PINTRU

Version 06in force since September 19, 2026Previous versions

Privacy notice

What PINTRU collects, why, who it shares it with, and what you can ask for at any time.

1. In short

PINTRU is a layer of annotations over the web: it lets you leave pins — personal notes, reviews with a rating, verifications — anchored to a web page. There are two ways to use it: by installing the browser extension, or by visiting a website that has included our integration script (the embed).

2. Who processes your data

The data controller is Thomas Casadei, VAT number 04151640408, registered at Galleria OIR 16, 47521 Cesena (FC), Italy, tax code CSDTMS78T14C573H, email: info@pintru.com.

For any matter concerning personal data, including exercising the rights described below, the contact is info@pintru.com.

Data protection officer (DPO): not appointed.

3. When this notice applies

This notice concerns the data PINTRU processes as controller when:

In the last case there is an important distinction, and it concerns two different phases of the same processing.

The website that decides to install the embed chooses to activate PINTRU for its visitors. For the collection phase alone — data collected in the visitor's browser and communicated to PINTRU — that choice is the publisher's, and the publisher and PINTRU are joint controllers within the meaning of Article 26 of the Regulation: it falls to the publisher to inform their visitors and, where necessary, to collect consent before activation.

For everything that happens after the data is received — storage, moderation, publication of content, security, abuse prevention — PINTRU processes as an independent controller, and this notice applies in full.

The essence of the arrangement between the joint controllers, which Article 26(2) requires to be made available to data subjects, is published in the Joint controllership arrangement section of the integration terms. How it works is described in the section The embed on third-party websites.

4. The data we process

Below are the categories of data actually present in the service, with an indication of where each comes from.

Device identifier

A random identifier generated locally (a hexadecimal string, with no link to your identity) that serves to attribute pins to whoever created them, even without an account. It is kept by the extension in its own storage area and, in the case of the embed, in the browser's local storage only if the host website has collected consent; without consent it is temporary and disappears when the page is closed.

Account data

If you register: email address, password (kept only as an encrypted hash, never in the clear), any first name, surname and profile picture, preferred language, creation date and date of last access, and the email verification status. If you sign in with Google we receive from the identity provider the Google account identifier, the verified email address and, where available, first name, surname and the URL of the profile picture; name, surname and picture are used only if the corresponding fields are still empty. We do not receive your Google password.

Sessions

For each device you sign in from we keep a session token, the date it was created and the date it was last used. In the export file the tokens appear masked: they are access credentials, not data to be handed over.

Content you create

Pin text, category (note, review, verification), the visibility chosen, the position on the page and the reference dimensions of the frame, creation and modification dates, and any attached images. For reviews: a rating from 0 to 10, the text, the name of the subject reviewed, any product code and locality. For verifications: the statement, the source, the reasoning and the value of the contribution. Also your votes, your favourites, the share links you generate and your personalised arrangement of pins on pages.

The images you upload are stripped of embedded metadata before being saved: any capture data and geographic coordinates present in the file are not kept.

Proof of purchase attached to a review

If you voluntarily attach a document supporting your experience — a receipt, a till slip, an order confirmation — it is not published and is accessible only to those responsible for moderation. It is kept together with the review: we undertake to keep it available for 2 years, and it remains tied to the life of the review, with which it is deleted. Images are stripped of metadata before being saved, including any geographic coordinates present in the file.

Content of the verified page

Only when you use a verification feature: the text of the page — or the part the contribution refers to — kept together with the contribution to document the statement, with the outcome of any automated analysis. It does not concern the pages you visit without using those features.

Annotated pages

In order to show a page's pins, the service must know its address. The address is normalised before any use: the protocol, domain and path remain, while the query string and the fragment are discarded. What stays in the database is the page — normalised address, domain, an aggregate view counter and the number of pins — without any link to who requested it. A link to the author exists only for the content you created yourself.

Client usage data

When the extension starts or is used we record the channel (for example the Chrome extension), its version, the type of event, the date and time, and a cryptographic hash of your identifier, which serves to count distinct users without tracing anyone. This measurement contains no page address and no visited domain.

Embed usage data

Only if the host website declares active consent, our script reports to the service the website's domain, the page address, any referring page, the date and time, and the consent receipt passed on by the publisher (collection method, consent management platform and receipt identifier, where provided). Without consent this report is not sent at all.

Subscription and payments

If you subscribe to a paid plan we keep the plan, the subscription status, the payment service provider used, the subscription identifier held by it and the end of the current period. We do not receive, see or store your card details: collection is carried out through the provider, which acts on our instructions and is not the counterparty to the contract. The seller is stated in the purchase and subscription terms.

