ProfitPinsBack home

ProfitPins legal

Privacy Policy

Last updated October 8, 2026

This Privacy Policy explains how ProfitPins collects, uses, shares, and protects information when you use our website, applications, and related services.

Facebook Page publishing

When you connect Facebook, ProfitPins receives your app-scoped Facebook identifier, the Pages you authorize, the selected Page’s name, image and identifier, and authorization tokens. Tokens are encrypted in private server storage. We never request your Facebook password. We use this information to show your connected Page, create previews and publish the images, captions and product links you choose.

We request business portfolio access to discover Pages you manage that belong to a Meta business portfolio. ProfitPins uses this permission for Page discovery; it does not manage your business portfolio, advertising accounts or other business assets.

Enabling automatic posting includes existing future scheduled Pins and subsequent schedules. You can select Pinterest, Facebook or both for each Pin. Facebook publishing supports one business Page and static feed posts; it does not publish to personal profiles, Stories, Reels or Instagram. We send the selected image, caption and link to Meta when delivering a post. Facebook credentials and Page information are not supplied to caption-generation providers.

Disconnect in Settings → Social Media or revoke ProfitPins in Facebook to remove stored credentials and stop unsent Facebook deliveries. Disconnecting does not remove posts already published on Facebook or your publication history in ProfitPins. We retain a minimal identifier mapping to honor subsequent deletion requests. Request deletion through Facebook’s app settings or contact hello@profitpins.com to remove Facebook connection details, captions and publication identifiers. A confirmed Meta deletion request removes these records from our active application storage; separately created product images and Pinterest Pins remain part of your ProfitPins workspace unless you request their deletion too. Manage already published posts on Facebook.

We do not sell Facebook data or use it for advertising. See Meta’s Privacy Policy for Meta’s handling of published content.

Optional affiliate referrals

With your permission, we use Rewardful to credit the affiliate who referred you. Affiliate tracking requires a separate opt-in worldwide. It does not change your subscription price or enable advertising or product analytics.

For an accepted referral, ProfitPins keeps a referral code, random referral identifier, consent choice, and a 30-day expiration. We associate the referral with your account when you sign in. Rewardful receives the referral identifier and customer information, including email, through Stripe when an eligible subscription checkout is prepared; and its tracking script receives browser, device, IP address, and referring-page information for attribution and fraud checks. Stripe shares payment, refund, and dispute information with Rewardful through our connected payment integration.

You can decline or withdraw using Affiliate tracking choices. We also honor Global Privacy Control and your existing opt-out. Withdrawal clears referral storage in this browser, stops new tracking, cancels undelivered browser tracking, and flags linked purchases for commission review. It does not recall information already sent to Rewardful or disconnect the merchant’s Stripe integration. Payment and commission records may be retained for accounting, dispute resolution, and fraud prevention; they are separate from the 30-day referral window. Contact hello@profitpins.com for requests concerning previously shared data.

Expired referral identifiers are removed from browser storage on your next visit and from active server attribution storage by our scheduled cleanup. Consent preferences last up to 180 days. Affiliate reports are accessible only to authorized ProfitPins administrators.

If you join our affiliate program, Rewardful stores your affiliate profile and PayPal payment email. Authorized ProfitPins administrators use those details to review commissions and send manual payments through PayPal. Payment details and transaction records are shared with PayPal as needed to send and reconcile your payout and are retained separately from expiring referral identifiers.

Information we collect

We collect information you provide or create while using ProfitPins, including:

  • Account information such as your email address, account identifier, subscription status, and credit balance.
  • Content and workflow information such as product links, uploaded images, generated creative, Pin copy, schedules, and settings.
  • Pinterest connection information, including OAuth tokens, your Pinterest account identifier and username, boards you choose, and publishing results.
  • Technical and operational information such as request logs, error details, browser or device information, IP address, and feature usage.

How we use information

  • Provide, secure, maintain, and improve ProfitPins.
  • Generate and organize content at your direction.
  • Connect to Pinterest and publish only the Pins and schedules you choose.
  • Manage accounts, subscriptions, credits, support, and service communications.
  • Detect misuse, troubleshoot problems, and comply with legal obligations.

Pinterest data

ProfitPins accesses Pinterest only after you authorize the connection through Pinterest's OAuth flow. We use Pinterest information only to provide features to the person who connected that account. We do not ask for or store your Pinterest password, and we do not sell Pinterest data.

You choose the boards, Pins, and publishing actions performed through ProfitPins. You can disconnect Pinterest from your ProfitPins settings or revoke access in Pinterest. Revoking access may prevent connected features from working.

