Version 06in force since September 19, 2026Previous versions
Privacy notice
What PINTRU collects, why, who it shares it with, and what you can ask for at any time.
1. In short
PINTRU is a layer of annotations over the web: it lets you leave pins — personal notes, reviews with a rating, verifications — anchored to a web page. There are two ways to use it: by installing the browser extension, or by visiting a website that has included our integration script (the embed).
- Using PINTRU does not require an account: without registering, the only identity data is a random identifier generated on your device.
- To show you a page's content the service transmits its address, which is needed to find the content that refers to it. We do not collect the content of the pages you visit — with one declared exception: if you use a verification feature, the text of the page the verification refers to is transmitted together with your contribution, because without it there would be nothing to verify.
- On some pages PINTRU does not activate at all: payments, sign-in forms, restricted areas and pages handling particularly sensitive data. The detail is in Where PINTRU does not operate.
- Private notes stay private. Reviews and public notes are, by definition, visible to anyone opening that page with PINTRU active.
- Public content may undergo an automated anti-abuse assessment that sends it to an external artificial intelligence provider. Private content does not.
- We do not sell data and we do not do advertising profiling. On PINTRU's own pages, only with your consent, we measure in aggregate how the service is used: without consent the tool is not loaded at all. On third-party websites and in the extension there is no measurement of ours. The detail of what ends up on your device is in the cookie policy.
- You can download your data and delete your account yourself, from your personal area, without needing anyone's permission.
2. Who processes your data
The data controller is Thomas Casadei, VAT number 04151640408, registered at Galleria OIR 16, 47521 Cesena (FC), Italy, tax code CSDTMS78T14C573H, email: info@pintru.com.
For any matter concerning personal data, including exercising the rights described below, the contact is info@pintru.com.
Data protection officer (DPO): not appointed.
3. When this notice applies
This notice concerns the data PINTRU processes as controller when:
- you visit the website and the service's pages;
- you install and use the browser extension;
- you create an account, subscribe to a paid plan, publish content;
- you use PINTRU on a third-party website that has included our script.
In the last case there is an important distinction, and it concerns two different phases of the same processing.
The website that decides to install the embed chooses to activate PINTRU for its visitors. For the collection phase alone — data collected in the visitor's browser and communicated to PINTRU — that choice is the publisher's, and the publisher and PINTRU are joint controllers within the meaning of Article 26 of the Regulation: it falls to the publisher to inform their visitors and, where necessary, to collect consent before activation.
For everything that happens after the data is received — storage, moderation, publication of content, security, abuse prevention — PINTRU processes as an independent controller, and this notice applies in full.
The essence of the arrangement between the joint controllers, which Article 26(2) requires to be made available to data subjects, is published in the Joint controllership arrangement section of the integration terms. How it works is described in the section The embed on third-party websites.
4. The data we process
Below are the categories of data actually present in the service, with an indication of where each comes from.
Device identifier
A random identifier generated locally (a hexadecimal string, with no link to your identity) that serves to attribute pins to whoever created them, even without an account. It is kept by the extension in its own storage area and, in the case of the embed, in the browser's local storage only if the host website has collected consent; without consent it is temporary and disappears when the page is closed.
Account data
If you register: email address, password (kept only as an encrypted hash, never in the clear), any first name, surname and profile picture, preferred language, creation date and date of last access, and the email verification status. If you sign in with Google we receive from the identity provider the Google account identifier, the verified email address and, where available, first name, surname and the URL of the profile picture; name, surname and picture are used only if the corresponding fields are still empty. We do not receive your Google password.
Sessions
For each device you sign in from we keep a session token, the date it was created and the date it was last used. In the export file the tokens appear masked: they are access credentials, not data to be handed over.
Content you create
Pin text, category (note, review, verification), the visibility chosen, the position on the page and the reference dimensions of the frame, creation and modification dates, and any attached images. For reviews: a rating from 0 to 10, the text, the name of the subject reviewed, any product code and locality. For verifications: the statement, the source, the reasoning and the value of the contribution. Also your votes, your favourites, the share links you generate and your personalised arrangement of pins on pages.