Technical and security data

When you request email verification or a password reset we keep, together with the request, the IP address and the browser identification, so that any abuse can be reconstructed; of the link sent we keep only a cryptographic hash, never the value in the clear. To limit abuse the service counts requests per IP address in temporary memory, aggregating IPv6 addresses by block. An application log records the service's relevant events (sign-ins, errors, administrative operations).

Moderation and reports

Of public content we keep the outcome of the anti-abuse assessment: verdict, risk score, categories found, a brief explanation, the model used and technical data about the call. Of users' reports we keep the content reported, the reason, any note, who reported it and how it was dealt with.

Requests concerning personal data

Of every export and every deletion we keep a record: the identifier of the account concerned, a cryptographic hash of the email address, the type and manner of the request, the outcome and counts of what was deleted, anonymised or kept. This record survives the deletion of the account and does not contain the email in the clear: it serves to demonstrate that the request was dealt with.

Service operators

People working in the back office have a separate account, with name, email, role and permissions, sessions of limited duration and a record of the last sign-in. It is not a product account and follows a distinct life cycle.

What you have to give us, and what happens if you do not

No data is required of you by law. The email address is necessary to create an account and to subscribe to a paid plan: without it, those features are not available, but the service remains usable without registering, with the reduced features described in the terms of use. The page address is technically necessary in order to show you the pins that concern it: without it the service cannot work. First name, surname and profile picture are optional. The proof of purchase attached to a review is always optional and its absence does not affect publication.

5. Why we process it

PurposeBasis for processing
Displaying, creating, saving and synchronising pinsPerformance of the service you requested
Storing the identifier on the device through the embedConsent, collected by the website hosting the embed
Accounts, subscriptions and obligations towards the payment providerPerformance of the contract
Publication of reviews, public notes and verification contributionsPerformance of the contract with the author (art. 6(1)(b)). As regards third-party data that may be contained in the content: legitimate interest (art. 6(1)(f)) in the informational function of the service and in users' freedom of expression, balanced within the limits of Article 85 of the Regulation and Articles 136 et seq. of the Italian Code
Email address verification and password resetPerformance of the contract, and security
Verification features: processing the text of the verified pagePerformance of the service requested (art. 6(1)(b)) and legitimate interest (art. 6(1)(f)) in the verified statement being documentable and open to review
Moderation of public content and handling of reportsLegitimate interest in a service free from abuse, and protection of third parties
Usage measurement of the clients and of the embedConsent, or legitimate interest for aggregate measurement alone
Measurement of the site and of PINTRU's pages (Google Tag Manager and the tools configured within it)Consent (art. 6(1)(a) and art. 122 of the Italian Code), collected by the banner and withdrawable at any time. Failing that, nothing is loaded
Security, prevention and detection of abuseLegitimate interest (art. 6(1)(f)) in protecting the integrity and availability of the service and in preventing unauthorised access and abuse
Accounting and tax obligationsLegal obligation

Where processing is based on our legitimate interest, we have verified that it does not override your fundamental rights and freedoms. You can obtain a copy of the balancing assessment by writing to the contacts given above.

Where processing is based on consent, you can withdraw it at any time: withdrawal applies to the future and does not affect what was done before.

6. The browser extension

Installing an extension is a decision that deserves to be taken knowingly. In order to work, the PINTRU extension asks for permission to operate on all websites: without that permission it could not show pins on the page you are reading, whatever it may be. Here is exactly what it does with that permission.

What it does

What it does not do

You can switch the extension off at any time from its panel: from that moment it no longer activates on any page. You can uninstall it from your browser settings: uninstalling also removes everything it had stored on the device. Content already saved on the service remains, and is deleted from your personal area.

7. The embed on third-party websites

A website can activate PINTRU for its visitors by including one line of code in its pages. In that case pins appear to whoever visits that website, without their having to install anything.

Our script is designed to be discreet by default. Until the host website declares consent collected from its visitor, it:

If and when the host website declares consent, the identifier becomes persistent on the device and the usage report is sent, with any consent receipt passed on by the publisher.

There is one further case to be aware of: if you move a pin on the page by hand, the new position is remembered in the browser's local storage for that page, even without consent, so that the pins are not shuffled again on every reload. It is a display preference, it contains no identifying data and it stays on your device. The entry is described in the cookie policy.

Who is answerable for what. It is the website that includes the script that decides to activate PINTRU for its visitors: it falls to them to inform those visitors and, where necessary, to collect consent before activation. PINTRU supplies the technical tool and the mechanism by which consent is passed on, but cannot check whether it was actually collected. For this phase the publisher and PINTRU are joint controllers: the division of obligations, the contact point for data subjects and the rest of the arrangement are in the Joint controllership arrangement section of the integration terms.

