Privacy Policy
Last updated: 30 September 2026
1. Who we are
PinMarks (“PinMarks”, “we”, “us”) provides a visual bug reporting and feedback platform, including the PinMarks web app, the embeddable feedback widget and the PinMarks for Chrome browser extension (together, the “Service”). This policy explains what information we collect, how we use it and the choices you have. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
2. Information we collect
We collect the following types of information:
- Account information. Your name, email address and authentication details when you create an account or are invited to a workspace.
- Workspace content. Projects, feedback items, comments, annotations, assignments and settings that you and your team create.
- Feedback report data. When someone submits feedback through the widget or the extension, the report can include a screenshot, annotations, the page URL, browser and operating system details, screen size, console errors and, if provided, the reporter’s name and email address.
- Integration data. If you connect a third-party tool (for example Slack, Jira, GitHub or ClickUp), we store the access tokens and identifiers needed to send and sync feedback, comments and status changes with that tool.
- Usage and technical data. Basic logs such as IP address, request timestamps and error information, used to run and secure the Service.
3. The PinMarks for Chrome extension
The extension is designed to collect as little as possible. Specifically:
- Stored on your device. The extension saves your connected project’s API key, app URL, project name and the list of websites where you have enabled the widget. This is kept in Chrome’s local extension storage (
chrome.storage.local) on your device. - Screenshots on request only. A screenshot is captured only when you click the PinMarks button to report an issue. It is sent to your PinMarks workspace as part of that report. The extension does not capture pages in the background.
- Page access. The extension requests access to websites so it can show the feedback widget and capture the visible page when you ask it to. It does not read, record or transmit your browsing history, and it does not collect page content except what is included in a report you submit.
- No selling or advertising. We do not sell data obtained through the extension, use it for advertising, or use it to determine creditworthiness or for lending purposes. Data is used only to provide the reporting features you have asked for.
You can disconnect the extension at any time from its options page, or remove it from Chrome, which deletes the locally stored connection details.
4. How we use information
- To provide, operate and maintain the Service, including delivering feedback reports to your workspace and connected tools.
- To send transactional emails such as invitations, notifications about feedback and account messages, according to your notification preferences.
- To provide optional AI features, such as summarising or rewriting feedback, when you choose to use them.
- To secure the Service, prevent abuse, diagnose problems and improve performance.
- To respond to your enquiries and meet our legal obligations.
5. Who we share information with
We do not sell your personal information. We share it only as follows:
- Your workspace. Feedback and comments are visible to members of the workspace and project they belong to.
- Service providers. Trusted providers that help us run the Service, such as cloud hosting, database and file storage, email delivery and AI processing. They may only use the information to provide services to us.
- Integrations you enable. Tools you connect receive the feedback data needed for the integration to work.
- Legal reasons. Where required by law, or to protect the rights, safety and security of our users and the Service.
6. Storage, security and overseas disclosure
We use industry-standard safeguards including encryption in transit, access controls and per-workspace data separation. No system is completely secure, so we cannot guarantee absolute security. Our service providers may store or process information in countries outside Australia. Where this happens, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles.
7. Retention and deletion
We keep workspace data for as long as your account or workspace is active. Workspace owners and admins can delete a workspace at any time, which permanently removes its projects, feedback and related data. You can also ask us to delete your account information by contacting us. We may retain limited information where required by law or for legitimate security and record-keeping purposes.
8. Your rights
You can ask to access or correct the personal information we hold about you, or ask us to delete it. To make a request, email us using the details below. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
9. Cookies
We use cookies and similar technologies that are necessary to keep you signed in and to keep the Service secure. We do not use advertising cookies.
10. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.
12. Contact us
Questions or requests about privacy can be sent to hello@pinmarks.in.