The images you upload are stripped of embedded metadata before being saved: any capture data and geographic coordinates present in the file are not kept.
Proof of purchase attached to a review
If you voluntarily attach a document supporting your experience — a receipt, a till slip, an order confirmation — it is not published and is accessible only to those responsible for moderation. It is kept together with the review: we undertake to keep it available for 2 years, and it remains tied to the life of the review, with which it is deleted. Images are stripped of metadata before being saved, including any geographic coordinates present in the file.
Content of the verified page
Only when you use a verification feature: the text of the page — or the part the contribution refers to — kept together with the contribution to document the statement, with the outcome of any automated analysis. It does not concern the pages you visit without using those features.
Annotated pages
In order to show a page's pins, the service must know its address. The address is normalised before any use: the protocol, domain and path remain, while the query string and the fragment are discarded. What stays in the database is the page — normalised address, domain, an aggregate view counter and the number of pins — without any link to who requested it. A link to the author exists only for the content you created yourself.
Client usage data
When the extension starts or is used we record the channel (for example the Chrome extension), its version, the type of event, the date and time, and a cryptographic hash of your identifier, which serves to count distinct users without tracing anyone. This measurement contains no page address and no visited domain.
Embed usage data
Only if the host website declares active consent, our script reports to the service the website's domain, the page address, any referring page, the date and time, and the consent receipt passed on by the publisher (collection method, consent management platform and receipt identifier, where provided). Without consent this report is not sent at all.
Subscription and payments
If you subscribe to a paid plan we keep the plan, the subscription status, the payment service provider used, the subscription identifier held by it and the end of the current period. We do not receive, see or store your card details: collection is carried out through the provider, which acts on our instructions and is not the counterparty to the contract. The seller is stated in the purchase and subscription terms.
Technical and security data
When you request email verification or a password reset we keep, together with the request, the IP address and the browser identification, so that any abuse can be reconstructed; of the link sent we keep only a cryptographic hash, never the value in the clear. To limit abuse the service counts requests per IP address in temporary memory, aggregating IPv6 addresses by block. An application log records the service's relevant events (sign-ins, errors, administrative operations).
Moderation and reports
Of public content we keep the outcome of the anti-abuse assessment: verdict, risk score, categories found, a brief explanation, the model used and technical data about the call. Of users' reports we keep the content reported, the reason, any note, who reported it and how it was dealt with.
Requests concerning personal data
Of every export and every deletion we keep a record: the identifier of the account concerned, a cryptographic hash of the email address, the type and manner of the request, the outcome and counts of what was deleted, anonymised or kept. This record survives the deletion of the account and does not contain the email in the clear: it serves to demonstrate that the request was dealt with.
Service operators
People working in the back office have a separate account, with name, email, role and permissions, sessions of limited duration and a record of the last sign-in. It is not a product account and follows a distinct life cycle.
What you have to give us, and what happens if you do not
No data is required of you by law. The email address is necessary to create an account and to subscribe to a paid plan: without it, those features are not available, but the service remains usable without registering, with the reduced features described in the terms of use. The page address is technically necessary in order to show you the pins that concern it: without it the service cannot work. First name, surname and profile picture are optional. The proof of purchase attached to a review is always optional and its absence does not affect publication.
