Pinpinmo Inc. ("Pinpinmo," "we," "us") operates pinpinmo.com and related services. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding it. By using our platform you agree to this policy.
Account information. When you create a buyer or creator account we collect your email address, display name, and encrypted password. Creators additionally provide legal name, address, tax identification number, and banking information through our Stripe Connect onboarding flow.
Order and transaction data. When you purchase a product we collect your shipping address (for physical print-on-demand orders), order details, and payment method metadata. We never store raw card numbers — all payment processing is handled by Stripe, Inc. as our payment processor and co-Merchant of Record. We receive a Stripe payment intent ID, last-four digits, card brand, and billing country.
Usage and device data. We collect browser type, operating system, referring URL, pages visited, and approximate location derived from your IP address. This helps us detect fraud, improve the platform, and diagnose technical problems.
Communications. If you email us, submit a support ticket, or chat with our AI concierge Coco, we retain those messages to resolve your request and improve service quality.
Cookies and local storage. We use a session cookie (ppm_token) for buyer authentication, and localStorage for creator (merchant) sessions. See our Cookie Policy for details.
We share only the minimum data necessary with each sub-processor:
Pinpinmo is an AI-native platform. Most of the content in a creator store — product images, store names, and product descriptions — is generated by our AI system, gmvagent, working on the creator's behalf. Not all of it: creators write and upload their own material too, and the platform's own pages (policies, help articles, and the copy around the stores) are written by us. No personal buyer data is used as input to AI image generation. Creator prompts and configuration preferences may be used to fine-tune generation parameters in aggregate.
We use the Pinterest API. Pinpinmo uses the Pinterest API (v5) to publish product Pins and to supply a product catalog data source. Pins are published from Pinpinmo's own Pinterest business account — one board per creator store, with each Pin linking back to that product's page on pinpinmo.com. The data we send to Pinterest is product data: title, description, price, availability, product image URL, and destination link. We do not send buyer names, email addresses, shipping addresses, order contents, or payment data to Pinterest.
We are not affiliated with, endorsed by, or sponsored by Pinterest. Pinpinmo is an independent platform and is solely responsible for its own services. Pinterest is a trademark of Pinterest, Inc.; our use of the Pinterest API does not imply any sponsorship, endorsement, affiliation, partnership, or approval by Pinterest, Inc. Your own use of Pinterest is governed by Pinterest's Privacy Policy and Terms of Service, not by this policy.
What Pinterest-derived data we hold. Only what the API returns about content we ourselves published: the Pin ID and board ID Pinterest assigns to a Pin we created, the publish timestamp, and any error message Pinterest returned. We do not read, import, or store any Pinterest user's profile, boards, followers, saves, or browsing activity. Referral traffic arriving from Pinterest reaches us as an ordinary HTTP referrer, the same as traffic from any other website. Our Pinterest access credentials are held in our server environment only — they are never written to our database, never written to logs, and never exposed to a browser.
Connecting and disconnecting a Pinterest account. Pinpinmo does not currently ask buyers or creators to connect their personal Pinterest accounts, so there is no end-user Pinterest authorization to revoke today. If we offer that connection in the future, you will be able to disconnect it at any time from your dashboard settings, or by emailing [email protected]. On disconnection we will immediately revoke and delete the stored OAuth access and refresh tokens, stop making any further Pinterest API calls on your behalf, and delete the Pinterest-derived records associated with that connection — including Pin IDs, board IDs, publish timestamps, and any cached Pinterest metadata — within 30 days. Deleting your Pinpinmo account triggers the same deletion. Pins that have already been published live on Pinterest's own service rather than ours; to remove those, delete them from within Pinterest.
No resale, no redistribution, no advertising, no AI training. We do not sell, rent, license, resell, syndicate, or otherwise redistribute Pinterest content or Pinterest-derived data to any third party. We do not use Pinterest data for advertising or ad targeting, we do not combine it with data from other sources to build profiles of individuals, and we do not use it to train, fine-tune, or evaluate AI models. Pinterest-derived data is used solely to operate the publishing and catalog features described above.
The same commitments apply to our other social platform integrations (for example X, Instagram, and TikTok) where a creator chooses to connect one: we request the narrowest scopes needed to publish on their behalf, we do not redistribute platform data to third parties, and we delete platform-derived data on disconnection under the timeline stated above.
Depending on where you live, you may have the following rights under the CCPA (California), GDPR (EU/UK), or similar laws:
To exercise any right, email [email protected] from the address associated with your account. We will respond within 30 days. Identity verification may be required before processing sensitive requests.
Pinpinmo is a US-based company. If you access the platform from outside the United States, your data may be transferred to and processed in the US. Where required by law (e.g., GDPR), we rely on Standard Contractual Clauses or equivalent safeguards for international transfers.
Pinpinmo is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
If you are in the European Economic Area or the United Kingdom, we process your personal data under one or more of the following legal bases under GDPR Article 6:
We protect personal data with encryption in transit (HTTPS/TLS), scoped access controls, hashed credentials, and payment data isolation (raw card data is handled only by Stripe). No system is perfectly secure, but if we become aware of a personal-data breach affecting you, we will notify affected users and, where required, the relevant supervisory authority without undue delay and consistent with applicable law (e.g., GDPR Article 33/34).
We may update this Privacy Policy from time to time. Material changes will be announced via email and a banner on the platform at least 14 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.
Email our Data Privacy team at [email protected]. For general legal questions: [email protected].