Privacy Policy
Last updated: January 15, 2025
At pulsarmax, we believe your financial data deserves serious protection. This policy explains how we collect, use, and safeguard your personal information when you use our budget automation services. We're based in Thailand and operate under Thai data protection laws, but we're committed to transparency regardless of where you access our platform.
Information We Collect
Account Information
When you sign up for pulsarmax, we collect basic details to create and maintain your account. This includes your name, email address, phone number, and a password that you create. If you're using our services through a business account, we might also collect your company name and business registration details.
Financial Data
Here's where things get more specific. Our budget automation tools need to see your financial information to work properly. We collect transaction data from the accounts you connect, including purchase amounts, merchant names, transaction dates, and account balances. We don't store your actual bank login credentials though – we use secure third-party banking APIs that connect directly to your financial institutions.
- Transaction history and categorization data
- Account balance information across linked accounts
- Recurring payment patterns and subscription details
- Budget targets and spending limits you set
- Income sources and payment schedules
Usage Information
We track how you interact with pulsarmax to improve our service and fix problems. This includes your IP address, device type, browser information, pages you visit, features you use most often, and how long you spend on different sections of our platform. Nothing invasive – just standard analytics that help us understand what's working and what needs improvement.
Communication Records
If you contact our support team through email, chat, or phone, we keep records of those conversations. This helps us provide better assistance and track issues that might affect multiple users.
How We Use Your Information
Your data serves specific purposes within our budget automation system. We're not in the business of selling your information or using it for purposes beyond what's necessary to run our service effectively.
Primary Service Functions
- Processing and categorizing your financial transactions automatically
- Generating spending insights and budget recommendations
- Sending alerts when you approach budget limits or detect unusual spending
- Creating personalized financial reports and forecasts
- Syncing data across your devices so you can access information anywhere
Account Management
We use your contact information to manage your account, send password resets, notify you about important changes to our service, and respond to support requests. You'll also get essential service updates – like when we're doing scheduled maintenance or if there's a security issue that affects your account.
Service Improvement
Analytics data helps us understand which features get used most, where people struggle, and what improvements would make the biggest difference. For example, if we notice many users abandoning a particular workflow, we know that process needs redesigning.
We never use your transaction data for advertising purposes. Your spending habits stay between you and pulsarmax.
Data Sharing and Third Parties
Budget automation requires some external connections, but we're selective about who gets access to what.
Banking Connections
We partner with regulated financial data aggregators to connect securely with your banks. These services – companies like Plaid and similar providers – use bank-level encryption and never share your login credentials with us. They simply pass transaction data through secure, authenticated channels.
Service Providers
Some operational tasks require trusted third parties. Our hosting provider stores encrypted data on secure servers. Our email service sends account notifications and password resets. Our analytics platform helps us track how the application performs. Each of these partners signs data processing agreements that legally bind them to protect your information and use it only for specified purposes.
Service Type | Purpose | Data Access Level |
---|---|---|
Cloud Hosting | Application infrastructure and data storage | Encrypted data only |
Banking APIs | Transaction data retrieval | Read-only financial data |
Email Services | Account notifications and communications | Email address and message content |
Analytics Platform | Usage patterns and performance monitoring | Anonymized usage data |
Payment Processor | Subscription billing | Payment method details |
Legal Requirements
Thai law requires us to disclose information in certain circumstances. If we receive a valid court order, subpoena, or official government request, we may need to provide relevant data. We also reserve the right to share information if we believe it's necessary to prevent fraud, protect our legal rights, or ensure user safety.
We'll never sell your personal information to data brokers, advertisers, or marketing companies. That's not our business model and it never will be.
Data Security Measures
Financial data demands serious protection. Here's what we do to keep your information secure.
Encryption Standards
All data transmission between your device and our servers uses TLS 1.3 encryption – the same standard banks use for online banking. Your stored data sits in encrypted databases with AES-256 encryption. Even if someone somehow accessed our servers physically, they'd find only encrypted data that's essentially unreadable without proper decryption keys.
Access Controls
Our team operates on strict need-to-know principles. Engineers who maintain our infrastructure can't access your financial data. Support staff who help with account issues only see the minimum information necessary to resolve your specific problem. We log every internal access to sensitive systems and review those logs regularly.
Regular Security Audits
Third-party security firms conduct penetration testing on our systems twice yearly. We also run continuous automated vulnerability scans and patch critical security issues within 24 hours of discovery. Our infrastructure undergoes annual compliance reviews to verify we're meeting industry security standards.
- Multi-factor authentication required for all staff accounts
- Automated monitoring for suspicious activity patterns
- Regular backup systems with encrypted storage
- Incident response procedures tested quarterly
- Security training required for all team members annually
No security system is completely bulletproof though. If we ever experience a data breach that affects your account, we'll notify you directly within 72 hours and explain exactly what information was involved and what steps you should take.
Your Privacy Rights
Thai data protection laws give you specific rights regarding your personal information. Here's what you can do and how to exercise these rights.
Access Your Data
You can request a complete copy of all personal information we hold about you. This includes your profile details, transaction history, usage logs, and any notes from support interactions. We'll provide this data in a readable format within 30 days of your request.
