TrustPin™
™
HomeFeaturesSecuritySDKs & CLIFAQPricingAbout

Privacy Policy

Effective date: June 2, 2026

Last updated: August 4, 2026

About this Policy

TrustPin ("TrustPin", the "Service") is a certificate-pinning platform operated by Capa7 LLC, a Wyoming limited liability company ("Capa7", "we", "our", or "us"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have. It applies to https://trustpin.cloud, the TrustPin web console at https://app.trustpin.cloud, our documentation site, our APIs, and the TrustPin SDKs.

We have written this policy to be readable. Where defined terms from the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act, as amended by the CPRA (together, “CCPA”), apply, we use them with their statutory meaning.

It should be read together with our Cookie Policy, Acceptable Use Policy, and Sub-processor List.

1. Data Controller & Contact

The data controller for personal data processed under this policy is:

Legal entity: Capa7 LLC, a Wyoming limited liability company

Principal and mailing address: 1007 N Orange Street, 4th Floor, Suite 3317, Wilmington, DE 19801, United States

Privacy contact: privacy@trustpin.cloud

General support: support@trustpin.cloud

For all privacy questions, GDPR/CCPA rights requests, DPA requests, or sub-processor questions, please contact privacy@trustpin.cloud.

2. Scope: the two data layers

TrustPin works with two clearly separated data layers, and our role and obligations differ between them. We describe both up front so the rest of this policy is unambiguous.

Layer A: TrustPin account holders

Developers, security engineers, and companies who sign up for TrustPin. For this layer, we act as the data controller of the minimal personal data needed to operate the account (name, email, company info, OAuth profile basics, support communications, and usage/log data described in section 3).

Layer B: End users of customer apps

People using mobile or desktop apps that embed our SDK. TrustPin is not designed to collect identifying personal data about users of customer applications. On each request the SDK transmits only limited, non-identifying technical metadata needed to retrieve and validate configuration (described in section 4). TrustPin-managed CDN and infrastructure providers may transiently process IP addresses and network metadata as technically necessary to deliver configuration content; TrustPin does not intentionally use those identifiers to identify application end users and does not retain them except as described in this Policy or the applicable provider retention terms. With respect to this metadata, TrustPin does not act as a controller or processor of identifying personal data about end users.

3. Information we collect from account holders (Layer A)

Information you provide to us

  • Account information: name, email address, and company information.
  • OAuth profile basics received via Auth0 (our identity layer) when you sign in with a third-party identity provider (Google, GitHub, and similar): typically name, email address, and profile picture. We do not receive your password.
  • Service configuration data: certificate pin sets, project metadata, signing key references, and other configuration you enter. This is not personal data about end users.
  • Support communications, feedback, and content you submit to us.
  • Billing contact details if you are on a paid plan or support contract (see section 5 for billing).

Information collected automatically when you use the console or APIs

  • Usage and product analytics for the console and marketing site (see section 7, Cookies & Analytics).
  • Device and browser information (user agent, language, approximate location derived from IP geolocation at the network layer for the console only).
  • IP address of the device accessing the console or APIs, processed for security, abuse prevention, and operational logging.
  • Application and security logs (request paths, status codes, error reports, audit events).

Customers should minimize or redact personal data before submitting logs, screenshots, crash reports, diagnostic files, or other support materials, and should not submit special-category or highly sensitive data unless Capa7 has expressly agreed in writing.

4. What the SDK sends (Layer B)

When the TrustPin SDK embedded in a customer’s app fetches its pinning configuration, the request carries only non-identifying technical metadata, in the User-Agent string:

  • SDK version.
  • The app’s bundle identifier and app version (identifies the app, not the user).
  • The operating system name and OS version.
  • A coarse, continent-level region (Americas / Europe / Asia-Pacific / Africa / Other) derived from the device timezone, not from IP geolocation.

The SDK does not send device identifiers, advertising identifiers, names, email addresses, precise location, or any other end-user data. TrustPin does not use request IP addresses to identify end users and does not store them in its application databases. Raw CDN access logs, which include the requesting IP address, are retained for a limited period in secured storage for security, abuse prevention and the generation of anonymous aggregate statistics (such as the number of distinct clients per day), and are automatically deleted on a rolling basis. Only the aggregate counts are retained long-term; individual addresses cannot be reconstructed from them.

Because two different users of the same app, OS, and region produce an identical string, this metadata cannot be used to single out an individual end user. Like any networked service, the global CDN edges that deliver public configuration may transiently process the IP address of a device fetching it for the purpose of delivery, and TrustPin handles any such addresses only as described above.

5. How we use account-holder data

We use the personal data described in section 3 to:

  • Provide, maintain, and improve the TrustPin platform and the services you request.
  • Authenticate you, create and administer your account and organization, and enforce access controls.
  • Send service-related communications: technical notices, configuration changes, security alerts, and updates to this policy.
  • Respond to support requests and feedback.
  • Issue and reconcile invoices for paid plans or ad-hoc support contracts. TrustPin does not operate an integrated payments system; billing for paid plans is handled out-of-band via invoicing. We do not store payment-card data.
  • Monitor service usage, performance, and reliability, and detect, investigate, and prevent abuse, fraud, and security incidents.
  • Comply with our legal obligations.