5. Why we process it
| Purpose | Basis for processing |
|---|---|
| Displaying, creating, saving and synchronising pins | Performance of the service you requested |
| Storing the identifier on the device through the embed | Consent, collected by the website hosting the embed |
| Accounts, subscriptions and obligations towards the payment provider | Performance of the contract |
| Publication of reviews, public notes and verification contributions | Performance of the contract with the author (art. 6(1)(b)). As regards third-party data that may be contained in the content: legitimate interest (art. 6(1)(f)) in the informational function of the service and in users' freedom of expression, balanced within the limits of Article 85 of the Regulation and Articles 136 et seq. of the Italian Code |
| Email address verification and password reset | Performance of the contract, and security |
| Verification features: processing the text of the verified page | Performance of the service requested (art. 6(1)(b)) and legitimate interest (art. 6(1)(f)) in the verified statement being documentable and open to review |
| Moderation of public content and handling of reports | Legitimate interest in a service free from abuse, and protection of third parties |
| Usage measurement of the clients and of the embed | Consent, or legitimate interest for aggregate measurement alone |
| Measurement of the site and of PINTRU's pages (Google Tag Manager and the tools configured within it) | Consent (art. 6(1)(a) and art. 122 of the Italian Code), collected by the banner and withdrawable at any time. Failing that, nothing is loaded |
| Security, prevention and detection of abuse | Legitimate interest (art. 6(1)(f)) in protecting the integrity and availability of the service and in preventing unauthorised access and abuse |
| Accounting and tax obligations | Legal obligation |
Where processing is based on our legitimate interest, we have verified that it does not override your fundamental rights and freedoms. You can obtain a copy of the balancing assessment by writing to the contacts given above.
Where processing is based on consent, you can withdraw it at any time: withdrawal applies to the future and does not affect what was done before.
6. The browser extension
Installing an extension is a decision that deserves to be taken knowingly. In order to work, the PINTRU extension asks for permission to operate on all websites: without that permission it could not show pins on the page you are reading, whatever it may be. Here is exactly what it does with that permission.
What it does
- On every page where it is active, it asks our server for that page's pins. To do so it transmits the page address. The server normalises it immediately, discarding the query string and the fragment, and does not store it together with your identifier.
- It draws the existing pins on the page, and the interface for creating new ones. The changes are display-only and concern you alone: the website visited is not altered and receives no information from the extension.
- It sends to the server the content you create: pin text, category, position, any attachments, votes and favourites.
- It reports startup and use to the counter described above, without sending the page address, and checks whether a newer version of the extension exists.
- It keeps in the extension's storage area, on your device: the identifier, the server address, the activation switch, the email you may have signed in with, and any update notice.
- When you open the form to write a review, it reads the structured data the page already publishes (the markers used by search engines: product or place name, image, barcode, city, title) so as to suggest the right subject without your having to type everything. Those values leave the browser only if you save the review, and only the ones you confirmed.
What it does not do
- It does not collect the content of the pages you visit: not the text, not the images, not the documents you open. The exception is the use of a verification feature, which presupposes a deliberate action on your part: in that case the text of the verified page is transmitted together with the contribution. Merely visiting a page entails no processing of its content.
- It does not intercept what you type into forms: not credentials, not searches, not messages, not banking details.
- It does not take screenshots of the page.
- It does not build a browsing history linked to you. The page address serves to query the pin store; it is not kept in a list of the pages you have visited.
- It does not use cookies and does not contact third-party advertising or analytics networks.
- It sends nothing, and does not even touch the page, if you switch it off from its panel.
You can switch the extension off at any time from its panel: from that moment it no longer activates on any page. You can uninstall it from your browser settings: uninstalling also removes everything it had stored on the device. Content already saved on the service remains, and is deleted from your personal area.
7. The embed on third-party websites
A website can activate PINTRU for its visitors by including one line of code in its pages. In that case pins appear to whoever visits that website, without their having to install anything.
Our script is designed to be discreet by default. Until the host website declares consent collected from its visitor, it:
- does not write the identifier into the browser's local storage: the identity is temporary and is lost when the page is closed;
- does not send any usage report to our service.
If and when the host website declares consent, the identifier becomes persistent on the device and the usage report is sent, with any consent receipt passed on by the publisher.
There is one further case to be aware of: if you move a pin on the page by hand, the new position is remembered in the browser's local storage for that page, even without consent, so that the pins are not shuffled again on every reload. It is a display preference, it contains no identifying data and it stays on your device. The entry is described in the cookie policy.
