Privacy Policy
Last updated: August 11, 2026
LaunchPulse is a web analytics product of Basekick Labs LLC, a limited liability company organized in the State of Delaware, United States ("Basekick Labs", "we", "us"). This policy explains what we collect, why, and what we do with it — both for the people who use LaunchPulse ("customers") and for the visitors to the websites our customers measure ("end visitors").
This document describes how the product behaves. It is not legal advice, and it does not determine your own obligations: if you install LaunchPulse on your site, you are the data controller for your visitors' data and remain responsible for your own compliance.
The short version
- We do not sell your data, and we never share it with advertisers.
- We do not track people across other websites. Analytics data belongs to one project.
- End visitors' IP addresses are used only to derive a country, then discarded. We do not store them.
- We do not use advertising identifiers, fingerprinting, or third-party trackers.
- You decide what is sent to us. Do not send us personal data you don't need us to have.
Data we collect from customers
To provide an account we store:
- Account details — your email address, an optional display name, and a hashed password (we never store passwords in plain text). If you sign in with Google or GitHub, we store the identifier that provider gives us.
- Security data — session tokens (stored hashed), and, if you enable them, an encrypted two-factor secret, hashed recovery codes, and registered passkeys.
- Project configuration — project names, website URLs, domains, timezone, and the settings that define your conversion and activation events.
- Billing data — subscription status and renewal dates. Payments are processed by Stripe; we never see or store your full card number.
- Operational logs — an audit record of significant account actions, used for security and support.
Data we collect about end visitors
When you install our tracker, we receive an event for each pageview and for any custom events you choose to send. An event can include:
- Page path and URL, page title context, and referrer
- UTM parameters and the traffic source, medium, and campaign derived from them
- Country, derived from the IP address and then the IP is discarded
- Device type, browser, and operating system
- A random visitor identifier, a session identifier, and — only if you call
identify()— the user identifier you supply - Timestamps, and any custom properties you attach to your own events
We do not receive names, email addresses, or other personal details unless you choose to send
them. Please don't: use an internal user identifier instead. Our SDK warns in the browser
console if the value passed to identify() looks like an email address.
Cookies
Our tracker sets one first-party cookie, _lp_vid, on the customer's own domain.
It holds a random visitor identifier, a session identifier, and the first traffic source
that brought the visitor to the site. It lasts 30 days, uses SameSite=Lax, and
is marked Secure on HTTPS sites.
We do not use third-party cookies and we do not use this cookie to track anyone across other websites. Because it is still a cookie, cookie-consent obligations may apply in your jurisdiction — as the site owner, that decision and any required consent banner are yours.
How we use data
We use the data described above only to:
- Provide the analytics dashboards, insights, alerts, and reports you asked for
- Send transactional email you have asked for or need — verification, alerts, weekly digests (each with an unsubscribe link), and billing notices
- Keep accounts secure, prevent abuse, and enforce rate limits
- Bill for the service
- Diagnose and fix problems
We do not profile end visitors for advertising, and we do not use your analytics data to train models.
Who we share data with
We share data only with the service providers needed to run LaunchPulse:
- Stripe — payment processing and subscription management
- Mailgun — transactional and digest email delivery
- Our hosting and infrastructure providers — running the service
- Cloudflare — bot protection on sign-up and sign-in, where enabled
We may also disclose data where we are legally required to, or where necessary to protect our rights, our users, or the public. If LaunchPulse is ever involved in a merger or acquisition, we will give notice before your data becomes subject to a different privacy policy.
Retention
- Analytics events are retained while your project exists. Deleting a project removes it from the app; the underlying analytics data is retained on our side unless you ask us to delete it.
- Alert history is automatically deleted after 90 days.
- Account data is retained while your account is open. Ask us to close it and we will delete or anonymize your account data, subject to any records we must keep for legal or accounting reasons.
Security
Passwords are hashed with argon2id and two-factor secrets are encrypted at rest. Session and API tokens are stored only as hashes. Traffic is served over HTTPS. Access to production data is restricted to the people who need it to operate the service. No system is perfectly secure, but we take these safeguards seriously and will notify affected customers promptly if a breach materially affects their data.
Your choices and rights
- Access and export — your analytics data is visible in your dashboards, and the events log can be exported as CSV.
- Correction and deletion — edit your account details in the app, or email us to request deletion.
- Email preferences — every weekly digest includes an unsubscribe link. Transactional messages (security, billing) cannot be turned off while your account is open.
- End visitors — a visitor's identifiers can be cleared and rotated at any time by calling
lp.reset()in your application, for example on logout.
Depending on where you live, you may have additional rights over your personal data. Email us and we will honour applicable requests. If you are an end visitor of a site that uses LaunchPulse, please contact that site's owner first — they control the data and we act on their behalf.
International transfers
LaunchPulse is operated from, and processes data in, the infrastructure regions we use to run the service, which may be outside your country. By using LaunchPulse you consent to that processing.
Children
LaunchPulse is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as the product evolves. The "last updated" date at the top always reflects the current version, and we will notify customers by email of material changes.
Contact
Questions about privacy, or a request about your data? Email hello@launchpulse.dev.
For a technical explanation of exactly what the tracker collects, see the privacy page in our documentation and the data model reference.
Basekick Labs LLC · Delaware, United States