Privacy Policy
Version 1.0.0 · Effective August 2, 2026
HeartLedge is operated by Pulse ROI, LLC, a Texas limited liability company ("Pulse ROI," "we," "us"). This policy explains what we collect, who we share it with, how long we keep it, and how to reach us.
Coaches and organization owners are our customers. Their clients use HeartLedge because their coach does, and for client information the coach decides what is collected and why.
If you are a client and you want a copy of your information, want it corrected, or want it deleted, contact your coach. We act on the coach's instructions.
1. What we collect
From coaches: an email address and password, and the details needed to run a practice on HeartLedge: practice name (which sets a permanent public URL), timezone, currency, optional branding and public profile, subscription status, and the identifiers linking the account to Stripe. Bank details stay with Stripe.
From and about clients: contact details, intake form answers, session records, session notes written by the coach, messages with the coach, and booking and purchase history. Intake forms are written by the coach and we do not review them. Because of what coaching involves, answers and notes can contain sensitive personal information, including health adjacent, emotional, or financial details. Coaches are responsible for obtaining any consent their clients need to give before that information is stored here.
Payments: the amount, currency, status, date, and Stripe reference for each payment and refund, including failed attempts. We never see or store card numbers. Stripe collects card details on its own pages.
Security and technical: a log of sign ins, failed attempts, and lockouts, including the IP address of the request; a record of significant actions taken in an account; and error diagnostics configured to exclude personal information where possible. We collect and retain the IP address associated with a request for account security, to detect and prevent abuse, and to evidence agreement to the Terms of Service.
Cookies: essential cookies only. One keeps you signed in, and one is a short-lived security token used when a coach connects a Stripe account. On pages where you enter card details, Stripe sets its own cookies to prevent fraud. Analytics on our public pages are cookieless. We use no advertising, marketing, or cross site tracking of any kind, which is why you do not see a cookie banner.
2. How we use it
To run coach accounts and client portals; to deliver the features coaches use (offers, intake, scheduling, notes, messaging, payments); to send transactional email such as verification, sign in links, receipts, and booking confirmations and reminders; to take subscription payments and keep the financial records we are required to keep; to keep the Service secure and diagnose errors; and to comply with law.
We do not sell personal information or share it for advertising. We do not send unsolicited marketing email to clients. We may occasionally send product updates to coaches, who can opt out at any time. We do not use client personal information to train machine learning models.
3. Who we share it with
We share information with service providers who help us run HeartLedge, each limited to that purpose. These include our hosting and encrypted backup provider (located in the European Union), our payment processor, our transactional email provider, our error monitoring provider, and a cookieless analytics provider for our public pages. We also use a private email service for our own mailboxes.
If we add a new category of service provider that handles personal information, we will update this policy promptly.
We may also disclose information where required by law or legal process, to protect our rights or someone's safety, or in connection with a merger, financing, or sale of the HeartLedge business, including a possible spin out of HeartLedge into its own company. A successor will treat transferred information in accordance with this policy until it provides notice of any changes.
4. Where it is stored
Our servers and backups are hosted in the European Union (Hetzner, in Germany). Pulse ROI, LLC is a United States company, and several of our service providers, including our payment processor (Stripe) and transactional email provider, are based in the United States, so information moves between the two regions in normal operation. HeartLedge is offered from the US and aimed at coaches operating in the US. Coaches serving clients in the EEA or UK are responsible for their own obligations there and should contact us before relying on HeartLedge for that purpose.
5. How long we keep it
While an organization is active, we keep what is in it. Coaches can delete client records and export their whole organization at any time.
When an owner deletes an organization: it is deactivated immediately, a 30 day grace period runs during which signing in and confirming restores everything, and after that we permanently purge clients, intake responses, sessions, notes, messages, offers, purchases, and branding.
Three things survive the purge:
- Minimal financial records (amount, currency, status, Stripe reference, date), kept 7 years for tax and accounting, linked only to the organization's name and deletion dates and built so they cannot rebuild any practice or client data.
