Legal

Privacy Policy

Effective date: Last updated:

This policy explains what personal data BatchPin collects, why we collect it, how we handle data obtained through the Pinterest API, and the choices you have. It applies to our website, our web application, and any account you connect to the service.

1. Who we are

BatchPin ("we", "us") operates the Pinterest scheduling and automation service described at this website. For the purposes of the UK GDPR and EU GDPR, we act as the data controller for account data and as a processor for content you instruct us to publish on your behalf.

Legal entityYassine Bouchama, sole trader
Registered address21 Rue Jbala, Quartier Nahj El Amir, Morocco
Privacy contact[email protected]

2. Data we collect

Account data. Name, email address, password hash, workspace settings, plan and credit balance.

Connected account data. OAuth access and refresh tokens for Pinterest, your Pinterest username and profile ID, and the list of boards on the connected profile.

Source content. Public page content we fetch from the website, shop or app listing URL you supply: titles, text excerpts, images and product metadata.

Generated content. Pin images, titles, descriptions, alt text and board assignments produced by the service, plus the schedule attached to each pin.

Performance data. Aggregate impression, save, click and publish-status metrics returned by Pinterest for pins created through the service.

Technical and billing data. IP address, browser and device type, log timestamps, error traces, and payment records held by our payment provider. We do not store full card numbers.

3. Pinterest data and API use

When you connect a Pinterest profile, you authorise us through Pinterest's OAuth flow. We never see or store your Pinterest password. Access is limited to the scopes you approve, which are the minimum needed to read your boards and to create, schedule and report on pins.

You can revoke our access at any time from within the app, or from your Pinterest account settings under connected apps. Revoking access stops all scheduled publishing to that profile immediately.

What we hold locally, and for how long

We are specific about this because Pinterest's Developer Guidelines are specific about it — see how this policy measures against them below.

Pinterest dataWhere it livesWhy
Access and refresh tokensOur database, encryptedRequired to publish on your behalf without asking you to reauthorise each time
Profile ID and usernameOur databaseIdentifies which account a campaign publishes to
Board name, description, privacy, pin countNot stored. Read from the Pinterest API when needed, held in a short-lived cache for at most 10 minutesBoard routing scores a pin's keywords against your board descriptions at generation time
Board keyword indexNot stored. Computed in memory from the name and description above, discarded after useRouting only
Which board we published a pin toOur databaseOur own record of a decision we made, not a copy of Pinterest's data
Pin performance metricsOur databaseCampaign analytics for pins this service created
Your Pinterest home feed, other people's pins, follower listsNever requestedNot needed for anything the service does

4. How this policy measures against Pinterest's Developer Guidelines

Pinterest requires every developer using its API to hold a privacy policy consistent with applicable law, and to link that policy when applying for API access. Its Developer Guidelines — the version effective 18 August 2026 — set specific obligations beyond that. This table states each one and what we actually do, including where we do not yet meet it.

Pinterest requiresWhat BatchPin doesStatus
Only access an account with authorisation, e.g. an access tokenOAuth 2.0 only. No password is ever requested or stored.Meets
Do not solicit or collect login credentialsWe never ask for Pinterest credentials, on any screen.Meets
Only use account information to provide services to that personPinterest data is scoped to the workspace that connected it and used only to generate, route and publish that workspace's pins.Meets
Do not combine one person's account information with another's, or with other servicesBoard and pin data are partitioned per connection; nothing is pooled across workspaces.Meets
Keep API credentials private; do not share themApp credentials are server-side only. User tokens are AES-GCM encrypted and never returned by any endpoint.Meets
Do not share or sell API information with third partiesWe do not. AI generation requests carry source content only — no Pinterest identifiers.Meets
Do not use API information to target advertising outside PinterestWe run no advertising and build no advertising profiles.Meets
No automated scraping of PinterestAll Pinterest access is through the documented API. Our scrapers read your source site, never Pinterest.Meets
Be honest and transparent with end users about what the service doesThis policy, and the table above stating exactly what is cached.Meets
Have a privacy policy consistent with applicable law, linked at API applicationThis page.Meets
Do not automatically initiate actions without specifically considering each one — the person chooses each individual pinGeneration stops at a draft. Every pin is approved individually before it is scheduled, and nothing is ever published that you have not approved. Approving several selected pins at once still records a decision per pin.Meets
Store no information accessed through the API, other than campaign analytics about your own account — call the API each time insteadBoard content is read from the API when it is needed and never written to our database. A short-lived cache holds a board listing for at most 10 minutes so that generating a batch of pins is one API call rather than one per pin. Pin performance metrics are stored under the campaign-analytics exception.Meets

None of this changes the commitments in the previous section: board data, cached or not, is never sold, never shared, never used for advertising, and never combined across accounts.

