Back to Pins

pinmy.travel

Privacy Policy

Effective February 13, 2026

1.What we collect

Account data: name, email address, hashed password, plan status, and the date you accepted our terms. Journal data: the pins, notes, photos, trips, dates and locations you choose to record. Payment data: handled by Stripe — we store only subscription status and customer references, never card numbers. Minimal analytics: anonymous counters for our own signup prompts (shown/clicked/signed-up) and a server error log; no third-party trackers, no ad networks, no fingerprinting.

2.How we use it

To run your journal, sync it across devices, process subscriptions, send transactional email (verification, password resets) and — only if you keep it switched on — a weekly digest of your own activity. You can turn the digest off in Settings at any time. We never sell personal data.

3.Photos and storage

Photos are stored in private object storage and served through short-lived signed URLs. They are only visible to you, collaborators on the same trip, and — if you enable public sharing — holders of your share links.

4.Sharing controls

Nothing is public by default. Public trip pages expose only what the page shows (no email address, no private notes on hidden pins); public passports expose only country/state stamps and counts. Disabling or rotating a link immediately revokes access. Live location sharing stops the moment you end it or it expires.

5.Cookies

We use a single essential authentication cookie to keep you signed in. No advertising or cross-site tracking cookies.

6.Service providers

We share the minimum necessary with: Stripe (payments), Resend (transactional email), our hosting and object-storage providers, and OpenStreetMap/tile providers (map requests include your viewport, as with any web map). AI trip recaps send trip stats and pin titles — never your photos or email — to our AI provider to compose the text.

7.Your rights

You can export everything (Settings → "Download full archive") and delete your account and all data yourself (Settings → Danger zone). You may also email us to access, correct or erase your data. Depending on where you live (e.g. GDPR, CCPA) you may have additional statutory rights, which we honour.

8.Retention and security

Data is kept while your account exists and deleted when you delete it (server error logs auto-expire after 30 days). Passwords are stored hashed, share tokens are unguessable, and public endpoints are rate-limited.

9.Changes and contact

We'll announce material changes to this policy in the app or by email. Privacy questions: hello@pinmy.travel.

Also read: Terms of Service