Effective date: June 2, 2026
Last updated: August 4, 2026
TrustPin ("TrustPin", the "Service") is a certificate-pinning platform operated by Capa7 LLC, a Wyoming limited liability company ("Capa7", "we", "our", or "us"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have. It applies to https://trustpin.cloud, the TrustPin web console at https://app.trustpin.cloud, our documentation site, our APIs, and the TrustPin SDKs.
We have written this policy to be readable. Where defined terms from the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act, as amended by the CPRA (together, “CCPA”), apply, we use them with their statutory meaning.
It should be read together with our Cookie Policy, Acceptable Use Policy, and Sub-processor List.
The data controller for personal data processed under this policy is:
Legal entity: Capa7 LLC, a Wyoming limited liability company
Principal and mailing address: 1007 N Orange Street, 4th Floor, Suite 3317, Wilmington, DE 19801, United States
Privacy contact: privacy@trustpin.cloud
General support: support@trustpin.cloud
For all privacy questions, GDPR/CCPA rights requests, DPA requests, or sub-processor questions, please contact privacy@trustpin.cloud.
TrustPin works with two clearly separated data layers, and our role and obligations differ between them. We describe both up front so the rest of this policy is unambiguous.
Developers, security engineers, and companies who sign up for TrustPin. For this layer, we act as the data controller of the minimal personal data needed to operate the account (name, email, company info, OAuth profile basics, support communications, and usage/log data described in section 3).
People using mobile or desktop apps that embed our SDK. TrustPin is not designed to collect identifying personal data about users of customer applications. On each request the SDK transmits only limited, non-identifying technical metadata needed to retrieve and validate configuration (described in section 4). TrustPin-managed CDN and infrastructure providers may transiently process IP addresses and network metadata as technically necessary to deliver configuration content; TrustPin does not intentionally use those identifiers to identify application end users and does not retain them except as described in this Policy or the applicable provider retention terms. With respect to this metadata, TrustPin does not act as a controller or processor of identifying personal data about end users.
Customers should minimize or redact personal data before submitting logs, screenshots, crash reports, diagnostic files, or other support materials, and should not submit special-category or highly sensitive data unless Capa7 has expressly agreed in writing.
When the TrustPin SDK embedded in a customer’s app fetches its pinning configuration, the request carries only non-identifying technical metadata, in the User-Agent string:
The SDK does not send device identifiers, advertising identifiers, names, email addresses, precise location, or any other end-user data. TrustPin does not use request IP addresses to identify end users and does not store them in its application databases. Raw CDN access logs, which include the requesting IP address, are retained for a limited period in secured storage for security, abuse prevention and the generation of anonymous aggregate statistics (such as the number of distinct clients per day), and are automatically deleted on a rolling basis. Only the aggregate counts are retained long-term; individual addresses cannot be reconstructed from them.
Because two different users of the same app, OS, and region produce an identical string, this metadata cannot be used to single out an individual end user. Like any networked service, the global CDN edges that deliver public configuration may transiently process the IP address of a device fetching it for the purpose of delivery, and TrustPin handles any such addresses only as described above.
We use the personal data described in section 3 to:
For account holders in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases for processing personal data:
Our website and console use a small number of cookies and similar technologies. We group them into three categories:
On your first visit, a consent banner lets you accept or reject non-essential cookies. Analytics and preference cookies stay off until you opt in. You can change or withdraw your choice at any time via the “Cookie Settings” link in the footer. We do not use cookies for cross-site advertising and we do not share cookie data with advertising networks. See our Cookie Policy for the full list of cookies and technologies we use.