8. Public content

The service distinguishes three levels of visibility: private (only you see the note), shared (visible to whoever has the link you generated) and public (visible to anyone opening that page with PINTRU active).

If you choose to publish, the content leaves your private sphere: it will be readable by people you do not know, it can be voted on and reported, and it can be copied or quoted elsewhere — like anything published on the web. Think carefully about what you write, particularly when it concerns identifiable people.

Reviews and public notes stay visible after your account is deleted, but detached from you: see the section Deleting your account. If you would rather they were removed entirely, you can ask for that.

9. If you are mentioned in content and you are not a user

Content published on PINTRU may concern you even though you have never used the service: a review of your business, a note mentioning you, a verification contribution on a page that talks about you. We process your data as controller, and we cannot inform you individually because we do not have your contact details and because doing so would involve disproportionate effort: this section is the measure the Regulation prescribes in that case, under Article 14(5)(b).

What data. The data contained in the content published by the user: your name or the name of your business, the opinion expressed, the contextual elements the author included. The source is always the user who wrote the content, never a collection carried out by us.

Why. To make available to the public opinions and information of interest to anyone about to choose a product, a service or a source. The basis is our legitimate interest in that informational function and in users' freedom of expression (art. 6(1)(f)), balanced against your rights within the limits of Article 85 of the Regulation and Articles 136 et seq. of the Italian Personal Data Protection Code.

What we do not do. We do not build profiles of the people mentioned, we do not aggregate the content concerning you for purposes other than reading it, we do not communicate it to third parties for their own purposes, and we do not use it for advertising.

What you can ask for, and how. By writing to info@pintru.com you can: find out what published content concerns you; ask for inaccurate data to be corrected; object to the processing, stating the grounds relating to your particular situation; ask for unlawful or damaging content to be removed; reply publicly to the review, in place of its removal. We respond within 30 days. If the request is granted, the content is removed or made inaccessible and the author is informed with the reasons, with the right to complain.

What we cannot do. We do not remove content merely because it expresses a negative or unwelcome opinion. We remove what is unlawful: unproven allegations of specific and damaging facts, personal attacks, disclosure of other people's personal data, anything that goes beyond the limits of the right to criticise. The reasons are explained in the terms of use.

If you consider the processing not to be compliant, you can turn to the Italian data protection authority (Garante per la protezione dei dati personali).

10. Automated moderation

To stop the service becoming a vehicle for insults, defamation or fake reviews, content intended for publication goes through a two-stage check: a local automated filter, which decides most cases on its own, and — for doubtful cases only — an assessment carried out by an external provider's artificial intelligence model.

When that assessment takes place:

Non-public content is not sent to this check. Private notes and those shared by link do not leave our service.

The automated assessment may hold a piece of content pending (it stays visible only to you) or reject it. It is not a decision about you as a person and it produces no legal effects concerning you: it affects the publication of that single item of content, and you can ask for it to be reviewed by a person by writing to the contacts given above.

Of a decision that withholds, removes or makes inaccessible any content of yours you are given the reasons, stating the basis, the elements assessed and any use of automated tools; you may lodge a complaint under the procedure described in the terms of use, the examination of which is not entrusted solely to automated tools.

11. Where PINTRU does not operate

PINTRU is designed for the public pages of the web. We have set ourselves the goal that the service should not activate, and should stop operating, on pages where data is entered or consulted that must not reach us. This is a goal we pursue with progressive measures, not a result we can guarantee absolutely: no technique makes it possible to recognise with certainty the content of every page on the web. The categories we aim to exclude are the following:

It is a minimisation measure: the safest way not to process a piece of data is not to be in a position to receive it. The exclusions are extended over time. The exclusions currently active operate on two levels. The service recognises from the page's address the typical paths of payment, checkout, sign-in, registration, credential recovery and personal areas, and does not activate on those pages. In addition, the extension and the script check the page's content and switch themselves off when they find a password field or a card details field, whatever the address. The check is repeated on the server, which in any case refuses to display or record content on those addresses.

12. The verification features and page content

The service provides features with which users assess how reliable what a page states is. They are introduced progressively and may be reserved to particular plans.

When you use one of these features, in addition to your contribution we may process the textual content of the page, or the part of it the verification refers to: without the verified text the statement could not be documented or reviewed. The text may be subjected to automated analysis, including by external providers, in order to assess how well founded the contribution is.

What we do not do, and do not intend to do. We do not collect the content of the pages you visit when you are not using a verification feature; we do not reconstruct your browsing history; we do not process the content of the pages excluded by the preceding section; we do not use these texts to profile you or for advertising purposes. What is processed is the statement being verified, not the person verifying it.

