1. Who we are
The Booth Pulse (“The Booth Pulse,” “we,” “us,” or “our”) provides AI-driven analytics and business tools for working artists — festival ROI tracking, sales consolidation, commission tracking, inventory management, follow-up tools, and Gallery Connect portfolios — through our website at theboothpulse.com and related services (together, the “Service”).
The Service is operated by The Booth Pulse, with its registered address at 1370 Shady Knoll Ct, Longwood, Florida, USA. For the purposes of applicable data protection law, we are the controller of the personal information described in this policy, except where Section 9 explains that we act as a processor on your behalf.
2. What this policy covers
This policy applies to information we collect when you visit our website, create an account, use any part of the Service, contact our team, or interact with a Gallery Connect portfolio page. It does not cover third-party services you connect to The Booth Pulse (such as Square, Shopify, PayPal, Instagram, or Stripe) — those services have their own privacy policies, and we encourage you to read them.
3. Information we collect
3.1 Information you provide directly
- Account information. Your name, email address, password, artist or studio name, and profile details you choose to add (medium, bio, portfolio images).
- Business and sales data. Sales records, receipts you upload or enter, prices, commission terms and hourly rates, inventory and artwork details, festival names, booth fees, and related notes.
- Customer and contact data. Names, email addresses, and purchase details of your buyers and contacts that you add to the Follow-Up Manager or that flow in through connected sales channels (see Section 9).
- Payment information. If you subscribe to a paid plan, our payment processor collects your card details. We never see or store your full card number — we receive only a token, the card brand, the last four digits, and billing status.
- Communications. Messages you send us through the contact form, email, or support channels.
3.2 Information collected automatically
- Usage data. Pages viewed, features used, buttons clicked, session length, and referral source — used to understand what's working and what isn't.
- Device and log data. IP address, browser type, operating system, device identifiers, timestamps, and error logs.
- Cookies and similar technologies. Described in Section 10.
3.3 Information from connected services
When you choose to connect a sales or payment channel — Square, Shopify, PayPal, Instagram, or Stripe — we import the transaction data needed to power your dashboards: order totals, dates, items sold, fees, and (where the platform provides it) buyer name and email. You control which channels are connected and can disconnect them at any time in your settings.
3.4 Why we collect this information — and why we don't collect more
Every category above exists for one reason: the Service cannot do its job without it. You cannot see which festivals earn you the best return unless we hold your sales and booth-fee records; we cannot consolidate your channels unless we import transactions from the platforms you connect; the Follow-Up Manager cannot help you nurture collectors unless it stores their contact details. We follow the principle of data minimisation:
- Purpose-bound collection. We collect personal information only for the specific purposes listed in Section 4 — never “just in case,” and never to build advertising profiles.
- Minimum necessary scope. When you connect a platform, we request only the narrowest data scopes the feature needs; we do not pull your entire account history from a platform where a transaction feed will do.
- You decide what goes in. Beyond basic account details, everything in your workspace — sales records, receipts, buyer contacts, inventory — is there because you added it or connected a channel that supplies it, and you can remove it at any time.
- Proportionate retention. We keep information only as long as it serves you or the law requires (Section 11).
Our commitment: We collect only what the Service needs, we protect it as described in Section 12, and we do not sell your personal information to third parties. We do not share your personal information with third parties for cross-context behavioural advertising. We never claim any rights in your artwork, and we never charge a commission on the work you sell.
4. How we use your information
| Purpose | Examples |
|---|---|
| Provide the Service | Building your festival analytics dashboards, calculating per-show ROI, consolidating multi-channel sales, running the Commission Tracker and Follow-Up Manager, hosting your Gallery Connect portfolio. |
| Operate your account | Authentication, billing, plan changes, renewal notices, transactional emails such as receipts and buyer-purchase notifications. |
| Improve the Service | Understanding which features artists use, fixing bugs, testing improvements, developing new tools. |
| Communicate with you | Responding to support requests, sending service announcements, and — only with your consent — product news you can opt out of at any time. |
| Keep the Service safe | Detecting fraud, abuse, and security incidents; enforcing our Terms & Conditions. |
| Comply with law | Tax, accounting, and legal obligations; responding to lawful requests from authorities. |
5. How our AI uses your data
The Booth Pulse uses machine-learning models to generate insights — for example, which festivals earn you the best return, how pricing changes affect sales, and which inventory moves fastest. Here is what that means for your data:
- Your sales and festival data are analysed to produce insights for you. Insights shown to you are derived from your own account data.
- We may use aggregated and de-identified data (for example, average booth ROI across a festival, with no artist identifiable) to improve our models and publish trend insights. De-identified data is never re-identified.
- We do not use your personal information to train models that generate content for other customers, and we do not sell model outputs derived from your identifiable data.
- AI-generated insights are informational only — see our Terms & Conditions for the disclaimer that applies to business decisions you make based on them.
6. Legal bases for processing (GDPR/UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract — to provide the Service you signed up for (Art. 6(1)(b)).
- Legitimate interests — to secure and improve the Service, prevent fraud, and communicate about your account, where those interests are not overridden by your rights (Art. 6(1)(f)).
- Consent — for marketing emails and non-essential cookies; you may withdraw consent at any time (Art. 6(1)(a)).
- Legal obligation — to meet tax, accounting, and regulatory requirements (Art. 6(1)(c)).
7. When we share information
We share personal information only in the following circumstances:
- Service providers. Vendors who help us run the Service — cloud hosting, payment processing, email delivery, error monitoring, and customer support tooling — under contracts that limit their use of your data to providing services to us.
- Connected platforms, at your direction. When you link Square, Shopify, PayPal, Instagram, or Stripe, data flows between that platform and The Booth Pulse as needed to provide the features you've enabled.