Correct Inaccurate Information
Most account details can be updated directly in your settings. For information that requires manual correction – like transaction categorizations that got assigned incorrectly – contact our support team and we'll fix it promptly.
Delete Your Account
You can close your pulsarmax account anytime through your account settings. This removes your profile information and disconnects all linked financial accounts immediately. Transaction data gets anonymized after 90 days, though we retain some aggregated statistics for legal compliance and fraud prevention. Financial records required by Thai tax authorities may be kept for up to seven years in compliance with local regulations.
Restrict Processing
If you want to keep your account but limit how we use certain data, you can opt out of non-essential processing. This means we'll only use your information for core budget tracking functions and skip things like personalized recommendations or advanced analytics features.
Data Portability
You can export your transaction data, budget history, and spending reports in CSV format anytime. This lets you move to another service or keep your own records without being locked into our platform.
To exercise any of these rights, send an email to [email protected] with your account details and specific request. We'll verify your identity and respond within 15 business days.
Data Retention and Deletion
We don't keep your information forever. Different types of data have different retention periods based on legal requirements and practical needs.
Active Account Data
While your account remains active, we keep all your transaction history, budgets, and preferences available. This lets you view historical spending patterns and track long-term financial trends. Some users have asked us to keep data going back years – it's useful for year-over-year comparisons and understanding seasonal spending patterns.
Closed Account Data
After you close your account, here's what happens to different data types:
- Profile information gets deleted within 30 days
- Transaction details become anonymized after 90 days (we strip out all identifying information but keep aggregate spending patterns for fraud detection)
- Support conversation records are anonymized after six months
- Billing records stay on file for seven years to comply with Thai tax regulations
- Usage logs get purged after one year unless needed for ongoing security investigations
Legal Hold Exceptions
If your account is involved in a legal dispute, fraud investigation, or regulatory inquiry, we may need to preserve relevant data beyond normal retention periods. We'll only do this when legally required and will delete the information once the matter is resolved.
International Data Transfers
Our primary servers are located in Thailand, but some of our service providers operate in other countries. This means your data might occasionally get transferred internationally for processing.
When data leaves Thailand, we ensure receiving parties provide adequate protection through standard contractual clauses approved by Thai data protection authorities. Our cloud infrastructure provider maintains ISO 27001 certification and complies with international data protection standards.
If you connect bank accounts from countries outside Thailand, transaction data from those accounts flows through local banking APIs in those jurisdictions before reaching our servers. These connections use the same encryption standards regardless of location.
Cookies and Tracking Technologies
Our website and application use cookies to function properly and improve your experience. Here's what gets stored and why.
Essential Cookies
These keep you logged in, remember your preferences, and ensure security features work correctly. You can't disable these without breaking basic functionality. They include session identifiers, authentication tokens, and security settings.
Analytics Cookies
We use these to understand how people use pulsarmax – which features get used most, where people encounter problems, and how long different tasks take. This information helps us prioritize improvements and fix confusing interfaces. You can opt out of analytics tracking in your privacy settings.
Preference Cookies
These remember settings like your preferred currency display, dashboard layout, and notification preferences. They make the experience more convenient but aren't strictly necessary.
We don't use advertising cookies or share cookie data with third-party advertisers. Our tracking focuses exclusively on improving our own service.
Children's Privacy
pulsarmax is designed for adults managing their own finances. We don't knowingly collect information from anyone under 18 years old. If you're a parent and discover your child has created an account, contact us immediately and we'll delete it.
Our terms of service explicitly prohibit minors from using the platform. If we learn that someone under 18 has provided personal information, we'll delete that data within 48 hours.
Changes to This Policy
Privacy practices evolve as technology changes and regulations develop. When we update this policy, we'll notify active users via email at least 30 days before changes take effect. Significant changes – like new data collection practices or changes in how we share information – will require your explicit consent before they apply to your account.
The "Last updated" date at the top of this page always reflects the most recent version. We recommend reviewing this policy periodically, especially if you haven't checked it in a while.
Previous versions of this policy are archived and available upon request if you want to see what changed over time.
Thai Data Protection Compliance
As a company operating in Thailand, we comply with the Personal Data Protection Act B.E. 2562 (PDPA). This law gives Thai residents specific rights regarding their personal data and establishes standards for how organizations must handle information.
We've registered as a data controller with Thai authorities and maintain documentation of our data processing activities as required by law. Our data protection officer oversees compliance and serves as the primary contact for regulatory matters.
If you believe we've mishandled your personal information or violated your privacy rights under Thai law, you can file a complaint with the Personal Data Protection Committee through their official channels. We encourage you to contact us first though – most concerns can be resolved quickly through direct communication.
Contact Us About Privacy
Questions about how we handle your data? Need to exercise your privacy rights? Want to report a security concern?
Email: [email protected]
Phone: +66 3273 0082
Mail: pulsarmax Privacy Department
193 moo 13, Tha Wang Tan
Saraphi District, Chiang Mai 50140
Thailand
We aim to respond to privacy inquiries within three business days. For urgent security matters, mark your message as "Security Issue" and we'll prioritize it accordingly.