Privacy Policy

Transparency about how we collect, use, and protect your personal information.

Not affiliated with Telegram, Meta, TikTok or X

What we collect

  • Account & billing info
  • Service usage data

Why we collect

  • Provide our service
  • Security & compliance

Your choices

  • Access, export, delete
  • Opt-out marketing

1. Introduction

EMİRHAN GÜVEN GÜVEN YAZILIM HİZMETLERİ, a sole proprietorship registered in Istanbul, Türkiye (MERSİS 4872729489000001) ("we," "us," or "our"), operates Pinlyx, an omnichannel CRM and social media management platform (the "Service"), and is the data controller for the personal information described in this policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service available at pinlyx.com and app.crmsolid.com.

You can contact us at privacy@pinlyx.com.

This policy should be read alongside ourTerms of Service andData Processing Addendum.

2. Scope & Roles

We act in different capacities depending on the type of data:

  • Data Controller for website analytics, account management, and billing information
  • Data Processor for customer-uploaded contacts, message content, and automation sequences
  • Joint Controller with customers for certain AI features when enabled

See our Data Processing Addendum for more details.

3. Information We Collect

Information You Provide

  • Account details: name, email, password, profile information
  • Workspace information: team names, member roles, organization details
  • Billing information: payment methods, billing addresses, transaction history
  • Support communications: tickets, chat messages, feedback

Information Collected Automatically

  • Device information: IP address, browser type, operating system, device identifiers
  • Usage data: pages visited, features used, time spent, click patterns
  • Technical logs: error reports, performance metrics, API calls
  • Cookies and tracking technologies as described in our Cookie Policy

Connected Account & Service Data

  • Connected account data for the platforms you link — Telegram, Instagram, Facebook, WhatsApp, X (Twitter), TikTok, LinkedIn and email/IMAP — such as profile information, your published content/posts, messages, and comments, accessed only through each platform's official API and only on your instruction
  • OAuth access tokens and connection credentials for linked accounts, stored encrypted and revoked/deleted when you disconnect the account
  • Contact lists and conversation histories (processed on your behalf)
  • Automation sequences, templates, scheduled posts, and campaign data
  • Scraping results and lead information

We use connected-platform data solely to provide the features you enable (e.g., publishing posts, syncing your inbox, replying to messages). We do not sell it, and we do not use it to train AI models. Disconnecting an account removes its stored tokens and synced data.

AI Features Data

When AI features are enabled, we may process prompts, generated content, and feedback. This data may be sent to third-party AI providers under their terms and privacy policies.

4. How We Use Information (Purposes & Legal Bases)

We use your information for the following purposes:

  • Provide and maintain the Service (Legal basis: Contract performance)
  • Process payments and manage subscriptions (Legal basis: Contract performance)
  • Authenticate users and prevent fraud (Legal basis: Legitimate interests)
  • Provide customer support and respond to inquiries (Legal basis: Contract performance)
  • Improve our Service through analytics and research (Legal basis: Legitimate interests)
  • Send transactional communications (Legal basis: Contract performance)
  • Comply with legal obligations (Legal basis: Legal obligation)
  • Send marketing communications with consent (Legal basis: Consent)

We comply with GDPR, KVKK, CCPA, and other applicable privacy laws.

5. Cookies & Tracking

We use cookies and similar technologies for:

  • Essential cookies: Authentication, security, basic functionality
  • Analytics cookies: Usage statistics, performance monitoring
  • Marketing cookies: Personalized content, advertising (with consent)
  • Preference cookies: Language, theme, user settings
View Cookie Policy

6. AI & Model Providers

AI features are optional and can be disabled in your account settings. When enabled:

  • Content and metadata may be processed by our AI providers (Anthropic / Claude and OpenAI) under their terms
  • We disable training on your data by default where possible
  • You can opt-out of AI processing at any time
  • AI-generated content should be reviewed before use

7. Connected Platforms & Third-Party Services

Our Service integrates with the following platforms and third-party services. When you connect an account, you authorize us to access it on your behalf through its official API:

  • Connected platforms: Telegram, Meta (Instagram, Facebook, WhatsApp), X (Twitter), TikTok, LinkedIn, and Google / YouTube
  • AI providers: Anthropic (Claude) and OpenAI
  • Email delivery and inbox sync (Resend and your own IMAP/SMTP provider)
  • Payment processors for billing (Stripe, PayPal, Iyzico, PayTR, and others)
  • Analytics and product telemetry providers
  • GeoIP lookup, error monitoring, and cloud infrastructure providers

Each platform handles your data under its own terms and privacy policy. See ourSecurity Page andData Processing Addendum for more information.

8. Google User Data

This section covers information we receive from Google when you connect a Google account to Pinlyx. Nothing here applies unless you connect one. Connecting is always your own choice, and you can undo it at any time.

