1. Who we are
Pingwide is operated by the Pingwide team ("we", "us"). We are the controller of personal data collected through the service. Contact: privacy@pingwide.com.
2. Data we collect
- Account data: email, display name, language, password hash, timestamps.
- Billing data: Stripe customer and subscription identifiers, plan, billing period, renewal date. We never see your card number.
- Connected accounts: platform identifier, public username, display name, avatar URL, OAuth token metadata, token validity, last publish status. We do not collect your social passwords.
- Content: captions, media files, schedule times, per-platform results — strictly to deliver the publishing service you requested.
- Operational data: sign-in events, error logs, basic usage metrics needed to keep the service reliable.
3. How we use it
- To provide the service and publish your content to the networks you authorise.
- To enforce plan limits (connected accounts, daily posts, AI credits).
- To bill you and prevent fraud.
- To send essential service notifications and respond to support requests.
- To improve the product through aggregated, non-identifying usage analysis.
4. Legal basis (GDPR)
We process personal data on the basis of (a) the contract between you and Pingwide, (b) our legitimate interest in operating and securing the service, and (c) your explicit consent for optional features.
5. Sharing & subprocessors
We share data only with subprocessors strictly necessary to operate the service:
- Lovable Cloud / Supabase — database, authentication, file storage.
- Stripe — payment processing.
- Post for Me — token exchange and publishing to social networks.
- Anthropic & OpenAI — AI generation (only when you explicitly invoke it).
- Resend / email provider — transactional email.
Each subprocessor is bound by a data processing agreement.
6. Retention
Account data is retained while your account exists. After account deletion we remove personal data within 30 days, except where retention is required by law (e.g. invoices for 7 years).
7. International transfers
Some subprocessors are based in the United States. Transfers rely on Standard Contractual Clauses or equivalent safeguards.
8. Your rights
You have the right to access, rectify, delete, restrict or port your personal data, and to object to processing. Email privacy@pingwide.com and we will reply within 30 days. You may also lodge a complaint with your local supervisory authority.
9. Security
We encrypt data in transit (TLS) and at rest. Database access is protected by row-level security policies so that you can only access your own records. Media is stored in a private bucket and served via short-lived signed URLs.
10. Cookies
We use strictly necessary cookies for authentication and security. We do not use third-party advertising cookies.
11. Children
Pingwide is not intended for children under 16 and we do not knowingly collect their data.
12. Changes
We may update this policy. Material changes will be announced in-product or by email at least 30 days before they take effect.
Last updated: 2026-06-25