  • Cut off our access to your Instagram. Meta Business Settings, then Business Integrations, then SuperPulse, then Remove. You do not need to ask us first.
  • Complain to the regulator. If you think we have handled your data badly, tell us and we will fix it. If we do not, you can complain to the Information Commissioner's Office at ico.org.uk, or call them on 0303 123 1113. You do not need our permission.

Changes to this policy

If we add a tool or change what we collect, we update this page and change the date at the top. If it is a significant change, we email customers rather than quietly editing.

Contact

  • Email: asad@huddleduck.co.uk
  • Post: Huddle Duck Ltd, 22 Ventnor Road, Solihull B92 9BU, United Kingdom