Back to Tools
SendPulse logo

SendPulse

Partially Compliant

Multichannel marketing platform covering email, SMS, chatbots, CRM and courses, operated by SendPulse Inc. of New York despite its Ukrainian engineering roots.

πŸ‡ΊπŸ‡ΈUnited StatesNon-EU Β· United States

Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.

Freemium
SendPulse website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryUnited States
OwnershipNon-European
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
Unknown
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
High Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

Listed as United States, not Ukraine. The source map places SendPulse under Ukraine and its engineering heritage is genuinely Ukrainian, but the privacy policy read 2026-09-01 is unambiguous about the entity: "When we say 'we,' 'us', 'our,' and 'SendPulse,' we are referring to SendPulse Inc., 220 E 23rd St #401, New York, NY 10010." A New York corporation, so ownershipOrigin NON_EU and exposure US_CLOUD_ACT. Credit where due: the policy commits to GDPR rights in specific terms, including access under Article 15 within 30 days and correction, amendment or deletion on request, and it extends those rights explicitly to the customer's subscribers rather than only to the account holder, which many vendors do not. What is absent is everything this directory rates hosting on: no server location is stated anywhere in the privacy policy or on the security page, which describes redundancy and daily backups without a geography; no sub-processor list; no DPA at a public URL. Hence hosting UNKNOWN and Schrems II risk HIGH. The policy also covers Google API and Gmail data under Google's Limited Use requirements, indicating the product reaches into connected mailboxes.

About SendPulse

Very Broad, at a Low Price

SendPulse covers more ground than almost anything else in this directory, and does it cheaply. Email marketing and SMTP, SMS, web push, a chatbot builder spanning Telegram, WhatsApp, Instagram and Facebook Messenger, a free CRM, landing pages, and a platform for selling online courses.

For a solo founder or a small team that would otherwise be paying for four tools, the breadth is the entire argument, and it is a good one. The trade-off is the usual one: none of the individual modules is as deep as a specialist, and the CRM in particular is basic next to Pipedrive or Teamleader.

On the Country

The source map lists SendPulse under Ukraine. The engineering heritage is genuinely Ukrainian and the company is well known there.

The operating entity is not. From sendpulse.com/legal/pp:

When we say "we," "us", "our," and "SendPulse," we are referring to SendPulse Inc., 220 E 23rd St #401, New York, NY 10010.

A New York corporation. So this directory lists SendPulse as United States. That is not a judgement about the product or the people who build it, and this site lists non-European software all the time. It is simply what the privacy policy says the entity is, and it decides who can be compelled to hand over your subscriber list.

What the Documents Do and Do Not Say

The privacy policy commits to GDPR rights in specific terms: access under Article 15 within 30 days, correction, amendment and deletion on request from you or from any of your subscribers, at no charge, unless prohibited by law. Extending those rights explicitly to your subscribers rather than only to the account holder is better than a lot of vendors manage.

What it does not contain is a hosting region. There is no statement of where servers are, no sub-processor list, and no DPA at a public URL. The security page describes redundancy and daily backups without saying where any of it sits. The policy also covers Google API and Gmail data handling under Google's Limited Use requirements, which tells you the product reaches into connected mailboxes.

Combined with US incorporation, that puts this row at PARTIAL with hosting UNKNOWN and US CLOUD Act exposure.

Where It Fits

If breadth at a low price is what you need and jurisdiction is not the binding constraint, SendPulse is hard to beat on value. If you want the same shape from an EU-registered company, Yespo is the closest comparison and names its hosting down to the city, and Brevo covers email, SMS and CRM from France. See email marketing.

Key Features

Email campaigns and SMTP sending
SMS and web push notifications
Chatbots for Telegram, WhatsApp, Instagram and Facebook Messenger
Free CRM
Landing page builder
Online course platform
Marketing automation flows
Generous free tier across several modules

Pros & Cons

Exceptional breadth for the price: email, SMS, push, chatbots, CRM, pages and courses
Free tier that covers real usage rather than acting as a demo
Extends GDPR access and deletion rights explicitly to your subscribers, not just to you
Chatbot coverage across four messaging platforms in one builder
Replaces several separate subscriptions for a small team
SendPulse Inc. is a New York corporation, not a Ukrainian or European company
No server location stated anywhere in the privacy policy or on the security page
No sub-processor list or DPA located at a public URL
Individual modules are shallower than specialist tools, especially the CRM
Reaches into connected Gmail mailboxes under Google's Limited Use terms

SendPulse GDPR & data protection: common questions

Is SendPulse GDPR compliant?

Partly. SendPulse meets some of the requirements, with caveats worth reading before you commit. SendPulse is based in United States, outside the EU/EEA.

Where does SendPulse store data?

We could not locate a clear statement of where SendPulse hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.

Does SendPulse offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for SendPulse. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover β†’

Is SendPulse a European company?

No. SendPulse is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.

Is SendPulse subject to the US CLOUD Act?

Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.

Schrems II compliance checklist β†’

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at SendPulse and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.