If the text of a page by its nature contains third-party personal data, we limit ourselves to what is necessary to document the statement. You can ask for a verification contribution and the text kept with it to be removed, under the section Your rights. The processing is based on performance of the service you requested and on our legitimate interest in making the verified statement documentable and open to review; the verified text is kept for as long as the contribution it refers to, and is deleted with it.

13. Who we share data with

We do not sell data and we do not pass it to third parties for their own purposes. We use providers who process it on our behalf or, where stated, as independent controllers:

ProviderWhat forWhat data it receivesRoleWhere
Aruba S.p.A.Infrastructure, servers and databaseAll the service's data, since it hosts itProcessorItaly
Language model provider (who it is today)Automated assessment of content intended for publicationThe text of the content and minimal context, without data identifying the authorProcessorUnited States of America — standard contractual clauses
Google Ireland LimitedSending service communicationsThe recipient's address and the message contentProcessorEuropean Union
Google Ireland Limited, as measurement providerSite measurement, only with your consentBrowsing data on our pages: pages viewed, referrer, device type, a browser identifier. Not your name, not your email, not the content you writeIndependent controller for its own purposes — its own notice appliesEuropean Union and United States
Google, as identity providerSigning in with Google, if you choose itThe data you authorise at the time of sign-inIndependent controller — its own notice appliesEuropean Union and United States
Payment service providerCarrying out collection and renewals, on our instructionsThe data you give it at the time of payment; we do not see itIndependent controller for its own obligationsEuropean Union

We do not use content delivery networks or third-party traffic protection services: the pages, the scripts and the typefaces are served directly from our own infrastructure, hosted in Italy. The only resource that may be requested from a third-party server is the measurement tool, and only after your consent: without it, your browser never contacts it.

Data may also be communicated to the authorities where the law requires it.

Transfers outside the European Union. Some providers process data in third countries: this is the case for the provider that carries out the automated assessment of content intended for publication and — if you consent to it — for the one providing site measurement. In those cases the transfer takes place on the basis of the safeguards provided for by Chapter V of the Regulation — in particular the standard contractual clauses adopted by the European Commission, where no adequacy decision applies — accompanied, where necessary, by an assessment of the circumstances of the transfer and by supplementary measures. You can ask for a copy from the contacts given above. For providers established in the European Union no further safeguard is required. For the language model provider, established outside the European Union, the transfer takes place on the basis of the standard contractual clauses adopted by the European Commission: the list of providers states who it is and where it processes.

14. How long we keep it

DataRetention
Account and contentFor as long as the account is active, or until you ask for it to be deleted
Public content after account deletionIt stays in anonymous form, unless complete deletion is requested
SessionsUntil sign-out or account deletion
Email verification and password reset linksShort expiry; used requests are cleaned up periodically
Minimal billing data kept after deletion10 years, under civil and tax law obligations
Client and embed usage data12 months, then kept in aggregate form only
Application and security log12 months
Moderation outcomes and reports24 months from the decision, together with the related correspondence
Record of requests concerning personal dataKept as proof that the request was dealt with, for 24 months

15. Your rights

Right to object. Where we process your data on the basis of our legitimate interest — moderation, security, abuse prevention, aggregate usage measurement, publication of content concerning you — you have the right to object at any time, on grounds relating to your particular situation. If you object, we stop the processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or that the processing serves to establish, exercise or defend a legal claim. To exercise it, writing to info@pintru.com is enough.

You can ask at any time to access your data, to have it corrected, deleted or its processing restricted, to object to processing based on our legitimate interest, to receive in a readable format the data you provided to us, and to withdraw consent where it is the basis for processing.

Two of these rights you exercise yourself, from your personal area, without waiting for a reply:

For everything else, write to info@pintru.com. If you consider the processing not to be compliant, you can turn to the supervisory authority; in Italy this is the Garante per la protezione dei dati personali.

16. Deleting your account

Deletion is final and is carried out in a single operation. Before you confirm it you are shown a summary of what will be deleted, anonymised or kept. In the default mode:

If you would rather that public content too were deleted, you can ask for the complete mode: reviews, verifications and votes are deleted and the averages and verdicts of the pages involved are recalculated.

17. Security

We adopt appropriate technical and organisational measures: encrypted traffic, passwords kept only as a hash, tokens for verification and reset links kept in encrypted form, differentiated permissions for operators with sessions of limited duration, rate limits on requests, checks on uploaded files and removal of metadata from images. No measure removes risk entirely: should a data breach occur, we will act as the law requires.

18. Minors

The service is not intended for anyone under 14 years of age. If we become aware of an account created by a minor under that age, we will remove it.

19. Changes to this notice

We may update this document to keep it aligned with changes to the service or to the law. The version in force is always the one published on this page, with the date of the last update at the top. If the changes are substantial we will give notice by an appropriate means.

Previous versions