Pinsonar Legal Center
GDPR & Data Protection Compliant

Privacy Policy & Data Processing Notice

Effective Date: October 3, 2026 • Regulation: EU Regulation (EU) 2016/679 (GDPR) • Version 1.3

Privacy Principles at Pinsonar

We believe in rigorous data minimization, transparency, and purpose limitation. Here is what you need to know immediately:

No Private PII Harvesting We do not collect private individual profiles, consumer contacts, or payment credentials.
Device Keys, Not Fingerprints A collector device is identified by a public key registered in your account, never by screen, canvas or other hardware attributes. It is used for request signing, anti-abuse and quota protection.
Your GDPR Rights Full rights to access, export, rectify, and delete your account data on demand.

1. Data Controller Information

For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable data protection legislation, the data controller is:

Pinsonar Systems & Analytics

Infrastructure & Hosting: European Union

Privacy Contact: privacy@pinsonar.com

Data Protection Officer (DPO): dpo@pinsonar.com

2. Categories of Data Processed

We collect and process the following categories of personal and technical data:

A. User Account Information

When you create an account, we collect your business email address, full name (optional), and an encrypted representation of your password (cryptographically salted and hashed using bcrypt). Passwords are never stored in plaintext.

B. Collector Device & Session Data

To protect platform stability and enforce Fair-Use scan limits, each collector device (the Chrome extension or the desktop agent) creates a key pair on first start and registers only its public key in your account together with a device identifier, the device kind, the client version, the time it was last seen, a trust score and the revocation state. Every request of the device is signed with its private key, which never leaves the device. We also keep the IP address of the agent session and, in server logs, the IP address and time of each request. No hardware attributes (screen resolution, canvas rendering, installed fonts) are collected. This data is processed strictly for anti-abuse, rate limiting and the integrity of the shared data.

B2. Chrome Extension: What It Reads, Sends and Stores

What it reads. Only when your account gives the extension a scan job, it opens its own work tabs on Yandex Maps, Google Maps or 2GIS and reads the public pages of those services that the job names: business listings with their name, address, coordinates, phone numbers, website, categories, opening hours, services, promotions, social links, rating, review count and public reviews (text, date and the reviewer's public display name as posted on the service). It does not read your browsing history, other tabs, cookies, passwords, forms or any other website.

What it sends to the Pinsonar server (the server address is fixed in the downloaded copy): the data read from the public pages above, in structured form; a random installation identifier, the extension version, the connection token you pasted, the device kind and, if you choose it in the popup, the interface language; the public key of the device and a signature, timestamp and one-time number for each request; the platforms the extension can serve; and short technical diagnostics per listing (platform, listing identifier, the search phrase, counts and an error state, never page content). The listings it collects become part of the shared Pinsonar database (see section 3) and are visible to accounts according to the plan rules.

What it stores on your computer (Chrome extension storage): the connection token, the server address, the installation identifier, the device private key (never sent anywhere), your language and pause choice, your agreement to this disclosure, the last status and the progress of the current job. Removing the extension deletes all of it.

Why it needs its permissions. storage: the items above; alarms: to check for new jobs periodically; tabs: to open, reuse and close its own work tabs; notifications: to tell you when a service asks for a captcha that only you can solve. Access to the three map services is limited to their addresses. The extension asks for your agreement the first time it starts and does nothing until you give it; you can pause it in the popup or remove it at any time.

C. Analytical Audit & Campaign Metadata

Configuration parameters of your spatial audit campaigns, target keywords, geographic bounding coordinates, selected categories, and historical audit snapshots.

3. Public B2B Geo Data vs Personal Data

A fundamental principle of Pinsonar is that our automated intelligence pipeline targets publicly accessible commercial data from mapping platforms (Yandex Maps, Google Maps, 2GIS).

The data collected regarding businesses (such as company name, registered business address, commercial phone numbers, business opening hours, public rating score, and public consumer reviews) relates exclusively to business entities and publicly posted statements.

Notice on Reviews: While public reviews may include reviewer display nicknames publicly posted by individuals on mapping services, Pinsonar treats these solely as publicly available market feedback and does not profile, trace, or de-anonymize private reviewers.

4. Legal Bases for Processing under GDPR

Under Article 6 of the GDPR, we process your information under the following lawful grounds:

  • Performance of Contract (Art. 6(1)(b)): To manage your registration, authenticate sessions, process keyword rank audits, and deliver analytical reports.
  • Legitimate Interests (Art. 6(1)(f)): To safeguard infrastructure integrity, prevent multi-account abuse, enforce cooldown periods, and maintain service observability.
  • Explicit Consent (Art. 6(1)(a)): Provided during registration for executing automated client-side mapping data collection from your device session.
  • Compliance with Legal Obligations (Art. 6(1)(c)): To satisfy statutory accounting, tax, and law enforcement requirements where applicable.