We do not sell or rent your personal data, and we do not share it with third parties for their own marketing. We share personal data only with the following categories of recipients:
| Sub-processor | Purpose | Region |
|---|---|---|
| DigitalOcean | Primary platform hosting (databases, APIs, application servers) | EU (Frankfurt) |
| Amazon Web Services (AWS) | Mobile configuration origin and supporting infrastructure | EU (Ireland); supporting and edge processing may be global |
| Cloudflare, Inc. | CDN, edge delivery, routing, security, and availability for configuration delivery | Global edge network |
| Vercel | Marketing site and console hosting, edge delivery, Web Analytics, Speed Insights | United States & global edge |
| Auth0 (Okta, Inc.) | Authentication & identity management for the web console (sign-in, sessions, tokens); federates third-party identity providers | Europe |
| Identity provider federated through Auth0 when you choose Google at sign-in; Google Analytics 4 usage analytics on the marketing site (loaded only with your consent) | United States & global | |
| GitHub | Identity provider federated through Auth0 when you choose GitHub at sign-in | United States & global |
| Proton AG | Account email delivery and inbound support mail | Switzerland |
TrustPin’s management systems, including the dashboard, management API, primary databases, and Auth0 tenant, are hosted in the European Union. Configuration content may be cached or delivered through global CDN edge locations outside the EEA. Content delivery networks operated by the sub-processors above may transiently process the IP address and network metadata of a device fetching public configuration at the network layer for delivery. TrustPin does not store that IP address in its application databases; raw CDN access logs containing it are retained only for a limited period and then automatically deleted (see section 10).
For customers covered by a DPA, Capa7 ordinarily provides at least 30 days’ prior notice of a new or replacement sub-processor that will process Customer Personal Data. Shorter notice may apply where a change is urgently required for security, legal compliance, service continuity, or provider discontinuation.
The full, current list is published on our Sub-processor List. Questions may be sent to privacy@trustpin.cloud.
Account-holder data is hosted in the European Union, and our Auth0 tenant is in the EU region. Where personal data is transferred to or accessed from outside the European Economic Area, the United Kingdom, or Switzerland (including by US-based sub-processors such as Vercel, AWS group entities, Cloudflare, Google, and GitHub), we rely on the following safeguards under GDPR Chapter V:
You can request a copy of the relevant transfer mechanism for any sub-processor by writing to privacy@trustpin.cloud.
We retain personal data for as long as needed for the purposes described in this Policy. Our default retention periods are:
We may retain certain information longer where required by law or for the establishment, exercise, or defence of legal claims.
We use technical and organizational measures appropriate to the nature of the Service and the risks involved. These may include encryption in transit, encryption at rest where supported by the relevant provider, restricted administrative access, logging, automated backups, documented restore procedures, incident-response processes, and authentication through Auth0.
Capa7 does not currently require multi-factor authentication for every dashboard user, although customers may use external identity providers that support additional security controls.
No system can be guaranteed completely secure. If we become aware of a personal-data breach affecting you, we will notify you and any competent supervisory authority as required by applicable law.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:
To exercise any of these rights, write to privacy@trustpin.cloud. We will respond within one month of receipt. Where a request is complex or we receive a number of requests, we may extend that period by up to two further months as permitted by law and will tell you within the first month. We may need to verify your identity before acting on a request.
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the following rights with respect to your personal information.
We use this information for the purposes described in section 5. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
TrustPin does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. In the preceding twelve months we have not sold or shared personal information for those purposes.
To exercise any of these rights, write to privacy@trustpin.cloud. You may use an authorized agent; we will verify the agent’s authority and your identity before acting on the request.
We offer a GDPR Article 28 Data Processing Addendum (DPA) for business customers on request. Depending on the customer’s use of TrustPin, the DPA may cover account administration, authentication and access-control data, support materials, security and audit logging, configuration management, and limited transient network processing associated with configuration delivery.
To request the DPA, write to privacy@trustpin.cloud.
TrustPin is a business-to-business service for developers and security teams. It is not directed to children and we do not knowingly collect personal data from children. Consistent with GDPR Article 8, we do not knowingly process personal data of anyone under 16 (or the lower age set by an applicable EU member state, where it has set one between 13 and 16) and, consistent with the US Children’s Online Privacy Protection Act, we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, please contact privacy@trustpin.cloud and we will delete it.
TrustPin may update this Policy and our privacy practices from time to time. For material changes, we will provide notice at least 30 days before they take effect, by email and/or a notice on this page, where required by applicable law or our agreements. Non-material changes, or changes required by law, may take effect immediately. We will update the “Last updated” date above to reflect the most recent revision.
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Capa7 LLC, a Wyoming limited liability company
1007 N Orange Street, 4th Floor, Suite 3317
Wilmington, DE 19801, United States
Privacy: privacy@trustpin.cloud
Support: support@trustpin.cloud
Website: https://trustpin.cloud