PinSailor

Privacy Policy

Last updated: August 18, 2026

This policy explains how RSU GRAFX SRL ("PinSailor", "we", "us") processes information when a merchant installs or uses the PinSailor Shopify app. PinSailor creates reviewable Pinterest Pin drafts from Shopify product data and, only after the merchant's action and the required Pinterest authorization, can schedule or publish approved Pins.

Information we process

PinSailor does not request protected Shopify customer data and does not use product data to identify buyers. The mandatory customer privacy webhooks are still implemented, as Shopify requires for public apps.

Why we process it

We process this information to authenticate the merchant, sync product changes, create and maintain drafts, prevent duplicate webhook work, publish merchant-approved Pins, enforce plan limits, secure and debug the service, provide support, and meet legal obligations. The primary legal bases, where applicable, are performing our contract, legitimate interests in operating and securing the service, consent for the Pinterest connection, and compliance with law.

Sharing and service providers

We disclose data only as needed to operate PinSailor: to Shopify for app installation and billing, to Pinterest when the merchant connects an account or requests a Pin action, to Google Cloud for application hosting, secrets and scheduled processing, and to Neon for managed PostgreSQL hosting. We may disclose information when required by law or to protect users and the service. We do not sell personal information and do not use merchant data for third-party behavioral advertising.

Retention and deletion

We retain active-shop data while the app is installed and as needed to provide the service. Expired OAuth state is short-lived. A merchant-selected Pinterest board identifier is retained only while needed to execute the pending action and is removed after completion, account change, or disconnect. PinSailor retains the local completion status, time and usage count, but not the Pinterest Create Pin response. Operational records are kept only as long as reasonably needed for reliability, security, dispute handling, and legal obligations. On Shopify app/uninstalled or shop/redact, PinSailor deletes the shop record and its settings, Pinterest tokens, drafts, events, usage records, OAuth state, and webhook receipts. Shopify sessions are also deleted. Disconnecting Pinterest removes the OAuth connection, pending board references, and stored Pinterest error details. Provider backups, if any, expire according to the provider's rolling backup schedule.

Security and international transfers

We use least-privilege access, Shopify webhook HMAC verification, encrypted Pinterest credentials, transport encryption, and controlled production access. No online system is risk-free. Providers may process data in countries other than the merchant's; where required, we use lawful transfer mechanisms and contractual safeguards.

Your choices and rights

Merchants can disconnect Pinterest, edit drafts before publishing, and uninstall PinSailor from Shopify. Product deletion and uninstall apply the retention behavior described above. Depending on location, a person may request access, correction, deletion, restriction, portability, or an objection to processing. Contact us with the shop domain and enough information to verify the request. We may coordinate a request through the merchant or Shopify when they are the appropriate controller.

Contact

RSU GRAFX SRL · CUI 42387531 · Trade Register J2020000386049
Legal representative: Rusu Bogdan
Registered office: Str. 1 Decembrie nr. 218, sat Săucești, comuna Săucești, județul Bacău, cod poștal 607540, România
Privacy questions and requests: contact@rsugrafx.com.

Changes

We may update this policy as PinSailor or applicable requirements change. The date above identifies the current version. Material changes will be communicated in the app or by another reasonable channel.