- Security and audit logs, kept for up to 7 years with the organization reference removed.
- The owner's basic user record (email and hashed password). To have this erased, email questions@heartledge.com and we will delete it where we are not required to keep it.
Backups run daily on a 30 day rolling retention, so purged data ages out within about 30 days. After the purge date, we do not use backups to restore deleted data except where required by law or legal process. Stripe keeps its own records under its own terms.
In setting how long we keep information, we weigh the sensitivity of the information, the purpose we collected it for, applicable legal and tax requirements, and whether we can meet that purpose another way. This is why the security and audit logs and minimal financial records above are kept longer than practice and client data.
6. How we protect it
We use commercially reasonable safeguards to protect information, including encryption in transit on all public endpoints, hashed passwords, sign in lockout, and access controls that scope each organization’s data so one organization cannot reach another's. Administrative access is limited and the database is not reachable from the public internet. We monitor availability, log errors, and test our backups periodically.
What we do not claim. We hold no SOC 2, ISO 27001, HIPAA, or PCI attestation. HeartLedge is not designed for information subject to HIPAA and we do not sign business associate agreements. Card data never reaches our servers. No system is completely secure, and we cannot guarantee information will never be accessed without authorization. Our liability in connection with the Service is governed by the HeartLedge Terms of Service. If we determine that a breach has resulted in unauthorized access to personal information that poses a real risk of harm, we will notify affected coaches without undue delay and give them what they need to notify their own clients.
7. Your choices
Coaches can view and correct account details, export the organization's full data, delete individual client records, cancel, and delete the entire organization, all from inside the Service. For anything else, including the surviving user record above, email questions@heartledge.com.
Clients should contact their coach, who holds the tools to view, correct, export, and delete their information. If your coach is unresponsive, you may email questions@heartledge.com and we will make reasonable efforts to assist.
Where a privacy law applicable to our processing of your information gives you rights we are required to honor, email questions@heartledge.com and we will respond within the time that law requires.
We only send transactional email that is part of the Service, so there is no marketing list to leave.
8. Children
HeartLedge is built for adults. Coaches and clients must be 18 or older to use it on their own behalf; a parent or legal guardian may book for a minor and is responsible for that use. We do not knowingly collect information from anyone under 18 without parental or guardian involvement, and we do not knowingly collect information from children under 13 at all. If you believe we have, email questions@heartledge.com and we will delete it.
9. Health and medical information
Coaching is not therapy, counselling, or medical treatment, and coaches using HeartLedge are not acting as licensed therapists, psychologists, physicians, or other healthcare providers. Pulse ROI, LLC is not a “covered entity” or a “business associate” as those terms are defined under the Health Insurance Portability and Accountability Act (“HIPAA”), HeartLedge is not designed for information subject to HIPAA, and we do not sign business associate agreements. We do not ask for, and do not intentionally collect, “protected health information” as defined under HIPAA. While intake answers and session notes written by a coach may contain health adjacent details, coaches are responsible for not storing information that requires HIPAA protection and for obtaining any consent their clients need before storing sensitive information here.
10. Third-party sites and services
HeartLedge relies on third-party services such as Stripe, and our pages and communications may contain links to websites or applications we do not control. We are not responsible for the privacy practices or content of those third-party sites and services, and this policy does not apply to them. We encourage you to read the privacy policy of any third-party site or service before providing personal information to it. Any information you provide to a third party is governed by that party’s own terms and privacy practices.
11. Changes and contact
We may update this policy. Each version carries a version number, an effective date, and the revision history below, and the current version is always at https://heartledge.com/privacy. We will notify coaches by email or in product at least 14 days before a material change takes effect, unless the change is required by law or necessary to address a security concern, in which case it may take effect sooner. Continued use of the Service after an updated policy takes effect constitutes acceptance of the updated policy.
Pulse ROI, LLC (HeartLedge), a Texas limited liability company
Privacy and legal: questions@heartledge.com
Product support: support@heartledge.com