- Gallery Connect visitors. If you publish a Gallery Connect portfolio, the artwork, pricing, and profile details you choose to publish are visible to anyone with the link. You control what appears there.
- Legal reasons. When required by law, subpoena, or legal process, or to protect the rights, safety, and property of The Booth Pulse, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred; we will notify you before your data becomes subject to a different privacy policy.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. Third-party integrations
The Service integrates with third-party platforms you choose to connect. Each operates under its own terms and privacy policy:
- Square — in-person and online sales data.
- Shopify — online store orders and products.
- PayPal — payment and transaction records.
- Instagram — shop and engagement data you authorise.
- Stripe — subscription billing for The Booth Pulse, and “Buy Now” checkout on Gallery Connect portfolios.
We access only the data scopes needed for the features you enable, and disconnecting an integration stops all further imports from it. Data already imported remains in your account until you delete it.
9. Your customers' data — our role as processor
When you store information about your buyers and contacts in The Booth Pulse — for example in the Follow-Up Manager, or via buyer email notifications on Gallery Connect — you are the controller of that data and we act as your processor. In plain terms:
- We process your customers' data only to provide the features you use — never for our own marketing.
- You are responsible for having a lawful basis to collect and use your customers' information, and for honouring their requests (for example, unsubscribes or deletion).
- We will assist you with reasonable requests to access, correct, export, or delete customer records held in your account.
- If a buyer contacts us directly about data held in your account, we will refer them to you and assist as needed.
- Your customers' data receives the same safeguards as your own — encryption in transit and at rest, access controls, and the security measures described in Section 12 — and is never used for our own marketing, profiling, or advertising.
10. Cookies & tracking technologies
We use a small number of cookies and similar technologies:
- Essential cookies — keep you signed in and the Service secure. These cannot be switched off.
- Preference cookies — remember settings such as your dashboard layout.
- Analytics cookies — help us understand how the Service is used so we can improve it. Where required by law, these are set only with your consent.
We do not use third-party advertising cookies. Most browsers let you refuse or delete cookies; note that blocking essential cookies will prevent you from signing in. We honour the Global Privacy Control (GPC) signal where legally required.
11. Data retention
- Account data is kept for as long as your account is active.
- Sales and analytics history is kept for as long as you keep it in your account — your multi-year festival history is often the most valuable part of the Service, so we never delete it without your instruction.
- After account deletion, personal data is deleted or de-identified within 30 days, except records we must keep for legal, tax, or security purposes (typically up to 7 years for financial records) and residual copies in encrypted backups, which expire on a rolling schedule of up to 90 days.
- Free (Basic) accounts that remain inactive for an extended period may be deleted after advance email notice.
12. How we safeguard your data
Your festival history, sales records, and customer relationships are your business's most valuable assets, and we treat protecting them as a core part of the Service — not an afterthought. Our safeguards include:
- Encryption everywhere. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including uploaded receipts and customer contact records.
- Strict access controls. Our team operates on least-privilege access: staff can reach customer data only when needed to support you, every access is logged, and administrative access requires multi-factor authentication.
- Credential protection. Passwords are stored only as salted hashes; we never store your full card number (payments are tokenised by our payment processor); and platform connections use OAuth tokens rather than your platform passwords wherever the platform supports it.
- Certified hosting. The Service and your data are hosted with Hostinger, our hosting provider, in United States–based data centers. Hostinger's infrastructure is ISO/IEC 27001-certified — the international standard for information security management.
- Vendor safeguards. Service providers who touch personal data are bound by data-protection agreements and are reviewed before we use them.
- Resilience. Continuous monitoring, network protections, and regular encrypted backups so your records survive hardware failure.
- Account tools for you. You control your own security perimeter too — use a strong, unique password, and contact support@theboothpulse.com right away if you suspect unauthorised access.
No method of transmission or storage is 100% secure, but if we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law, without undue delay, and tell you what happened and what we are doing about it.
13. International data transfers
The Booth Pulse is operated from Longwood, Florida, in the United States. The website and your data are hosted with our hosting provider, Hostinger, in data centers located in the United States. If you access the Service from outside that region, your information will be transferred to, stored, and processed there. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
14. Your privacy rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information;
- Export your data in a portable, machine-readable format;
- Object to or restrict certain processing, including direct marketing;
- Withdraw consent at any time, where processing is based on consent;
- Complain to your local data protection authority.
You can exercise most of these rights directly from your account settings (export and delete included). For anything else, email privacy@theboothpulse.com. We respond to verified requests within 30 days (or the shorter period your local law requires), and we will never discriminate against you for exercising your rights.
15. Additional rights for US state residents
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, or another state with a comprehensive privacy law, you have the rights listed in Section 14, plus:
- Right to know the categories of personal information collected, the purposes, and the categories of third parties it is disclosed to — all described in Sections 3, 4, and 7.
- Right to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of — but we honour GPC signals regardless.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by the CCPA.
- Authorised agents may submit requests on your behalf with proof of authorisation.
- Appeals. If we decline a request, you may appeal by replying to our decision email; where applicable you may also contact your state Attorney General.
16. Children's privacy
The Service is intended for working artists running a business and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact privacy@theboothpulse.com and we will delete it promptly.
17. Changes to this policy
We may update this policy as the Service evolves. For material changes, we will notify you by email or an in-app notice at least 14 days before the change takes effect, and we will always update the “Last updated” date at the top of this page. Continued use of the Service after a change takes effect means you accept the updated policy.
18. How to contact us
Privacy questions & requests
Email: privacy@theboothpulse.com
Support: support@theboothpulse.com
General: hello@theboothpulse.com
Mail: The Booth Pulse, 1370 Shady Knoll Ct, Longwood, Florida, USA