6. Legal bases (GDPR Art. 6)

For account holders in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases for processing personal data:

  • Performance of a contract: to create and operate your account, deliver the service, provide support, and issue invoices (Art. 6(1)(b)).
  • Legitimate interests: to secure the service, prevent abuse and fraud, maintain operational and security logs, and improve our product. We balance these interests against your rights and freedoms (Art. 6(1)(f)).
  • Consent: for non-essential cookies and analytics, and for any marketing communications. You can withdraw consent at any time (Art. 6(1)(a) and Art. 7).
  • Legal obligation: to comply with applicable laws, lawful requests from authorities, tax or accounting obligations, and similar duties (Art. 6(1)(c)).

7. Cookies & analytics

Our website and console use a small number of cookies and similar technologies. We group them into three categories:

  • Strictly necessary: required for the site or console to function (e.g., session, authentication, security, load balancing). These are set without consent because the service cannot operate without them.
  • Preference: remember non-essential choices such as theme or language. Set only with your consent.
  • Analytics and performance: help us understand how the site and console are used so we can improve them. We currently use Vercel Web Analytics and Vercel Speed Insights, which are first-party analytics provided by our hosting platform, and, on the marketing site, Google Analytics 4, which sets cookies and shares usage data with Google LLC. Set only with your consent where required by law.

On your first visit, a consent banner lets you accept or reject non-essential cookies. Analytics and preference cookies stay off until you opt in. You can change or withdraw your choice at any time via the “Cookie Settings” link in the footer. We do not use cookies for cross-site advertising and we do not share cookie data with advertising networks. See our Cookie Policy for the full list of cookies and technologies we use.

8. Sharing & sub-processors

We do not sell or rent your personal data, and we do not share it with third parties for their own marketing. We share personal data only with the following categories of recipients:

  • Infrastructure sub-processors that host or deliver the service on our behalf, listed below.
  • Identity layer and federated identity providers: we use Auth0 (Okta, Inc.) as our identity layer. When you choose to sign in with a third-party identity provider (Google, GitHub, or similar), Auth0 federates the authentication and passes the necessary profile information back to us.
  • Professional advisors (e.g., legal, accounting) under confidentiality obligations.
  • Authorities where disclosure is required by law or to protect our rights, the safety of users, or the integrity of the service.
  • Acquirers in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and equivalent protection of your data.

Current sub-processors

Sub-processorPurposeRegion
DigitalOceanPrimary platform hosting (databases, APIs, application servers)EU (Frankfurt)
Amazon Web Services (AWS)Mobile configuration origin and supporting infrastructureEU (Ireland); supporting and edge processing may be global
Cloudflare, Inc.CDN, edge delivery, routing, security, and availability for configuration deliveryGlobal edge network
VercelMarketing site and console hosting, edge delivery, Web Analytics, Speed InsightsUnited States & global edge
Auth0 (Okta, Inc.)Authentication & identity management for the web console (sign-in, sessions, tokens); federates third-party identity providersEurope
GoogleIdentity provider federated through Auth0 when you choose Google at sign-in; Google Analytics 4 usage analytics on the marketing site (loaded only with your consent)United States & global
GitHubIdentity provider federated through Auth0 when you choose GitHub at sign-inUnited States & global
Proton AGAccount email delivery and inbound support mailSwitzerland

TrustPin’s management systems, including the dashboard, management API, primary databases, and Auth0 tenant, are hosted in the European Union. Configuration content may be cached or delivered through global CDN edge locations outside the EEA. Content delivery networks operated by the sub-processors above may transiently process the IP address and network metadata of a device fetching public configuration at the network layer for delivery. TrustPin does not store that IP address in its application databases; raw CDN access logs containing it are retained only for a limited period and then automatically deleted (see section 10).

For customers covered by a DPA, Capa7 ordinarily provides at least 30 days’ prior notice of a new or replacement sub-processor that will process Customer Personal Data. Shorter notice may apply where a change is urgently required for security, legal compliance, service continuity, or provider discontinuation.

The full, current list is published on our Sub-processor List. Questions may be sent to privacy@trustpin.cloud.

9. International data transfers

Account-holder data is hosted in the European Union, and our Auth0 tenant is in the EU region. Where personal data is transferred to or accessed from outside the European Economic Area, the United Kingdom, or Switzerland (including by US-based sub-processors such as Vercel, AWS group entities, Cloudflare, Google, and GitHub), we rely on the following safeguards under GDPR Chapter V:

  • EU Standard Contractual Clauses (SCCs) with sub-processors that do not benefit from an adequacy decision, supplemented where appropriate by additional technical and organizational measures.
  • EU–US Data Privacy Framework (DPF) where a US sub-processor is self-certified and the transfer falls within the certification.
  • Adequacy decisions, including for transfers to Switzerland and the United Kingdom.

You can request a copy of the relevant transfer mechanism for any sub-processor by writing to privacy@trustpin.cloud.

