Privacy Policy
Vesta's Brand Pulse Tools (Brand Pulse Check and Brand Pulse Monitor)
Last updated: July 7, 2026
We built Vesta's Brand Pulse Tools (Brand Pulse Check and Brand Pulse Monitor) to show you where your brand stands online. Here is what we collect, why we collect it, and how you stay in control.
We do not sell your personal information.
1. Who we are
This policy explains how Coridors Pte. Ltd. ("Coridors", "we", "us"), a company incorporated in Singapore, collects and uses personal information when you use the Vesta website at getvesta.io, the Brand Pulse Check tool at getvesta.io/brand-pulse-check, the Brand Pulse Monitor service (when available), and our marketing and demand generation services. Vesta and Vesta's Brand Pulse Tools (Brand Pulse Check and Brand Pulse Monitor) are brands of Coridors Pte. Ltd. Contact for privacy questions, grievances, and data requests: support@coridors.io.
2. Information we collect
We rely on you to ensure that the personal information you provide to us is accurate, complete, and up-to-date.
Information you give us:
-
The website URL you submit for a scan.
-
Your email address, which we verify with a one-time password (OTP) to unlock your full report and use to deliver your report and service messages.
-
Your WhatsApp/phone number, which is required to unlock the full report; we use it to send your report on WhatsApp and, with your separate consent, marketing messages.
-
Details you provide when booking a call, such as your name, email, and preferred times (collected through our scheduling provider).
-
Account details, if you create a Brand Pulse Monitor account, such as your name, email address, and login credentials, and billing information if you subscribe to a paid plan (payment card details are handled by our payment provider and are not stored by us).
-
Information you share when you become an agency client or contact us, such as business details, briefs, and correspondence.
Information we collect automatically:
-
Usage and device information through analytics tools and cookies, such as pages visited, approximate location, browser, and how you interacted with a report (see Section 7 on cookies).
-
Technical logs needed to run and secure the Services.
Information from public and third-party sources:
- When a URL is scanned, Brand Pulse Check gathers publicly available information about that website and business from sources such as Google PageSpeed Insights, Google Places (including public review data), YouTube, and public Instagram and TikTok pages, and queries AI assistants and large language model platforms such as ChatGPT, Perplexity, and Google AI Overviews to assess how they find and reference your business. This can include business names, addresses, phone numbers, and public review and follower statistics. This information relates to the business, but where the business is a sole trader it may also be personal information.
3. How we use your information
-
To run the scan and show you your Brand Pulse Check report.
-
To verify your email address with a one-time password and deliver your full report and service messages by email.
-
To send you your report on WhatsApp, which is required to unlock the full report.
-
With your separate consent, to send you follow-up messages on WhatsApp, such as your report summary, follow-up recommendations, and information about Vesta services. We will not send more than one message per week, and you can withdraw this consent at any time without affecting access to your report.
-
To schedule and hold strategy calls you book with us.
-
To provide agency services to clients and manage those relationships, including in our CRM.
-
To operate, secure, debug, and improve the Services, including caching scan results and monitoring API usage.
-
To operate Brand Pulse Monitor accounts: running the recurring scans you enable, maintaining your score history and trends, and sending you the alerts you have chosen to receive.
-
To notify you about upcoming products such as Brand Pulse Monitor, where you have asked us to, for example by joining a waitlist.
-
To send marketing communications, where permitted; you can opt out at any time.
-
To comply with legal obligations.
We process personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA), primarily on the basis of your consent, which you give when you verify your email address, provide your WhatsApp/phone number, or submit other details, and on other bases the PDPA recognises. Providing a WhatsApp/phone number is required to unlock the full report, but consent to marketing messages is collected separately from report delivery, and you can withdraw it at any time as described in Section 8. For users in India, we also have regard to the Digital Personal Data Protection Act 2023 (DPDP).
