How it worksFeaturesWhy pinndBrandingPricingFAQSign inStart free
← Back to home

Privacy

Privacy Policy

How pinnd handles personal data, including account information, project feedback, payment data processed by Stripe, analytics and cookies.

Effective date: 3 June 2026

1. Overview

This Privacy Policy explains how pinnd collects, uses, stores and protects personal data when you visit our website, create an account, use the app, receive or leave feedback, subscribe to a paid plan, or contact us.

We aim to collect only the information we need to provide, secure, support and improve pinnd.

2. Information we collect

Account information, such as your name, email address, organisation name, login details and plan information.

Project and feedback information, such as uploaded images, shared links, annotations, comments, voice notes, colour references, font references and related metadata that you or your collaborators add to pinnd.

Billing information, such as subscription plan, invoice status, billing address, tax details, payment method type and limited card details such as brand and last four digits where provided by Stripe. We do not store full card numbers.

Technical information, such as IP address, device type, browser type, operating system, pages viewed, referring URLs, timestamps, app events, diagnostics and security logs.

Communications information, such as messages you send to us, support requests, survey responses and marketing preferences.

3. How we use information

To provide pinnd, including account access, project hosting, feedback sharing, notifications, collaboration features and customer support.

To process subscriptions, invoices, tax, payment authentication, payment retries, fraud checks and billing support through Stripe.

To secure the service, investigate suspicious activity, prevent abuse, debug issues and maintain service reliability.

To improve the product, understand feature usage, measure website performance and develop new features.

To send service messages, billing notices, security alerts, product updates and marketing communications where permitted. You can opt out of marketing emails at any time.

To comply with legal, accounting, tax, regulatory and contractual obligations.

4. Lawful bases under UK GDPR and EU GDPR

Contract: we process account, project, collaboration and billing information to provide pinnd under our Terms of Service.

Legitimate interests: we process certain technical, usage, support and security information to operate, improve and protect the service, provided those interests are not overridden by your rights.

Consent: we use consent where required for non-essential cookies, certain analytics and marketing communications.

Legal obligation: we process information where needed for tax, accounting, regulatory compliance or lawful requests.

5. Payments and Stripe

Payments are handled by Stripe. When you enter payment details, that information is submitted to Stripe and processed under Stripe’s own terms and privacy practices.

We receive payment-related information from Stripe, such as customer ID, subscription status, invoice details, payment status, billing email, billing address, tax information and limited payment method details. This helps us manage subscriptions, provide receipts, handle support and prevent fraud.

We do not intentionally collect or store full credit or debit card numbers, CVC codes or equivalent sensitive payment credentials on pinnd servers.

6. Cookies and similar technologies

We use essential cookies and local storage to provide core functionality, remember choices, keep sessions secure and make the site work properly.

With your consent, we may use analytics or performance cookies to understand how visitors use the website and improve pinnd.

You can accept or decline non-essential cookies using the cookie consent prompt. You can also control cookies through your browser settings, though blocking essential cookies may affect functionality.

7. Sharing personal data

We share personal data only where needed to provide and operate pinnd, comply with the law, protect rights and security, or with your direction.

Service providers may include hosting providers, database providers, authentication tools, email delivery services, analytics tools, support tools and Stripe for payments.

If pinnd is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate protections.

We may disclose information where required by law or where we reasonably believe disclosure is necessary to protect pinnd, users or the public.

8. International transfers

Some service providers may process personal data outside the UK or European Economic Area. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses or equivalent transfer mechanisms.

9. Data retention

We keep personal data for as long as needed to provide pinnd, maintain account records, comply with legal obligations, resolve disputes and enforce agreements.

Project content is generally retained while your account or workspace remains active unless deleted by you or in accordance with our operational policies.

Billing and invoice records may be kept for longer where required for tax, accounting and legal compliance. Backup copies may persist for a limited period before being overwritten or deleted.

10. Security

We use technical and organisational measures designed to protect personal data, including access controls, encryption where appropriate, monitoring and provider security controls.

No online service can be guaranteed completely secure. You are responsible for using strong passwords, keeping credentials confidential and managing access to shared links appropriately.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to or receive a copy of your personal data.

Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect processing that happened before consent was withdrawn.

You may also have the right to complain to your local data protection authority. In the UK, this is the Information Commissioner’s Office.

To exercise privacy rights, contact hello@pinnd.it. We may need to verify your identity before responding.

12. Children

pinnd is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us so we can take appropriate action.

13. Changes to this policy

We may update this Privacy Policy as pinnd, our providers or legal requirements change. The latest version will be posted on this page with an updated effective date.

14. Contact

For privacy questions, data requests or cookie queries, contact hello@pinnd.it.

Last updated June 2026