PinChef Privacy Policy
Effective date: 16 August 2026 · Last updated: 16 August 2026
PinChef ("PinChef", "we", "us", or "our") provides a Pinterest automation service for food bloggers and content creators. This policy explains what personal data we collect, why we collect it, how long we keep it, and the rights you have over it. It applies to visitors to pinchef.net and to registered users of the PinChef dashboard and service.
This policy is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, for users located in the European Economic Area, the EU General Data Protection Regulation (EU GDPR).
1. Who we are
PinChef is operated by Alex Dingwall, trading as PinChef (a sole trader, not a registered company). For the purposes of GDPR, Alex Dingwall is the data controller for the personal data described in this policy.
2. What data we collect
2.1 Data you provide directly
- Account information: name, email address, and a hashed password when you sign up.
- Billing information: handled by Stripe on our behalf — PinChef never receives or stores your card number. We retain your Stripe customer and subscription identifiers to manage your plan.
- Site and brand information: the URL of your blog, and any brand settings you enter or edit (colours, fonts, logo, watermark text).
- Pinterest account connection: when you connect Pinterest via OAuth, we receive an access token and refresh token scoped to the permissions you approve (reading and creating pins and boards on your behalf). We never see or store your Pinterest password.
- Support communications: anything you send us via email or support channels.
2.2 Data we collect automatically from your blog
- Recipe post content: post URLs, titles, descriptions, categories, tags, and image URLs, gathered by periodically scanning the RSS feed of the site(s) you connect.
- Images: recipe photos are downloaded from your site and used to generate pin images. Generated pins are stored in our object storage (Cloudflare R2) so they can be previewed in your dashboard.
2.3 Data generated by using the service
- Pin job records: what was generated, scheduled, and posted, including status and any error messages, forming your activity history within PinChef.
- Pinterest analytics: if enabled on your plan, impression, save, and click counts for pins PinChef has posted, fetched from the Pinterest API.
- Usage and diagnostic data: standard application logs (e.g. errors, request timing) that do not include full request bodies or credentials.
2.4 Data we do not collect
- We do not collect your Pinterest password — authentication happens directly between you and Pinterest via OAuth.
- We do not use tracking cookies or third-party advertising trackers on the PinChef dashboard (see Section 8, Cookies).
3. Why we process your data (lawful basis)
We rely on the following lawful bases under UK/EU GDPR:
- Performance of a contract: processing your account details, site data, recipe content, and Pinterest tokens is necessary to provide the core service you signed up for — generating and posting pins on your behalf.
- Legitimate interests: sending transactional emails (failed pin alerts, trial expiry notices), maintaining security logs, and preventing fraud or abuse of the service.
- Consent: where we ask for it explicitly — for example, if we introduce optional marketing communications or non-essential analytics cookies in the future. You may withdraw consent at any time.
- Legal obligation: retaining certain billing records as required by tax and accounting law.
We do not sell your personal data, and we do not use your recipe content or images for any purpose beyond providing the PinChef service to you.
4. Who we share data with
We share data only with service providers (sub-processors) who help us operate PinChef, under data processing agreements that require them to protect your data to at least the standard required by GDPR. We do not sell or rent personal data to third parties, and we do not share it for third-party advertising purposes.
- Railway — application hosting, database, and background job infrastructure
- Cloudflare — object storage (R2) for generated pin images, and domain/DNS services
- Stripe — payment processing and subscription billing
- Resend / Postmark — transactional email delivery (verification, password reset, alerts)
- Pinterest — the platform you connect to; PinChef posts to Pinterest on your behalf using the permissions you grant
- Sentry — error monitoring, used to diagnose and fix bugs (does not receive passwords or tokens)
Each of these providers processes data under its own privacy policy and a data processing agreement with PinChef. We may also disclose data where required by law, to enforce our terms of service, or to protect the rights, property, or safety of PinChef, our users, or others.
5. International data transfers
Our infrastructure providers may process data outside the UK/EEA, including in the United States. Where this occurs, we rely on appropriate safeguards recognised under UK/EU GDPR, such as Standard Contractual Clauses or the provider's adequacy certifications, to ensure your data receives an equivalent level of protection.
6. How long we keep your data
- Generated pin images (posted): 90 days from posting, then deleted from storage. Pinterest continues to host the pin itself after this point.
- Generated pin images (failed jobs): 30 days, then deleted.
- Pin job history, recipe data, and analytics: retained for the lifetime of your account, as your activity history and reporting.
- Account data after deletion: soft-deleted immediately (access and posting stop at once), then permanently erased after a 30-day grace period, in case you change your mind.
- Billing event records: pruned after 7 days on our side; Stripe retains its own records as required by financial regulation.
- Security and application logs: retained for 30 days.
When we no longer need personal data for these purposes, we delete or anonymise it.
7. Your rights
If you are located in the UK or EEA, you have the following rights over your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure: ask us to delete your account and associated personal data (you can also do this directly from account settings).
- Right to restrict processing: ask us to limit how we use your data in certain circumstances.
- Right to data portability: request your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy@pinchef.net. We will respond within 30 days. We do not include decrypted Pinterest tokens in any data export, as this would itself be a security risk to your Pinterest account.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may complain to your local data protection authority.
8. Cookies
The PinChef dashboard uses only essential cookies required for you to stay logged in — specifically, secure, HTTP-only session cookies used for authentication. These are not used for tracking or advertising, and because they are strictly necessary for the service to function, no cookie consent banner is required for them under UK/EU rules.
If we introduce analytics or other non-essential cookies in the future, we will update this policy and request your consent first, via a cookie banner.
9. How we protect your data
- Pinterest access and refresh tokens are encrypted at rest and never stored or logged in plain text.
- Passwords are hashed using argon2id, a modern, industry-recommended hashing algorithm — we never store plain-text passwords.
- All data in transit is encrypted via HTTPS/TLS.
- Access to production systems is restricted and protected by two-factor authentication.
- Stripe webhook events are cryptographically verified to prevent forged billing events.
- Rate limiting is applied across our API to reduce the risk of abuse.
No method of transmission or storage is 100% secure, but we design PinChef's systems with these protections as a baseline, not an afterthought.
10. Children's privacy
PinChef is intended for use by professional and hobbyist content creators aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time, for example as PinChef adds features or as legal requirements change. If we make material changes, we will notify registered users by email before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision.
12. Contact us
If you have any questions about this policy or how PinChef handles your data, contact us at privacy@pinchef.net or write to us at 2/1 47 Havelock Street, Glasgow, G11 5HA.