Privacy Policy
The honest, readable version of what data Pogpin touches, why we touch it, and the controls you have over it. No dark patterns, no buried clauses.
This policy explains how Pogpin (“we”, “us”, “our”) handles personal data across our website and the Pogpin product. We’ve tried to keep it in plain English; the grey boxes are the human translation of each section. If anything is unclear, just ask us.
Who we are
Pogpin is a visual-feedback tool: people drop pinned comments directly onto a live web page, and each pin captures the context a team needs to reproduce the issue. We are the data controller for the information described here. You can reach us any time at hello@pogpin.com.
What we collect
We group data by why it exists, not by how scary the label sounds:
- Account data — when you sign up: name, email, password hash, and workspace/role. Guests leaving feedback don’t need an account, so we don’t ask for one.
- Feedback context — the heart of the product. For each pin we record the browser, operating system, screen size, page URL and the exact element you clicked, plus your comment text and any attachments you add.
- Billing data — if you’re on a paid plan, our payment processor handles your card. We store the subscription status and invoices, never the full card number.
- Usage & device data — basic logs, IP address and product analytics events so we can keep the lights on, fix bugs and understand what’s used.
- Messages — anything you send us by email, the contact form or the newsletter signup.
In plain English: a pin captures “what you were looking at” so “it’s broken on my screen” turns into something your team can actually reproduce — not your personal life story.
How we use it
We use data to:
- run the core product — store, route and display your pins and comments;
- authenticate you and keep your workspace secure;
- process payments and send receipts;
- provide support and reply when you write to us;
- improve the product through aggregate, de-identified analytics;
- send service and (if you opt in) occasional product emails.
We do not sell personal data, and we don’t use your feedback content to train third-party advertising models.
Legal bases (GDPR)
If you’re in the EEA or UK, we rely on these lawful bases:
- Contract — to deliver the service you signed up for.
- Legitimate interests — to secure, maintain and improve the product, balanced against your rights.
- Consent — for marketing emails and non-essential cookies, which you can withdraw anytime.
- Legal obligation — to meet tax, accounting and compliance duties.
Who we share it with
We share data only with vetted sub-processors who help us run Pogpin, under contracts that bind them to protect it:
- Hosting & infrastructure — to store and serve the app.
- Payment processing — to handle subscriptions securely.
- Email delivery — for transactional and opt-in emails.
- Product analytics & error monitoring — to spot and fix problems.
- Integrations you connect — Slack, Linear, Jira, GitHub, Figma, Zapier and webhooks only receive data when you switch them on.
In plain English: the only outside tools that see your data are the ones we need to run the service — and the integrations you deliberately turn on.
Cookies & analytics
We use essential cookies to keep you signed in and the app working. We use a light layer of privacy-respecting analytics to understand usage in aggregate. You can refuse non-essential cookies through your browser or our cookie controls without losing core functionality.
How long we keep it
We keep personal data only as long as your account is active or as needed to provide the service, then delete or anonymise it. Billing records are retained as long as the law requires. Delete your workspace and we remove the associated content on a rolling schedule, save for backups that age out.
Your rights
Depending on where you live, you can:
- access a copy of your data;
- correct anything inaccurate;
- delete your data (“right to be forgotten”);
- export your data in a portable format;
- object to or restrict certain processing;
- withdraw consent at any time.
Email hello@pogpin.com and a real person will action it. We won’t make you fill out a maze of forms.
How we protect it
Data is encrypted in transit and at rest. Access is scoped by role and limited to the people who need it to operate the service. No system is perfect, but we treat your data the way we’d want ours treated — and we’ll tell you promptly if something ever goes wrong.
International transfers
We may process data in countries other than yours. When we move personal data out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.
Children
Pogpin isn’t built for children. We don’t knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we’ll remove it.
Changes to this policy
If we make a meaningful change, we’ll update the date at the top and, for significant updates, let you know in-app or by email. Continuing to use Pogpin after a change means you accept the revised policy.
Talk to a human
Privacy questions, requests, or just a “wait, what does this mean?” — email hello@pogpin.com. We read every message.
Where feedback finally finds its place.
Drop your first pin in under a minute. Bring your team, your clients and your live site — Pogpin handles the rest.
Free forever for solo work · No credit card required