Who is answerable for what. It is the website that includes the script that decides to activate PINTRU for its visitors: it falls to them to inform those visitors and, where necessary, to collect consent before activation. PINTRU supplies the technical tool and the mechanism by which consent is passed on, but cannot check whether it was actually collected. For this phase the publisher and PINTRU are joint controllers: the division of obligations, the contact point for data subjects and the rest of the arrangement are in the Joint controllership arrangement section of the integration terms.
8. Public content
The service distinguishes three levels of visibility: private (only you see the note), shared (visible to whoever has the link you generated) and public (visible to anyone opening that page with PINTRU active).
If you choose to publish, the content leaves your private sphere: it will be readable by people you do not know, it can be voted on and reported, and it can be copied or quoted elsewhere — like anything published on the web. Think carefully about what you write, particularly when it concerns identifiable people.
Reviews and public notes stay visible after your account is deleted, but detached from you: see the section Deleting your account. If you would rather they were removed entirely, you can ask for that.
9. If you are mentioned in content and you are not a user
Content published on PINTRU may concern you even though you have never used the service: a review of your business, a note mentioning you, a verification contribution on a page that talks about you. We process your data as controller, and we cannot inform you individually because we do not have your contact details and because doing so would involve disproportionate effort: this section is the measure the Regulation prescribes in that case, under Article 14(5)(b).
What data. The data contained in the content published by the user: your name or the name of your business, the opinion expressed, the contextual elements the author included. The source is always the user who wrote the content, never a collection carried out by us.
Why. To make available to the public opinions and information of interest to anyone about to choose a product, a service or a source. The basis is our legitimate interest in that informational function and in users' freedom of expression (art. 6(1)(f)), balanced against your rights within the limits of Article 85 of the Regulation and Articles 136 et seq. of the Italian Personal Data Protection Code.
What we do not do. We do not build profiles of the people mentioned, we do not aggregate the content concerning you for purposes other than reading it, we do not communicate it to third parties for their own purposes, and we do not use it for advertising.
What you can ask for, and how. By writing to info@pintru.com you can: find out what published content concerns you; ask for inaccurate data to be corrected; object to the processing, stating the grounds relating to your particular situation; ask for unlawful or damaging content to be removed; reply publicly to the review, in place of its removal. We respond within 30 days. If the request is granted, the content is removed or made inaccessible and the author is informed with the reasons, with the right to complain.
What we cannot do. We do not remove content merely because it expresses a negative or unwelcome opinion. We remove what is unlawful: unproven allegations of specific and damaging facts, personal attacks, disclosure of other people's personal data, anything that goes beyond the limits of the right to criticise. The reasons are explained in the terms of use.
If you consider the processing not to be compliant, you can turn to the Italian data protection authority (Garante per la protezione dei dati personali).
10. Automated moderation
To stop the service becoming a vehicle for insults, defamation or fake reviews, content intended for publication goes through a two-stage check: a local automated filter, which decides most cases on its own, and — for doubtful cases only — an assessment carried out by an external provider's artificial intelligence model.
When that assessment takes place:
- what is transmitted to the provider is the text of the content intended for publication and a few contextual elements: category, the page's domain, the name of the subject reviewed and any rating;
- what is not transmitted is your name, your email, your identifier, or the page's full address;
- the provider returns a structured verdict — publishable, to be reviewed, to be rejected — with a score and a brief explanation;
- the service relies on a language model provider; processing takes place on the provider's infrastructure, including outside the European Union. Who that is, at any given time, is stated in the list of providers and sub-processors, which we keep current and which carries the date it was last updated. The agreement with the provider is available on request from the contacts given above, and on request we will tell you which provider processed your data.
Non-public content is not sent to this check. Private notes and those shared by link do not leave our service.
The automated assessment may hold a piece of content pending (it stays visible only to you) or reject it. It is not a decision about you as a person and it produces no legal effects concerning you: it affects the publication of that single item of content, and you can ask for it to be reviewed by a person by writing to the contacts given above.
Of a decision that withholds, removes or makes inaccessible any content of yours you are given the reasons, stating the basis, the elements assessed and any use of automated tools; you may lodge a complaint under the procedure described in the terms of use, the examination of which is not entrusted solely to automated tools.
