Privacy Policy
Last updated: June 1, 2026
Owner and data controller
SimplyPintastic dba PIN Hacking ("us", "we", or "our") operates https://app.pinhacking.com (the "Site" or "Service").
Contact email: info@laurarike.com
We are committed to protecting and respecting your privacy. This Site collects some personal data from its users. This Privacy Policy informs you of our views, practices, and policies regarding the collection, use, and disclosure of personal data we receive from users of the Service. By submitting personal data to us, you agree to us using your personal data as described below.
Information we collect
- Account data: name, email address, password hash, and any profile details you add.
- Billing data: processed by Stripe. We receive limited metadata (plan, status, last four digits, billing country) but never your full card number.
- Usage data: pages visited, features used, generation counts, device/browser type, IP address, and timestamps.
- Content you submit: URLs, keywords, briefs, and other inputs you provide to our tools.
- Support communications: messages you send us by email or in-app.
Authentication, payments, and Google connections
- Authentication: we use Lovable Cloud (a managed backend built on Supabase) to store accounts and sessions. Passwords are hashed and salted; we never see them in plain text.
- Payments: Stripe processes all transactions under their own Privacy Policy and PCI-DSS controls.
- Sign in with Google: if you choose to sign in with Google, we receive your basic profile information (name, email address, and profile picture) from the
openid,email, andprofilescopes, and use it only to create and identify your PIN Hacking account.
Google user data we access
PIN Hacking is a Pinterest marketing tool for creators and small businesses. We use a Google Cloud OAuth 2.0 client so you can securely sign in with Google and connect your own Google Search Console and Google Analytics accounts. You choose whether to connect either service, and you can disconnect at any time.
Google Search Console. With the read-only scope https://www.googleapis.com/auth/webmasters.readonly, we access:
- The list of verified sites (properties) in your account, so you can pick which one to analyze.
- Search Analytics data for the property you select: pages, search queries, clicks, impressions, click-through rate, and average position.
Google Analytics. With the read-only scope https://www.googleapis.com/auth/analytics.readonly, we access:
- The list of GA4 properties you have access to, so you can pick which one to analyze.
- Reporting data for the property you select, such as page paths, sessions, users, traffic sources, and date ranges you request.
How we use it. The app reads your own search and website-traffic data and displays it back to you inside the app, alongside your Pinterest performance. This helps you see which pages and keywords drive traffic, compare this year's performance to last year's, and identify content gaps worth promoting on Pinterest with new pins. Selected pages and keywords you choose to work on may be sent to our content generation providers to draft pin titles, descriptions, and board ideas for you.
Read-only access. We request read-only scopes only. The app never writes to, modifies, or deletes any data in your Google account.
Not sold, not shared, no ads. We do not sell or transfer Google user data to third parties. We do not use it for advertising, retargeting, audience building, or creditworthiness decisions, and we do not use it to train provider models. We share it only with the limited service providers needed to operate the features you request (our managed hosting and database provider, and the content generation provider that produces copy at your request), or when required by law.
Storage and deletion. Your Google access and refresh tokens are stored encrypted and are accessible only to your account. Report results are stored so you can revisit them. Disconnecting Google in Integrations deletes the stored tokens and connected property records. You can also revoke access at any time at myaccount.google.com/permissions. Deleting your PIN Hacking account removes the associated Google data.
Limited Use. PIN Hacking's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Content generation
When you generate pin titles, descriptions, board ideas, or keyword clusters, your inputs (URLs, keywords, briefs) are sent to our content generation service and its model providers for the sole purpose of returning a result to you.
- We do not use your prompts or outputs to train provider models.
- We retain generation history in your account so you can revisit past sessions. You can delete sessions at any time from inside the app.
- Our model providers may log requests transiently for abuse monitoring per their own policies.
Cookies and similar technologies
We use essential cookies for authentication and session management, and limited analytics cookies to understand product usage. You can block cookies in your browser, but parts of the app will not function without them.
How we use information
- To provide, maintain, and improve the Service.
- To process subscriptions, trials, and renewals.
- To send transactional email (receipts, trial reminders, security alerts).
- To respond to support requests.
- To detect, prevent, and address abuse, fraud, or security issues.
- To comply with legal obligations.
Sharing and subprocessors
We share personal data only with vendors that help us run the Service:
- Lovable Cloud (managed backend, hosting, database, auth)
- Stripe (payments)
- Content generation providers (generation requests)
- Email and CRM providers (transactional messages, support)
- Analytics providers (aggregate product usage)
- Google (only the data you authorize through OAuth)
We do not sell personal data. We may disclose data when required by law, court order, or to protect our rights and users.
Data retention and deletion
We retain account and content data for as long as your account is active. On account closure, we delete or anonymize personal data within 60 days, except where retention is required for legal, tax, or fraud-prevention reasons. You can request deletion at any time by emailing info@laurarike.com.
Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, contact info@laurarike.com. We respond within 30 days.
International transfers
We operate from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US and other countries where our subprocessors operate.
Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact info@laurarike.com and we will delete it.
Security
We use industry-standard safeguards including encryption in transit (TLS), encryption at rest for sensitive fields, hashed passwords, row-level security on tenant data, and least-privilege access controls. No system is perfectly secure; please use a strong, unique password and keep it private.
Changes to this policy
We may update this policy as the Service evolves. We will update the "Last updated" date above and, for material changes, notify you by email or in-app banner.
Contact
Questions about this policy? Email info@laurarike.com.