What we request, and why

  • Sign-in (openid, email, profile): to create or match your Pinlyx account and to show your name and picture inside the app. We never see or store your Google password
  • Google Ads (https://www.googleapis.com/auth/adwords): to list the Google Ads accounts you choose to grant us, read their performance figures, and, where you ask for it, create and manage campaigns, ad groups, ads and keywords on your behalf
  • Offline conversion import: to send conversions recorded in your own CRM back to the Google Ads account you connected, so that your reporting there is complete

What we do with it

  • We show it back to you inside your own workspace, and act on it only when you ask us to
  • Campaign changes follow an action you take in the product. Nothing is created, paused, edited or published on your Google Ads account automatically
  • Performance figures are cached briefly, for about fifteen minutes, so screens load quickly, and are refreshed from Google on demand
  • We request only the scopes listed above, and only when you start the connection yourself

How it is stored and protected

Your Google authorisation token is encrypted at rest with AES-GCM under a key held outside the database, and is scoped to your workspace alone. Google data is never sold, never rented, and never shared for advertising, and it never reaches anyone outside the processors named in this policy.

How to disconnect

Disconnect the account from its settings screen inside Pinlyx, which deletes the stored token straight away, or revoke our access at any time from yourGoogle account permissions page. Deleting your Pinlyx account deletes it as well.

Limited Use disclosure (Google API Services)

Pinlyx's use and transfer of information received from Google APIs to any other app will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. We do not allow humans to read it, except with your explicit consent for specific messages, where required for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised. We do not transfer it except as necessary to provide or improve Pinlyx, to comply with applicable law, or as part of a merger or acquisition that we disclose to you.

9. Meta Platform Data (Instagram, Facebook, WhatsApp)

This section covers information we receive from Meta Platforms when you connect an Instagram professional account, a Facebook Page or a WhatsApp Business account to Pinlyx through Meta's official APIs. Nothing here applies unless you connect one, and you can disconnect at any time.

What we request, and why

  • Facebook Login (public_profile, pages_show_list, business_management): to list the Facebook Pages, Instagram accounts and business assets you manage, so you can choose which ones to connect
  • Instagram (instagram_basic, instagram_manage_messages, instagram_manage_comments): to show your Instagram professional account's name and picture, and to read and answer its Direct messages and comments from your Pinlyx inbox
  • Facebook Pages (pages_messaging, pages_manage_metadata, pages_read_engagement): to receive and answer Messenger conversations for the Pages you connect, and to subscribe those Pages to message notifications
  • WhatsApp Business (whatsapp_business_management, whatsapp_business_messaging): to send and receive WhatsApp messages for the business phone numbers you connect

What we do with it

  • Conversations, comments and the sender's public profile (name, username and picture) are shown inside your own workspace, so your team can answer them and keep a customer record
  • A message is sent on your account only when you or a teammate sends it, or when an AI agent you switched on replies under the rules you set
  • Meta data is never sold, never rented, never used to build advertising profiles, and never shared with other Pinlyx workspaces
  • We use it in line with the Meta Platform Terms and Meta's Developer Policies

How it is stored and protected

Access tokens issued by Meta are encrypted at rest with AES-GCM under a key held outside the database and are scoped to your workspace alone. Synced conversations stay in your workspace until you delete them, disconnect the account and ask us to erase them, or delete your Pinlyx account.

How to delete your Meta data

  • Disconnect the account from the Accounts page in Pinlyx. This deletes the stored Meta access token straight away and stops all syncing
  • Remove Pinlyx from your Facebook settings under Settings & privacy, then Settings, then Business integrations. This revokes our access on Meta's side as well
  • To erase the conversations and contact records that were already synced, delete your Pinlyx account from its account settings, or email support@pinlyx.com with the subject "Data deletion request" and the account you connected
  • We complete deletion requests within 30 days and confirm by email once they are done. Backups are purged within the same 30 days

10. Browser Extension (Pinlyx Clipper)

Pinlyx Clipper is our optional browser extension for Chrome and Microsoft Edge. It saves the profile or web page you are looking at into your own Pinlyx workspace. Nothing in this section applies unless you install it.

What it reads

Only the page you are looking at, and only at the moment you ask it to: when you click the toolbar icon, press its keyboard shortcut, choose one of its two right-click menu items, or press the Save control it draws on X and Instagram profiles. It never opens a page by itself, never navigates or scrolls in the background, and never reads a tab you did not open yourself.