11. Where PINTRU does not operate
PINTRU is designed for the public pages of the web. We have set ourselves the goal that the service should not activate, and should stop operating, on pages where data is entered or consulted that must not reach us. This is a goal we pursue with progressive measures, not a result we can guarantee absolutely: no technique makes it possible to recognise with certainty the content of every page on the web. The categories we aim to exclude are the following:
- payment and checkout pages, and card or other payment instrument forms;
- authentication pages: sign-in, registration, credential recovery, two-step verification;
- restricted areas in which personal data of one's own or of third parties is consulted or entered;
- pages processing special categories of data within the meaning of Article 9 of the Regulation — health, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric data — or judicial data.
It is a minimisation measure: the safest way not to process a piece of data is not to be in a position to receive it. The exclusions are extended over time. The exclusions currently active operate on two levels. The service recognises from the page's address the typical paths of payment, checkout, sign-in, registration, credential recovery and personal areas, and does not activate on those pages. In addition, the extension and the script check the page's content and switch themselves off when they find a password field or a card details field, whatever the address. The check is repeated on the server, which in any case refuses to display or record content on those addresses.
12. The verification features and page content
The service provides features with which users assess how reliable what a page states is. They are introduced progressively and may be reserved to particular plans.
When you use one of these features, in addition to your contribution we may process the textual content of the page, or the part of it the verification refers to: without the verified text the statement could not be documented or reviewed. The text may be subjected to automated analysis, including by external providers, in order to assess how well founded the contribution is.
What we do not do, and do not intend to do. We do not collect the content of the pages you visit when you are not using a verification feature; we do not reconstruct your browsing history; we do not process the content of the pages excluded by the preceding section; we do not use these texts to profile you or for advertising purposes. What is processed is the statement being verified, not the person verifying it.
If the text of a page by its nature contains third-party personal data, we limit ourselves to what is necessary to document the statement. You can ask for a verification contribution and the text kept with it to be removed, under the section Your rights. The processing is based on performance of the service you requested and on our legitimate interest in making the verified statement documentable and open to review; the verified text is kept for as long as the contribution it refers to, and is deleted with it.
13. Who we share data with
We do not sell data and we do not pass it to third parties for their own purposes. We use providers who process it on our behalf or, where stated, as independent controllers:
| Provider | What for | What data it receives | Role | Where |
|---|---|---|---|---|
| Aruba S.p.A. | Infrastructure, servers and database | All the service's data, since it hosts it | Processor | Italy |
| Language model provider (who it is today) | Automated assessment of content intended for publication | The text of the content and minimal context, without data identifying the author | Processor | United States of America — standard contractual clauses |
| Google Ireland Limited | Sending service communications | The recipient's address and the message content | Processor | European Union |
| Google Ireland Limited, as measurement provider | Site measurement, only with your consent | Browsing data on our pages: pages viewed, referrer, device type, a browser identifier. Not your name, not your email, not the content you write | Independent controller for its own purposes — its own notice applies | European Union and United States |
| Google, as identity provider | Signing in with Google, if you choose it | The data you authorise at the time of sign-in | Independent controller — its own notice applies | European Union and United States |
| Payment service provider | Carrying out collection and renewals, on our instructions | The data you give it at the time of payment; we do not see it | Independent controller for its own obligations | European Union |
We do not use content delivery networks or third-party traffic protection services: the pages, the scripts and the typefaces are served directly from our own infrastructure, hosted in Italy. The only resource that may be requested from a third-party server is the measurement tool, and only after your consent: without it, your browser never contacts it.
Data may also be communicated to the authorities where the law requires it.
Transfers outside the European Union. Some providers process data in third countries: this is the case for the provider that carries out the automated assessment of content intended for publication and — if you consent to it — for the one providing site measurement. In those cases the transfer takes place on the basis of the safeguards provided for by Chapter V of the Regulation — in particular the standard contractual clauses adopted by the European Commission, where no adequacy decision applies — accompanied, where necessary, by an assessment of the circumstances of the transfer and by supplementary measures. You can ask for a copy from the contacts given above. For providers established in the European Union no further safeguard is required. For the language model provider, established outside the European Union, the transfer takes place on the basis of the standard contractual clauses adopted by the European Commission: the list of providers states who it is and where it processes.