5. How we use data

  • To create pins from your source content and publish them to the boards you or the automatic router select.
  • To generate titles, descriptions, alt text and pin imagery through our AI providers.
  • To schedule publishing and report on the results in your dashboard.
  • To operate accounts, apply plan limits and process payments.
  • To provide support, investigate failures and prevent abuse of the service.
  • To send service notices such as batch-ready and failed-publish emails.

Text and image prompts may be sent to third-party AI providers to generate pin content. We send only the source content needed for generation, and no Pinterest account identifiers.

Our AI providers do not train on your content. We use their standard business API, where training on submitted data is off unless the customer opts in, and we have not opted in. Our provider retains prompts and responses for a short period — currently up to 30 days — for abuse monitoring, after which they are deleted. We do not use your content to train any model of our own.

7. Sharing and subprocessors

We share data only with service providers who process it on our instructions under written agreements: cloud hosting and storage, our payment processor, transactional email delivery, error monitoring, and the AI providers that generate pin text and imagery. We also disclose data where required by law or to protect our rights. We do not sell personal data.

A current list of subprocessors is available on request at [email protected].

8. Retention and deletion

  • Pinterest access tokens are deleted immediately when you disconnect a profile or delete your account.
  • Cached board listings expire within 10 minutes on their own, and are dropped immediately when you disconnect a profile.
  • Pins, campaigns and generated content are deleted within 30 days of account deletion.
  • Cached source content and analytics are deleted within 90 days of the campaign being removed.
  • Backups roll off within 35 days.
  • Invoices and tax records are kept for the period required by law.

To request deletion, use the delete-account control in Settings or email us. Deleting your BatchPin account does not delete pins already published to Pinterest — those live on your Pinterest profile and you can remove them there.

9. Security

Traffic between your browser, our application and our API is served over TLS.

OAuth tokens are encrypted before they are written to our database. Each Pinterest, Etsy and Shopify token is sealed with AES-256-GCM under a key that lives in server configuration and never in the database. GCM authenticates as well as encrypts, so a token that has been altered fails to decrypt rather than decrypting into something that looks plausible. No endpoint of ours returns a token in any form, encrypted or otherwise.

Account passwords are stored only as Argon2id hashes. We cannot read your password, and neither can anyone who obtains a copy of our database. Our own application credentials for Pinterest and the other integrations are held server-side and are never sent to a browser.

The service is operated by one person, and access to the production systems that hold your data is limited to that person.

If a breach affects your personal data we will notify affected users without undue delay, and the relevant supervisory authority where the law requires it — within 72 hours of becoming aware, where the GDPR applies.

10. Cookies and tracking

We run no analytics, no advertising pixels and no third-party tracking of any kind. There is no Google Analytics, no tag manager, no advertising network and no session-recording tool on this site. Nothing here reports your visit to anyone else.

Because of that, browsing the public site — the home page, pricing, the blog, the free tools — sets no cookies at all. There is no consent banner because there is nothing to consent to.

Signing in sets two first-party cookies, and only these two:

CookiePurposeLifetime
pinflow_sessionKeeps you signed in. Issued and signed by our API, marked HttpOnly and SameSite=Lax, and sent over HTTPS only in production. JavaScript cannot read it.Until it expires or you sign out
pinflow_campaignRemembers which campaign you were last looking at, so the dashboard opens where you left it.Until you clear it

Both are strictly necessary or preference cookies under the ePrivacy rules, neither is used to profile you, and neither is shared with anybody. Clearing them signs you out and resets the dashboard to its default view; nothing else is affected.

The free tools run entirely in your browser. The pin size checker in particular never uploads your image — it is measured locally and no request leaves your device.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to withdraw consent. Residents of California may request disclosure of the categories of data collected and opt out of any sale of personal information; we do not sell personal information.

Email [email protected] to exercise any right. We respond within 30 days. You may also complain to your local supervisory authority.

12. International transfers

Our providers may process data outside your country, including in the United States. Where required, transfers rely on Standard Contractual Clauses or another approved safeguard.

13. Children

The service is not directed to anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

We update this policy as the service changes. Material changes are announced by email or in the app at least 14 days before they take effect. The date at the top of this page always reflects the current version.

15. Contact

Privacy enquiries[email protected]
Data deletion requests[email protected]
PostalYassine Bouchama, sole trader, 21 Rue Jbala, Quartier Nahj El Amir, Morocco

BatchPin is not affiliated with, endorsed by, or sponsored by Pinterest, Etsy or Shopify. Pinterest is a trademark of Pinterest, Inc.