What it sends to us

  • The profile or page you choose to save: name, handle, headline, company, location, profile picture address, and any email address or phone number the page itself displays
  • The note, tags and pipeline stage you type, and any text you highlighted and saved as a note
  • On a profile page where the extension shows one of its own controls, the address of that page, so it can tell you whether that person is already in your CRM. We resolve it to a deduplication key and keep nothing else from that check. This does not happen on LinkedIn, where the extension shows no control
  • On an X profile, the handle, so the lead score card can be filled in. This is the one request that does not wait for a click, and it happens only where that card can appear
  • When you press Find email, the person's name, company and website address, so our server can rank the addresses worth trying. We do not send or verify mail on your behalf
  • When you use the business lookup or the AI actions, the identity of the business or profile on screen
  • When you select people from a list already open on your screen and press save, only the rows you ticked
  • Technical data needed to run the request: the extension version, a device label you can edit, and the IP address the request arrives from

What it never does

  • It contains no analytics, telemetry, advertising or tracking code of any kind
  • It contacts no server other than api.crmsolid.com
  • It never sends a message, a connection request, a follow or any other action on your behalf
  • It does not read your passwords, your form entries, or your browsing history
  • What you capture is never sold, rented, or shared with anyone outside the processors listed in this policy

Where it is stored, and for how long

Captured contacts live in your own Pinlyx workspace under the account the extension is connected to, and follow the retention rules in the Data Retention section below: deleting the contact or closing your account deletes them. Before you connect an account at all, the extension works offline and holds what you save in your own browser only, in local extension storage, where it is never transmitted to us. You can export those to CSV or clear them without ever creating an account.

Its access token

Connecting the extension mints a token that belongs to the extension alone and can reach nothing but the extension endpoints of our API. It is held in local browser storage and deliberately never in synchronised storage, so it is never copied to your other devices or browser profiles. You can revoke it at any time from the extension's own settings screen or from your Pinlyx account, and revoking it stops all access immediately.

Limited Use disclosure

Pinlyx's use and transfer of information received from Google APIs to any other app will adhere to theChrome Web Store User Data Policy, including the Limited Use requirements. The same commitment applies to the Microsoft Edge Add-ons programme.

11. Data Sharing

We may share your information in the following circumstances:

  • With service providers and processors under appropriate agreements
  • With members of your organization or workspace as configured
  • For legal compliance, court orders, or regulatory requirements
  • In connection with a merger, acquisition, or sale of assets (with notice)
  • With your explicit consent for specific purposes

12. International Transfers

We may transfer your data internationally using appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for certain countries
  • Supplementary measures where required
  • Data residency options available for Enterprise customers

Primary data processing occurs in European Union (Frankfurt, Germany).

13. Data Retention

We retain different types of data for varying periods:

  • Account data: Until account deletion plus 30 days
  • Billing records: 7 years for tax and accounting purposes
  • Service logs: 90 days for security and debugging
  • AI interaction logs: 30 days unless opted out
  • Customer data: As directed by customer or until service termination

Workspace administrators can delete or export data through our self-service tools.

14. Security

We implement appropriate technical and organizational measures:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Network isolation and access controls
  • Regular security audits and penetration testing
  • Employee security training and background checks
  • Incident response and breach notification procedures

You are responsible for maintaining strong authentication, securing API keys, and managing user permissions.

15. Your Rights

Depending on your location, you may have the following rights:

GDPR/KVKK Rights

  • Right of access: Request copies of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your data
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured format
  • Right to object: Opt-out of certain processing activities

CCPA/CPRA Rights

  • Right to know: What personal information we collect and how it's used
  • Right to delete: Request deletion of your personal information
  • Right to opt-out: Opt-out of sale or sharing of personal information
  • Right to non-discrimination: Equal service regardless of privacy choices

To exercise your rights, use our or email privacy@pinlyx.com. We'll verify your identity and respond within applicable timeframes.

Deleting Your Data

You can delete your data at any time: disconnect any linked platform (Telegram, Instagram, Facebook, WhatsApp, X, TikTok, LinkedIn, email) to remove its stored tokens and synced content, delete your account from Settings → Account to erase your workspace data, or email privacy@pinlyx.com with a deletion request. Backups are purged within 30 days.

16. Children's Privacy

Our Service is not directed to children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

17. Workspace Admin Controls

Workspace administrators have additional controls and responsibilities:

  • Access to user data within their workspace
  • Ability to export and delete workspace data
  • User management and permission controls
  • Access to audit logs and activity reports
  • Responsibility for user consent and data protection compliance

18. Communications & Marketing

We send different types of communications:

  • Transactional emails: Account notifications, billing, security alerts
  • Product updates: New features, service changes, maintenance notices
  • Marketing emails: Newsletters, promotions (with consent)
  • Support communications: Responses to your inquiries

You can unsubscribe from marketing emails using the links provided or through your account settings.

19. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified via:

  • Email notification to registered users
  • Prominent notice on our website
  • In-app notifications for significant changes

The effective date is shown at the top of this policy.

20. Contact

For privacy-related questions or to exercise your rights, contact us:

Data Protection OfficerEMİRHAN GÜVEN GÜVEN YAZILIM HİZMETLERİ, Küçükçekmece, Istanbul, Türkiye

We value your privacy

We use cookies to improve our site, analyze traffic, and personalize ads. You can accept all, reject non-essential, or customize your choices. Read our Cookie Policy.