Privacy Policy
This Privacy Policy explains how Cafiyn Technologies Private Limited (“Cafiyn”, “we”, “us”) processes personal data collected through Cafiyn Pulse (“the Service”), available at pulse.cafiyn.com. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act 2023.
1. Data controller
The data controller responsible for your personal data is Cafiyn Technologies Private Limited. For questions about this policy or to exercise your rights, contact us at privacy@cafiyn.com. For EU residents, our EU representative is available at the same address.
2. Data we collect
We only collect data you provide directly and a minimum of technical data required to operate the Service.
- Account data: name, email address, phone number (optional), country, company name, professional role, and your stated purpose for using the Service.
- Product usage: your answers to the Stack Grader, checked items in the Launch Checklist, and configuration in the Cost Comparator. Stored so you can resume across devices.
- Verification data: a short-lived, one-way hashed 6-digit code used to verify your email address.
- Attribution data: UTM parameters and HTTP referrer captured on your first visit, to help us understand how you found us.
- Technical data: IP-derived country (never the IP itself), user-agent, timestamps of interactions.
3. Legal basis (GDPR / UK GDPR)
- Contract (Art. 6(1)(b)): account creation, email verification, saving your work.
- Legitimate interest (Art. 6(1)(f)): product analytics in aggregate to improve the Service. You may opt out via the cookie banner.
- Consent (Art. 6(1)(a)): newsletter subscription and non-essential cookies. Withdrawable at any time.
4. How we use your data
- Provide, operate, and improve the Service.
- Send transactional communications (verification codes, unlock notifications, cost alerts).
- Send occasional product updates, only if you opted in.
- Understand which features are used and where users struggle, in aggregate.
We do not sell, rent, or share your personal data with third parties for their marketing purposes. We do not pass your data to any Cafiyn product other than Cafiyn Pulse. In particular, no data flows from Cafiyn Pulse to Cafiyn FlyWheel unless you independently sign up on FlyWheel's own page.
5. Sub-processors
We rely on the following processors, each bound by a Data Processing Agreement:
- Neon (managed PostgreSQL, EU region), application database.
- Vercel (frontend hosting), CDN and edge functions.
- Railway or Fly.io (backend hosting), API compute.
- Resend (transactional email), email delivery.
- Twilio (SMS verification, only if you provide a phone number), one-time codes.
- PostHog (product analytics), anonymised behavioural analytics, opt-in in the EU.
- Sentry (error monitoring), application error tracking with IP scrubbing enabled.
6. International transfers
Where sub-processors process data outside your jurisdiction, transfers are governed by the European Commission's Standard Contractual Clauses (2021/914) and equivalent UK IDTA where applicable. Copies are available on request.
7. Retention
- Account data: for as long as your account is active, plus 90 days after deletion for backup rotation.
- Verification codes: 10 minutes, then automatically deleted.
- Product analytics: 24 months in aggregate, anonymised after 90 days.
- Support correspondence: 24 months from last contact.
8. Your rights
You have the right to:
- Access a copy of your data (self-serve via your profile or email us).
- Correct inaccurate data.
- Delete your data (self-serve via your profile, cascade deletion, no soft-delete).
- Restrict or object to processing.
- Data portability (JSON export).
- Withdraw consent for marketing at any time.
- Lodge a complaint with your local supervisory authority (ICO in the UK, CNIL in France, DPB in India, etc.).
We respond to verified requests within 30 days.
9. Security
We employ industry-standard safeguards including TLS 1.3 in transit, encryption at rest, one-way password hashing (bcrypt), least-privilege access, environment-based secrets, and quarterly access reviews. In the event of a personal data breach affecting your rights, we notify you and the relevant supervisory authorities within 72 hours as required by law.
10. Children
The Service is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
11. Changes to this policy
Material changes will be communicated by email to registered users at least 15 days before taking effect. The version and date at the top of this policy reflect the latest revision.
12. Contact
Privacy questions or requests: privacy@cafiyn.com.
Postal address available on request from the address above.