14. How long we keep it
| Data | Retention |
|---|---|
| Account and content | For as long as the account is active, or until you ask for it to be deleted |
| Public content after account deletion | It stays in anonymous form, unless complete deletion is requested |
| Sessions | Until sign-out or account deletion |
| Email verification and password reset links | Short expiry; used requests are cleaned up periodically |
| Minimal billing data kept after deletion | 10 years, under civil and tax law obligations |
| Client and embed usage data | 12 months, then kept in aggregate form only |
| Application and security log | 12 months |
| Moderation outcomes and reports | 24 months from the decision, together with the related correspondence |
| Record of requests concerning personal data | Kept as proof that the request was dealt with, for 24 months |
15. Your rights
Right to object. Where we process your data on the basis of our legitimate interest — moderation, security, abuse prevention, aggregate usage measurement, publication of content concerning you — you have the right to object at any time, on grounds relating to your particular situation. If you object, we stop the processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or that the processing serves to establish, exercise or defend a legal claim. To exercise it, writing to info@pintru.com is enough.
You can ask at any time to access your data, to have it corrected, deleted or its processing restricted, to object to processing based on our legitimate interest, to receive in a readable format the data you provided to us, and to withdraw consent where it is the basis for processing.
Two of these rights you exercise yourself, from your personal area, without waiting for a reply:
- Export. You download a structured file with your profile, sessions (with tokens masked), subscriptions, pins and attachments, shares, reviews, verifications, votes, favourites, preferences, teams and usage data, plus the information that must accompany a copy of the data. Each section states whether the data is data you provided to us, data observed during use, or values calculated by the service. To prevent abuse the number of exports is capped over any twenty-four hour period.
- Deletion. Described in the following section.
For everything else, write to info@pintru.com. If you consider the processing not to be compliant, you can turn to the supervisory authority; in Italy this is the Garante per la protezione dei dati personali.
16. Deleting your account
Deletion is final and is carried out in a single operation. Before you confirm it you are shown a summary of what will be deleted, anonymised or kept. In the default mode:
- Deleted: your profile — email, password, name, picture, Google link, language —, all sessions, private notes and those shared by link together with their attached files, favourites, personalised pin arrangements, team memberships and the client usage data relating to you.
- Anonymised: reviews, verifications, votes and public notes already published. They stay readable — other users do not lose content they voted on or consulted — but the link to you as a person is removed and the service is no longer able to trace you.
- Kept: the bare minimum needed for accounting obligations — plan, status, subscription references held by the payment provider and dates, without email or personal particulars, with a retention deadline.
- Active subscriptions are cancelled with the payment provider before deletion: see the purchase terms.
- If you own a team with other members, ownership passes to the longest-standing member.
- Personal references are removed from the application log, leaving the event for security purposes.
If you would rather that public content too were deleted, you can ask for the complete mode: reviews, verifications and votes are deleted and the averages and verdicts of the pages involved are recalculated.
17. Security
We adopt appropriate technical and organisational measures: encrypted traffic, passwords kept only as a hash, tokens for verification and reset links kept in encrypted form, differentiated permissions for operators with sessions of limited duration, rate limits on requests, checks on uploaded files and removal of metadata from images. No measure removes risk entirely: should a data breach occur, we will act as the law requires.
18. Minors
The service is not intended for anyone under 14 years of age. If we become aware of an account created by a minor under that age, we will remove it.
19. Changes to this notice
We may update this document to keep it aligned with changes to the service or to the law. The version in force is always the one published on this page, with the date of the last update at the top. If the changes are substantial we will give notice by an appropriate means.
Previous versions
- Version 06 September 19, 2026 ·
- Version 05 September 17, 2026
- Version 04 September 17, 2026