Last updated · May 2, 2026
Privacy Policy
This policy applies to every service offered by Pingine — websites, applications, and APIs that link to this document. We collect the minimum we need to operate the Services and explain in detail what data we process, on what legal bases, and how you can control it.
Who we are and the data controller
“Pingine”, “we”, or “us” in this document refers to the operator of all services published under the Pingine brand (the “Services”). The Services include websites, web and mobile applications, APIs, SDKs, and integrations published under the Pingine brand and linking to this policy. Individual Services may add narrower provisions in their own documents, but this policy remains the baseline for all of them. For any data-protection question, to exercise data-subject rights, or to reach the person responsible for data protection, contact us at the address listed at the end of this document.
Scope
This policy applies to every category of user: visitors to our websites, holders of accounts in the Services, end users of third-party applications who sign in through Pingine, and administrators or developers using our APIs. If you use the Services as an employee of a customer organization, that organization is the controller of your personal data and Pingine acts as a processor on its behalf — in that case, the contract between Pingine and the organization governs, and this policy describes the technical and organizational measures we apply.
What we collect
We collect only the data we need to operate the Services. Account and identity: email address, password hash, display name, locale preferences, multi-factor authentication factors (including TOTP secrets and backup codes), linked external identifiers (for example, when you sign in through third-party providers), and the list of active sessions and devices. Service usage: the requests and responses you submit, saved projects, files and settings, and an audit trail of actions inside the Services. Technical and operational metadata: IP address, user agent, device identifier, browser and OS type, timestamps, session and trace identifiers, security logs, error logs, and performance metrics. Payment data (where applicable): subscription type, payment history, and invoices. We do not store full card details — they are handled by a certified payment provider. Communications: support tickets, feedback, and data-subject requests.
Why we collect it and our legal bases
We use this data for the following purposes and on the following legal bases (as defined by GDPR and similar regimes): performance of a contract — providing the Services, authentication, OAuth authorization, customer support, billing; legitimate interests — securing the Services and preventing abuse, incident diagnostics, fraud protection, and aggregated analytics to improve our products; legal obligations — tax records, responding to lawful requests by public authorities, and complying with applicable law; consent — for specific optional features (for example, marketing emails, advanced analytics, optional cookies), which you can withdraw at any time. We do not sell your personal data to third parties, do not share it with advertising brokers, and do not use it to build advertising profiles.
International transfers
Pingine may process data on servers located in different countries, including outside your country of residence. Where applicable law requires additional safeguards for cross-border transfers (for example, GDPR), we rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent mechanisms, conduct transfer risk assessments, and apply additional technical measures (encryption in transit and at rest, data minimization).
Retention
Retention depends on the category of data. Account data is kept for as long as your account is active, plus a limited period after deletion needed to settle outstanding obligations. Security and authentication logs — typically up to 12 months. Error and observability logs — typically up to 90 days. Service content (for example, your projects and files) — until you delete it or while your subscription is active. Payment records — for the period required by tax law. Backups are purged on a rolling schedule, generally within 30 days after the source data is deleted. When you delete your account, we delete or anonymize the related data, except where retention is legally required.
Your rights
Applicable law (including the EU/EEA GDPR, UK GDPR, California CCPA/CPRA, and similar regimes) gives you a number of rights: to access your data and obtain a copy in a machine-readable format (portability), to rectify inaccurate data, to erase data (the “right to be forgotten”), to restrict or object to processing, to withdraw consent where processing is based on it, and to opt out of the sale or sharing of personal information for advertising purposes (we do not engage in such activities). Most actions can be performed in your account settings. If a control is not available, contact us — we respond within the time limits required by law (typically 30 days). If you believe we are violating your rights, you have the right to lodge a complaint with a data-protection supervisory authority in your country of residence.
Automated decisions and profiling
We may use automated rules for security purposes — for example, to detect anomalous logins, suspicious activity, and abuse — which can result in temporary access blocks or additional verification steps. These do not constitute decisions producing legal or similarly significant effects within the meaning of GDPR Article 22; you can always request human intervention and contest the decision by contacting support. We do not use your data for advertising or behavioral profiling.
Children
The Services are not directed to individuals under the age of 16 (or such other age as required by applicable national law). We do not knowingly collect data from such individuals. If you become aware that a child has provided us with data without parental or guardian consent, please contact us and we will delete it.
Security
We apply technical and organizational measures appropriate to the risks of processing, including: TLS encryption in transit, encryption of sensitive data at rest, password hashing with a modern algorithm (bcrypt at strength 12), refresh-token rotation on every use with server-side revocation, support for multi-factor authentication, environment isolation and least-privilege access, access logging and regular reviews, anomaly monitoring, rate limiting on sensitive endpoints, dependency audits and vulnerability scans, and security review for material changes. No system is perfectly secure — we strongly encourage you to enable two-factor authentication and to use unique passwords. We notify users of incidents affecting their data within the time limits required by law.
Changes to this policy
We may update this policy as the Services evolve. We will give reasonable advance notice of material changes — by email, in-product notice, or a banner on the site — before they take effect. The last-updated date appears at the top of this document. An archive of previous versions is available on request.