CrowdPulseCrowdPulse

Privacy Policy

Effective 2026-07-05 · Controller: AtriVex Tech · privacy@atrivex.com

CrowdPulse shows how busy places are using aggregated signals, explicit user reports, venue reports, and licensed provider feeds. This policy explains what we collect and the rights you have in the European Union, the United States, and Japan.

What we collect

  • Account data: email address and display name. If you sign in with Google or Apple we receive only your account identifier and email from them — never your contacts, calendar, or other provider data.
  • Crowd reports: the place, a busyness level, and a timestamp. We do not collect or store raw location timelines, movement history, or background GPS traces.
  • Business workspace data: venues, offers, campaigns, and redemption counts for the organization you belong to.
  • Technical data: request logs (IP address, request id, latency) kept for security and reliability.

How we use it

  • To show live and forecast crowd levels. Crowd statistics shown to businesses and any licensed exports are aggregate-only and cannot identify you.
  • To run the off-peak offers marketplace, including enforcing redemption caps.
  • To bill business subscriptions through Stripe. We never store full card numbers.
  • We do not sell personal information and do not use it for cross-context behavioral advertising.

Your rights — European Union (GDPR)

  • You can access and export your data (Art. 15, 20), correct it (Art. 16), delete it (Art. 17), and object to or restrict processing (Art. 18, 21).
  • Legal bases: contract performance for the service itself, consent for optional cookies, and legitimate interest for fraud prevention and security logging.
  • Transfers outside the EEA are covered by Standard Contractual Clauses. Complaints can go to your local supervisory authority.

Your rights — United States (CCPA/CPRA and state laws)

  • You have the right to know what personal information we hold, to delete it, to correct it, and to non-discrimination for exercising those rights.
  • We do not sell or share personal information as defined by the CPRA, so no opt-out is required — but you can still contact us about any concern.

Your rights — Japan (APPI)

  • You may request disclosure of your retained personal data (Art. 28), correction (Art. 29), and cessation of use or deletion (Art. 30).
  • Crowd statistics are produced as anonymously processed information under APPI and cannot be re-identified.
  • Personal data is processed on infrastructure outside Japan; by using CrowdPulse you consent to this cross-border transfer as described here (Art. 28 of the amended APPI).

Exercising your rights

  • In-app: Account settings → Export my data, or Delete my account. The API equivalents are GET /v1/me/export and DELETE /v1/me.
  • By email: privacy@atrivex.com. We respond within 30 days (GDPR), 45 days (CCPA), or 2 weeks (APPI disclosure requests), whichever applies to you.
  • Deleting your account removes your profile and memberships; your past crowd reports are detached from your identity and survive only as anonymous statistics.

Retention and security

  • Account data is kept while your account is active and deleted on request. Request logs are kept for 90 days.
  • All traffic is encrypted with TLS 1.2+. Data is encrypted at rest. Access by AtriVex staff is time-limited, reason-bound, and visible in your workspace audit log.
  • Security disclosures: security@atrivex.com or /.well-known/security.txt.