Exclusion for Business Contact Information (BCI): In accordance with the First Schedule of the Singapore Personal Data Protection Act (PDPA) and guidelines issued by the Personal Data Protection Commission (PDPC), this policy does not apply to Business Contact Information (BCI). BCI—such as job titles, business emails, organisation names, and professional telephone or WhatsApp numbers provided to us solely for corporate communications and B2B transactions—is exempt from the data protection provisions of the PDPA.
4. Who we share it with
We do not sell your personal information.
We share it only with:
-
Service providers who help us run the Services, such as hosting providers, our CRM, our WhatsApp Business messaging provider, our scheduling provider, and analytics providers (e.g. Google Analytics). They may only use it to provide services to us.
-
Our payment provider, if you subscribe to a paid plan, for processing payments.
-
Data sources we query to run a scan. When we scan a URL, that URL is sent to the third-party APIs listed in Section 2. Their own privacy policies apply to their processing.
-
Professional advisers and authorities, where required by law or to protect our rights.
-
A buyer or successor, if we sell or restructure our business, in which case this policy will continue to apply to your information.
Data processing and delivery services are provided by our affiliate IO Coridors Pte. Ltd., acting as a data processor on our behalf. We operate from Singapore and India, and some of our service providers (such as hosting, CRM, and analytics providers) may store data in other countries. Where personal data is transferred across borders, we do so in accordance with applicable law, including the Singapore PDPA and, where applicable, India's DPDP Act.
5. Scanned businesses and reports about you
Anyone can run a Brand Pulse Check scan on a publicly accessible website. If someone has scanned your business's website, the resulting report contains only information gathered from public sources at the time of the scan. If you believe a report about your business is inaccurate, or you want information about your business removed from our cached results, contact support@coridors.io and we will review your request.
6. How long we keep information
We keep personal information only as long as needed for the purposes above, then delete or anonymise it. Current retention periods:
| Data | How long we keep it | Why |
|---|---|---|
| Scan results and reports (anonymous teaser) | 7 days | Caching so a repeated scan of the same URL is fast and does not waste API quota |
| Full reports linked to your verified email | 24 months | So you and our team can refer back to your report and track changes |
| Email address, WhatsApp number, and contact details | Until you opt out or ask us to delete them, or after 24 months of inactivity | Report delivery, follow-up, and marketing with your consent |
| CRM records for agency clients and prospects | For the duration of the relationship | Service delivery, accounting, and legal obligations |
| Brand Pulse Monitor account data and score history | For as long as your account is active, then 1 month after account closure | Providing the monitoring service and your trend history |
| Analytics data | Per our analytics provider settings (GA4 default 14 months) | Understanding how the Services are used |
7. Cookies and analytics
We use cookies and similar technologies to keep the Services working (for example, remembering that you have already verified your email so you are not asked to verify again), to measure how the Services are used, and to improve marketing. You can also control cookies through your browser settings, although blocking some cookies may affect how the Services work.
8. Your rights
Depending on where you live, you may have rights to access, correct, update, or delete your personal information, to receive a copy of it, and to withdraw consent (for example, to stop WhatsApp marketing) at any time without affecting access to your report. To exercise any of these rights, contact support@coridors.io. Our Data Protection Officer is Piyush Bhatia, reachable at support@coridors.io; we aim to respond within the timelines required by applicable law. If you are not satisfied, you may complain to Singapore's Personal Data Protection Commission (PDPC) or, for users in India, the authority designated under the DPDP Act.
9. Security
We use appropriate technical and organisational measures to protect personal information, including access controls and encryption in transit. No system is completely secure, and we cannot guarantee absolute security.
10. Children
The Services are intended for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us personal information, contact support@coridors.io and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The current version, with its "last updated" date, will always be available on our website. Material changes will be highlighted where reasonably practical.
12. Contact
Privacy questions, grievances, complaints, or data requests: support@coridors.io, or write to Coridors Pte. Ltd. Data Protection Officer: Piyush Bhatia, support@coridors.io.