Service providers and disclosures

We may share information with service providers only as needed to operate ProfitPins, including:

  • Supabase for authentication, database, and file storage.
  • Resend for authentication and service-email delivery, including support requests you submit.
  • Vercel for application hosting, delivery, logs, and scheduled jobs.
  • PostHog (US region) for product analytics and masked session replay as described below.
  • Pinterest when you connect your account or publish content.
  • Stripe for billing and subscription management. ProfitPins does not store full payment-card numbers.
  • AI, media-generation, and content-processing providers when you request those features.

We may also disclose information when required by law, to protect rights and safety, or as part of a business transfer.

Advertising measurement and cookies

We use the Meta Pixel and Conversions API and the TikTok Pixel and Events API to measure public-page visits, pricing views, verified registrations, checkout starts, and initial paid subscriptions, attribute them to ads, and improve advertising. Measurement starts automatically for eligible visitors in the United States unless you opt out or send a Global Privacy Control signal. We determine eligibility using our hosting provider's country information. Advertising measurement is disabled in other or unknown regions until the applicable regional rules have been reviewed. You can use ProfitPins without advertising measurement, and no Allow popup is required.

Meta and TikTok may receive public page URLs, browser and device information, IP address, advertising identifiers, subscription plan identifiers, paid amounts, currency, and random event identifiers. For eligible authenticated conversions, we send your email after trimming, lowercasing, and SHA-256 hashing it to help match events to ad viewers. Hashing does not make this information anonymous. We do not send plain email, collect phone numbers for matching, or enable automatic collection of form fields. We exclude private workspace content, Pinterest data, authentication tokens, and payment-card details.

A first-party click-ID cookie lasts up to seven days and preserves attribution through signup and checkout. We retain browser identifiers and hashed email for up to seven days for bounded delivery retries, and retain event counts and delivery status for reporting. Our server verifies purchases with Stripe. Browser and server Purchase events share an identifier to prevent duplicate counting.

Use Privacy choices on this page or in Settings → General to select Do not sell or share my personal information. We honor Global Privacy Control and previously recorded declines. Opting out stops future measurement in this browser and, when signed in, cancels queued conversions that have not already been sent or started delivery. Reset my choice removes this browser's saved preference; regional rules and Global Privacy Control still apply. Choices are saved for up to 180 days. Previously delivered events cannot be recalled through this control.

See Meta's Privacy Policy and TikTok's Privacy Policy for how they handle information they receive.

Product analytics and session recordings

We use PostHog to understand visits, traffic sources, signup, pricing, checkout, subscription payments, and feature use. Analytics and masked session replay start for eligible US visitors. They are disabled in other or unknown regions, for administrative accounts, and when you opt out or send Global Privacy Control.

PostHog receives a random visitor identifier, a pseudonymous account identifier after sign-in, browser and device information, sanitized page paths and campaign parameters, feature events, subscription plan, and confirmed payment amount and currency. We do not send email addresses, names, authentication codes, raw advertising click identifiers, Pinterest credentials, or payment-card details. Query strings and URL fragments are removed. Our servers confirm subscription payments with Stripe; opening a thank-you page is not counted as a payment.

Session replay reconstructs visible page text, images, layout, scrolling, and interactions. This includes generated Pins and product previews so we can review image quality and troubleshoot creation. Displayed images may be stored with the recording so they remain visible after temporary image links expire. Form inputs, email addresses, and text marked private are masked; file inputs, embedded frames, and content marked private are blocked. Network bodies, request headers, and browser console logs are not recorded. Authentication callback and administrative pages are excluded. Recordings cannot show the external Stripe checkout or other websites.

Use Privacy choices on this page or in Settings → General to opt out. This stops future collection in this browser and cancels pending server events for your signed-in account. Previously delivered data cannot be recalled through this control; contact us for access or deletion requests. Analytics identifiers and preferences last up to 180 days. Server delivery records are deleted after 30 days. See PostHog’s Privacy Policy.

Retention and security

We retain information for as long as needed to provide the service, maintain legitimate business records, resolve disputes, and meet legal obligations. Pinterest authorization information is retained while your account remains connected and may be removed or invalidated when you disconnect.

We use administrative, technical, and organizational safeguards designed to protect information. No online service can guarantee absolute security.

Your choices and rights

You may update your account, disconnect connected services, or request access to, correction of, or deletion of your personal information by contacting us. Some information may be retained where required by law or for legitimate security, fraud-prevention, and recordkeeping purposes.

ProfitPins is not directed to children under 13, and we do not knowingly collect their personal information.

Changes and contact

We may update this policy as ProfitPins changes. The date below identifies the latest revision.

For privacy questions or requests, contact hello@profitpins.com.