10. Data retention

We retain personal data for as long as needed for the purposes described in this Policy. Our default retention periods are:

  • Account and organization data: active term plus 30 days after closure.
  • Configuration data: contract term plus 30 days after termination.
  • Support tickets and attachments: 12 months after ticket closure.
  • Security and audit logs: up to 12 months.
  • Raw CDN access logs (including the requesting IP address): a limited period, then automatically deleted; only anonymous aggregate counts are retained long-term.
  • Backups: normal overwrite cycle, generally within 90 days.
  • Billing and tax records: the period required by applicable law.
  • CDN / network data: provider defaults where Capa7 does not control retention.

We may retain certain information longer where required by law or for the establishment, exercise, or defence of legal claims.

11. Data security

We use technical and organizational measures appropriate to the nature of the Service and the risks involved. These may include encryption in transit, encryption at rest where supported by the relevant provider, restricted administrative access, logging, automated backups, documented restore procedures, incident-response processes, and authentication through Auth0.

Capa7 does not currently require multi-factor authentication for every dashboard user, although customers may use external identity providers that support additional security controls.

No system can be guaranteed completely secure. If we become aware of a personal-data breach affecting you, we will notify you and any competent supervisory authority as required by applicable law.

12. Your rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:

  • Access: obtain confirmation of whether we process your data and a copy of it (Art. 15).
  • Rectification: correct inaccurate or incomplete data (Art. 16).
  • Erasure: request deletion where one of the grounds in Art. 17 applies.
  • Restriction: require us to limit processing in certain circumstances (Art. 18).
  • Objection: object to processing based on our legitimate interests (Art. 21).
  • Portability: receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible (Art. 20).
  • Withdraw consent: where processing relies on your consent, withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3)).
  • Lodge a complaint: with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement (Art. 77).

To exercise any of these rights, write to privacy@trustpin.cloud. We will respond within one month of receipt. Where a request is complex or we receive a number of requests, we may extend that period by up to two further months as permitted by law and will tell you within the first month. We may need to verify your identity before acting on a request.

13. California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the following rights with respect to your personal information.

Categories of personal information we collect

  • Identifiers: name, email, account identifiers, IP address (console/APIs only).
  • Customer records: billing contact details for paid plans.
  • Commercial information: subscription/plan information.
  • Internet or network activity: service usage, log data, analytics.
  • Professional or employment information: company name and role you provide.

We use this information for the purposes described in section 5. We do not collect sensitive personal information for the purpose of inferring characteristics about you.

“Do not sell or share”

TrustPin does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. In the preceding twelve months we have not sold or shared personal information for those purposes.

Your CCPA rights

  • Right to know what personal information we have collected, used, disclosed, and shared.
  • Right to delete personal information we have collected from you, subject to statutory exceptions.
  • Right to correct inaccurate personal information.
  • Right to limit the use and disclosure of sensitive personal information (we do not use it for purposes that would trigger this right).
  • Right to non-discrimination for exercising your CCPA rights.

To exercise any of these rights, write to privacy@trustpin.cloud. You may use an authorized agent; we will verify the agent’s authority and your identity before acting on the request.

14. Data Processing Addendum (B2B customers)

We offer a GDPR Article 28 Data Processing Addendum (DPA) for business customers on request. Depending on the customer’s use of TrustPin, the DPA may cover account administration, authentication and access-control data, support materials, security and audit logging, configuration management, and limited transient network processing associated with configuration delivery.

To request the DPA, write to privacy@trustpin.cloud.

15. Children’s privacy

TrustPin is a business-to-business service for developers and security teams. It is not directed to children and we do not knowingly collect personal data from children. Consistent with GDPR Article 8, we do not knowingly process personal data of anyone under 16 (or the lower age set by an applicable EU member state, where it has set one between 13 and 16) and, consistent with the US Children’s Online Privacy Protection Act, we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, please contact privacy@trustpin.cloud and we will delete it.

16. Changes to this Policy

TrustPin may update this Policy and our privacy practices from time to time. For material changes, we will provide notice at least 30 days before they take effect, by email and/or a notice on this page, where required by applicable law or our agreements. Non-material changes, or changes required by law, may take effect immediately. We will update the “Last updated” date above to reflect the most recent revision.

17. Contact

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Capa7 LLC, a Wyoming limited liability company

1007 N Orange Street, 4th Floor, Suite 3317

Wilmington, DE 19801, United States

Privacy: privacy@trustpin.cloud

Support: support@trustpin.cloud

Website: https://trustpin.cloud

TrustPin

TrustPin is a certificate pinning platform that lets teams update SSL/TLS pins remotely, with no app release required.

Product

  • Features
  • Pricing
  • Integration
  • DevSecOps

Resources

  • Documentation
  • White Papers
  • FAQ
  • Platform Status

Company

  • About
  • Security
  • Partners
  • Contact

Developers

  • Swift SDK
  • Kotlin SDK
  • Flutter SDK
  • React Native SDK
  • CLI Tool

Legal

  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • Terms of Service
  • Sub-processors

© 2026 TrustPin™ by Capa7 LLC. All rights reserved.

Checking Status...