5. Cookies, Tokens & Local Storage

Pinsonar does not utilize third-party advertising tracking cookies. We utilize strictly necessary storage technologies. The authentication token lives only in the HttpOnly cookie below and is never stored in localStorage; no analytics or advertising identifiers are set:

Key / Token Storage Type Purpose Duration
pinsonar_session Cookie (HttpOnly, SameSite=Lax, Secure in production) Sign-in session (authentication token); not readable by page scripts 7 days or until you sign out
oauth_state Cookie (HttpOnly) Protects the Google sign-in redirect against forgery; only while signing in with Google 5 minutes
pinsonar_lang, pinsonar_theme localStorage Interface language and colour theme Until you clear site data
pinsonar_basemap sessionStorage The map style you picked with ?basemap= for a comparison, only for this tab Until you close the tab
currentCampaignId, pinsonar_report_id, pinsonar_session_ids, pinsonar_params, searchHistory, crmSavedViews, crmScope, pinsonar_wizard_<user id>, tabulator-pinsonar_* localStorage Interface state: the selected project and report, the running scan, the last scan form, recent searches, saved table views and the table layout, filters and sort, the first-run guide Until you clear site data

6. Telemetry & Error Tracking

When an error-monitoring address (Sentry DSN) is configured for the deployment, we use Sentry to detect runtime exceptions, system failures, and background worker stalls. Without it nothing is sent. The integration operates with data minimization:

  • No Default PII: Automatic transmission of personal identifiable information is disabled (send_default_pii=False).
  • Scrubbed Payloads: The Sentry SDK's built-in scrubber masks the values of sensitive fields such as passwords, tokens, authorization headers and cookies before an event leaves the server.

7. Data Retention & Erasure

We retain personal data only as long as necessary to fulfill the purposes for which it was collected. We do not currently run automatic time-based deletion of personal data; erasure happens on request or when an account is closed:

  • Account Records: Kept while your account exists. On your request (privacy@pinsonar.com) we delete the account; your registered collector devices are deleted with it.
  • Server Logs: Application logs (including IP addresses and request paths) are written to rotating files limited by size, so the oldest entries are overwritten as new ones arrive.
  • Your Reports and Personal CRM Layer: Kept until you remove them. "Remove from me" hides a report and deletes your personal CRM data (statuses, notes, tasks, tags) for organizations that no other report of yours contains.
  • Public Business Data: Company listings collected from mapping platforms form a shared database of public business information; they are not personal data of the account holder and are not deleted when you leave. When an operator unlinks a wrongly matched business card, a backup copy of that card is kept for 30 days so the step can be undone, then deleted automatically; this concerns public business data only.

8. Security & Technical Measures

We employ enterprise-grade technical and organizational measures (TOMs) to secure your data:

Encryption in Transit & Rest The service is served over HTTPS (TLS) with HSTS in production. Database backups are encrypted with AES-256 (OpenSSL) before they are stored. Encryption of the server disks is a property of the hosting provider and is not a promise of this policy.
Access Control Role-based access control (USER / PRO / ADMIN) and per-user visibility of data; passwords are stored only as bcrypt hashes; sessions are HttpOnly and revoked on sign-out; request logs.

9. Your Rights under GDPR

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you enjoy the following statutory rights under the GDPR:

• Right of Access (Art. 15): You have the right to obtain confirmation and copy of your personal data held by us.

• Right to Rectification (Art. 16): You may request correction of inaccurate personal data.

• Right to Erasure ("Right to be Forgotten", Art. 17): You may request erasure of your personal data from our databases; requests are handled by us manually.

• Right to Restriction of Processing (Art. 18): You can limit how we process your personal information under certain statutory conditions.

• Right to Data Portability (Art. 20): You can receive your account and campaign data in a structured, machine-readable format (XLSX exports of your reports are available in the app; the rest of your account data on request).

• Right to Object (Art. 21): You may object to data processing based on legitimate interests at any time.

To exercise any of these rights, email us directly at privacy@pinsonar.com. We will respond within thirty (30) days without undue delay.

10. Subprocessors & EU Hosting

Our primary infrastructure, databases (PostgreSQL/PostGIS, Redis), and background processing workers are intended to be hosted on servers located within the European Union.

Third parties that may receive technical data (such as your IP address and the pages you open) when you use the service:

  • Scripts, styles and fonts of the pages are served from our own servers; no content delivery network or font service receives your IP address from them.
  • Map tile providers (basemaps.cartocdn.com by CARTO, or tiles.openfreemap.org by OpenFreeMap, both based on OpenStreetMap data; the service uses one or both, depending on its configuration): your browser requests the map tiles, fonts and symbols of the area you view.
  • Google (OAuth), only if you choose "Continue with Google".
  • Cloudflare Turnstile (or reCAPTCHA), only when the anti-bot check is enabled for sign-up.
  • Sentry, only when an error-monitoring address is configured (see section 6).
  • E-mail delivery provider (SMTP): receives your address and the verification or reset message.
  • Hosting provider of the servers.

The data collectors (Chrome extension, desktop agent) contact the mapping platforms directly from your own device; in the production configuration the server of Pinsonar does not visit those platforms.

11. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect technological developments, operational refinements, or regulatory updates. We will notify you of material changes via email or an in-app banner alert prior to the change becoming effective.

12. Data Protection Officer & Supervisory Authority

If you have questions, complaints, or concerns regarding our privacy practices or wish to contact our Data Protection Officer:

Pinsonar Data Protection Office

Email: dpo@pinsonar.com

Response Time: Within 48 hours for preliminary review

You also have the right to lodge a formal complaint with the competent supervisory authority for data protection in your country of residence or workplace within the European Union.