Review Pulse Privacy Policy
SOFT BETA — Operational draft. This Policy is published for soft-beta use of Review Pulse. It is not a formal Florida counsel opinion and is not counsel-cleared for paid production. Soft beta may display visible placeholders (for example [NOTICES_EMAIL]). Fill real contacts and obtain Florida counsel review before paid / full production.Version: 1.1-soft-beta-draft (no AI) Effective date: September 21, 2026 Status: Soft-beta operational draft — pending Florida counsel review before paid production Changelog 1.1: Automated draft-reply / LLM features removed from product and this Policy (Boris + Lead Engineer).
Controller (for merchant account data): OSHER PULSE LLC (“Osher Pulse,” “we,” “us,” or “our”), a Florida limited liability company Document No.: L26000375612 Address: [PHYSICAL_ADDRESS], Boca Raton, FL area Product: Review Pulse (“Service”) Public URL: https://reviews.osherpulse.com Privacy / notices contact: [NOTICES_EMAIL]
This Privacy Policy describes how we collect, use, disclose, and protect information when you use Review Pulse. Review Pulse is B2B software that helps merchants request post-service feedback (including via WhatsApp/SMS links), manage private feedback and public review workflows in a compliant manner, view a dashboard, connect Google Business Profile where authorized, and manage billing when enabled. We are not a law firm and do not provide legal advice. We do not claim HIPAA, SOC 2, ISO 27001, or similar certifications in this Policy. Review Pulse does not generate automated draft replies to reviews.
Roles. For personal information of a merchant’s end customers (name, phone, message content, ratings, and related feedback), the merchant (our Customer) is the controller and Osher Pulse acts as a processor under the Customer’s instructions, as described in the Terms of Service (Data Processing section). For account, billing, and Service-usage data about the merchant and its users, Osher Pulse is the controller.
1. Scope
This Policy applies to the Review Pulse website, application (including any PWA), and related services operated by Osher Pulse at https://reviews.osherpulse.com and associated domains. It does not apply to third-party sites or services you access through Review Pulse (for example, Stripe checkout, Google Business Profile, WhatsApp/Meta, or Twilio-powered messaging interfaces), which have their own privacy practices.
Soft-beta features may change without notice. This Policy describes current intended practices for soft beta.
2. Information We Collect
2.1 Account and profile information
Name, email address, business name, password or authentication credentials, role/team settings, plan or subscription status, and preferences you provide.
2.2 Merchant business information
Business profile details you submit (for example location name, public review profile identifiers, brand voice notes, reply templates, and Google Business Profile connection metadata when you authorize OAuth).
2.3 Billing information
If paid plans are enabled, payment processing is handled by Stripe. We do not store full card numbers. We may receive tokens, last-four digits, payment status, customer IDs, and subscription status as needed to operate billing.
2.4 End-customer data (processed on behalf of the merchant)
When the merchant uses the Service to request feedback or manage reviews, we may process, on the merchant’s instructions: end-customer name, phone number, email (if provided), message content, star ratings or sentiment indicators, private feedback text, public review text synced from connected platforms, merchant-authored reply text and published replies, channel (SMS/WhatsApp/etc.), delivery status, and related timestamps and tokens.
2.5 Messaging and consent logs
Records that SMS/WhatsApp or similar messages were authorized to be sent, opt-out/STOP events, template identifiers, and delivery/error metadata provided by messaging providers — used to operate the Service and support compliance logging. Obtaining legally required consent from end customers is the merchant’s responsibility; we log what the Service records under the merchant’s configuration.
2.6 Device, usage, and log data
IP address, user-agent, approximate location derived from IP, feature usage, crash or diagnostic events, and security logs typical of SaaS products.
2.7 Cookies and similar technologies
We use session cookies necessary to keep you logged in and operate the Service. We may also use optional analytics cookies or similar technologies if enabled. You can control cookies through your browser; disabling necessary cookies may limit functionality. Soft beta may not yet load non-essential analytics until configured.
3. How We Use Information
We use information to:
- Provide, operate, and improve Review Pulse (review-request tooling, feedback routing, dashboard, and integrations);
- Authenticate users and secure accounts;
- Process subscriptions/billing when enabled and communicate about billing and service changes;
- Send or facilitate transactional messages that the merchant instructs us to send to end customers (for example post-service feedback links), and process STOP/opt-out where supported;
- Sync or display public reviews when the merchant connects Google Business Profile (or similar) via OAuth/API;
- Provide customer support to the merchant;
- Detect abuse, fraud, spam, security incidents, or policy-violating use (including abusive review solicitation);
- Comply with law and enforce our Terms of Service;
- Analyze aggregated or de-identified usage to improve the product.
Legal bases (where helpful / for transparency): performance of a contract with the merchant; legitimate interests in operating and securing a B2B SaaS product; and, for certain SMS/WhatsApp or marketing communications to end customers, consent obtained by the merchant (and logged where the Service supports it). Soft beta does not assert GDPR adequacy for every jurisdiction; international merchants should assess their own obligations.
We do not use the Service to provide legal advice. We do not instruct merchants to suppress negative reviews or to send only high ratings to public platforms.
4. SMS / WhatsApp and Messaging
- Merchant responsibility. The merchant is responsible for having a lawful basis (including TCPA, state telemarketing rules, WhatsApp/Meta Business terms, and any applicable consent) before instructing Review Pulse to message end customers.
- Our role. We send messages as a processor/service provider under the merchant’s instructions and configuration, using providers such as Twilio and/or WhatsApp / Meta (or successors).
- Transactional vs marketing. Feedback-request messages may be treated as transactional or marketing depending on content, timing, and law. Merchants must configure templates and audiences lawfully. Soft beta does not guarantee classification under every statute.
- STOP / opt-out. Where channel rules allow, end customers may reply STOP (or channel-equivalent) to opt out of further messages from that program. Merchants should include clear opt-out language in message templates. We process opt-out signals we receive through connected providers.
- Logging. We may retain consent attestations the merchant records in-product, send logs, and opt-out events for operational and compliance-support purposes.
5. How We Share Information
We share information only as needed to operate the Service:
- With messaging and review platforms you connect — for example Twilio/SMS, WhatsApp/Meta, and Google (Business Profile OAuth/API) so messages can be delivered and reviews synced under your authorization;
- With service providers (subprocessors) — including payment processing (Stripe), email delivery ([EMAIL_PROVIDER]), and hosting ([HOSTING]), under contracts that limit use to providing services to us;
- With your authorized users — team members on your tenant account;
- For legal reasons — if required by law, legal process, or to protect rights, safety, or the Service;
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to appropriate protections.
We do not sell personal information for money. We are not a party to the relationship between the merchant and its end customers.
6. International Transfers
Review Pulse may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms at a high level. Soft-beta international transfer documentation may be incomplete until counsel review.
7. Retention
- Account and merchant business data: retained for the life of the account, then deleted or anonymized within a reasonable period after closure, unless we must retain longer.
- End-customer messaging, ratings, and feedback: retained while needed to provide the Service to the merchant and for a reasonable period thereafter (or as the merchant configures/deletes where available), subject to legal holds and provider retention.
- Billing records: retained as required for tax, accounting, and dispute purposes.
- Consent / STOP / security logs: retained for a reasonable period to support abuse prevention and compliance inquiries.
- Legal holds: we may retain data longer if needed for disputes, investigations, or legal obligations.
Exact soft-beta retention windows may be tuned; contact [NOTICES_EMAIL] for current practice.
8. Security
We implement reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure. You are responsible for safeguarding account credentials and for configuring integrations securely. Soft beta does not claim SOC 2, ISO 27001, HIPAA, or similar certifications.
9. Your Choices and Rights
Depending on your location and applicable U.S. state privacy laws (and other laws that may apply), you may request access, correction, deletion, or export of personal information by contacting [NOTICES_EMAIL]. We will respond as required by applicable law.
- Merchants may update account settings, disconnect integrations, and request deletion of tenant data subject to retention rules.
- End customers should generally contact the merchant (controller) regarding their feedback/messaging data; we will assist the merchant as processor where appropriate.
- You may opt out of non-essential marketing emails from Osher Pulse (transactional emails will continue).
- You may control cookies via your browser.
- You may close your account (subject to retention rules above).
A fuller Data Processing Addendum (DPA) for enterprise merchants is available on request during soft beta ([NOTICES_EMAIL]).
10. Children
Review Pulse is for users 18 years of age or older and for commercial / B2B use. We do not knowingly collect personal information from anyone under 18. If you believe we have, contact [NOTICES_EMAIL] and we will take appropriate steps. Merchants must not use the Service to target minors.
11. Not Legal Advice; No Special Compliance Claims
Review Pulse is software only. We do not claim HIPAA, SOC 2, ISO 27001, or similar certifications in this Policy unless separately and expressly stated in writing. Use of Review Pulse does not guarantee compliance with FTC Endorsement Guides, Google review policies, TCPA, WhatsApp policies, or any other law or platform rule — merchants remain responsible for compliant review solicitation and messaging.
12. Changes
We may update this Policy. Soft beta may change features and practices with limited notice. We will post the new version with an updated effective date and, where appropriate, notify you via the Service or email. Continued use after the effective date constitutes acceptance of the updated Policy.
13. Contact
OSHER PULSE LLC [PHYSICAL_ADDRESS] Boca Raton, FL area Email: [NOTICES_EMAIL] Product: Review Pulse — https://reviews.osherpulse.com
English version. If a Spanish translation is also provided, the English version prevails in case of conflict (see Terms of Service).