Pincite Privacy Policy
Effective: 7 August 2026
Pincite Pty Ltd (ACN 700 309 753 | ABN 43 700 309 753) (Pincite, we, us, our) provides an online tool that helps users format and manage legal citations. This policy explains how we collect, hold, use and disclose your personal data, and how you can access it, correct it, erase it, or make a complaint.
We are an Australian company, and your information is held outside the United Kingdom. That does not put you outside the reach of UK data protection law. The UK General Data Protection Regulation (the UK GDPR) applies to a controller outside the United Kingdom that offers services to individuals in the United Kingdom, so we handle your personal data in accordance with the UK GDPR and the Data Protection Act 2018 (UK). The UK GDPR has no small-business exemption — it applies to every controller regardless of size — so these are obligations we owe you, not commitments we have chosen to make. Guidance on your rights is published by the Information Commissioner's Office at https://ico.org.uk.
Because we are an Australian company, the Privacy Act 1988 (Cth) and the Australian Privacy Principles also govern our handling of your information. Where the two sets of rules differ, we apply whichever gives you the greater protection. This means you have two complaints routes, and you may use either — see clause 15.
This policy forms part of our Terms and Conditions. Capitalised terms not defined in this policy have the meanings given to them in clause 18 (Definitions) or in the Terms and Conditions.
1. Scope
This policy applies to personal data we collect through the Website, including when you browse our Website, create an Account, subscribe, use the citation generator, save Projects, or contact us for support. It does not cover the citation content itself (for example, case names or statute titles) unless that content also happens to identify you.
2. Personal data we collect, and why
2.1 What we collect. We collect the following personal data for the purposes described, and only because it is necessary for them (the data minimisation principle in Article 5 of the UK GDPR):
| We collect | Why |
|---|---|
| Name and email address | To create and manage your Account, and to contact you about your subscription |
| Login and authentication details | To sign you in securely |
| Subscription and billing status (plan, renewal date, access status) | To manage your subscription and give you the right access |
| Your saved Projects (your citation work) | So that you can save, return to, and export your work |
| Website usage data (pages viewed, general location, device and browser type) | To understand how Pincite is used and to improve it, via Google Analytics and Vercel Analytics |
| How you move through our public pages (clicks, scrolling, mouse movement, and a replay of the page as you saw it) | To see where our public pages confuse people, so that we can fix them, via Clarity. This does not run on the citation generator or your Account settings (see clause 8) |
| Support enquiries (bug reports, feature requests) | To respond to you and improve the service |
| Referral information (if you use our referral program) | To apply referral rewards to your Account |
2.2 Lawful bases. The UK GDPR requires a lawful basis for each use of your personal data (Article 6). Ours are:
- (a) performance of a contract — creating and managing your Account, providing the citation generator and your Projects, billing, and service communications;
- (b) legitimate interests — website analytics, improving Pincite, and detecting and preventing fraud, misuse and security incidents, in each case balanced against your rights and freedoms;
- (c) consent — marketing emails, and any non-essential cookies (you may withdraw consent at any time); and
- (d) legal obligation — record-keeping, tax and responding to lawful requests.
2.3 Payment details. We do not collect or store your full payment card details. They are collected and held directly by our payment processor, Stripe.
2.4 Special category data. We do not seek out information about your health, race, ethnicity, religious or political beliefs, or other special categories of personal data. You should not enter confidential, privileged or sensitive material into Pincite. If you send us such information unasked, we will only use it for the purpose for which you provided it, or as the law requires, and will delete it if it is not needed.
2.5 Children. Pincite is for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we become aware that we have, we will delete it and close the Account, and refund any unused Fees.
3. How we collect personal data
Where practical, we collect personal data directly from you — when you create an Account, subscribe (through Stripe's checkout), save a Project, contact support, or take part in our referral program. We tell you what we are collecting and why at the point we collect it, as Articles 12 and 13 of the UK GDPR require. We also collect some information automatically through cookies and analytics tools when you use our Website (see clause 8).
4. What we will never do with your data
- (a) We will never use your Projects, your citation content, or other content you submit through Pincite to train, fine-tune, evaluate or develop any artificial intelligence or machine learning model, whether ours or anyone else's.
- (b) We will never permit a service provider to use that content for those purposes on our behalf. This does not prevent a provider from processing your content strictly as necessary to provide its service to us, subject to appropriate confidentiality and security obligations.
- (c) We will never sell your personal data, and we will never share it with data brokers or advertisers.
- (d) We will never publish your Project content.
- (e) We do not use artificial intelligence or machine learning to generate your citations. Pincite runs on rules-based logic that we author and maintain.
- (f) We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
5. How we use your data to improve Pincite
We analyse aggregated and de-identified information about how Pincite is used — for example, which citation types most often produce errors, or which fields users most often leave blank — so that we can identify and remedy the parts of the product that do not work well. "De-identified" means the data does not identify you and you cannot reasonably be re-identified from it. This is subject to the commitments in clause 4; in particular, this data is never used to train an artificial intelligence model.
6. How we hold and secure your data
We take appropriate technical and organisational measures against loss, misuse and unauthorised access, use, modification or disclosure (Article 32 of the UK GDPR):
- (a) Your Account and Projects data is stored in a Supabase database hosted in the Sydney, Australia region. This is outside the United Kingdom — see clause 9.
- (b) Payment card details are held by Stripe, not by us.
- (c) We restrict internal access to what is needed to run the service, using database-level access controls (Row Level Security).
- (d) We use multi-factor authentication on all our administrative and infrastructure accounts.
- (e) We take reasonable technical and organisational steps to protect your data from misuse, loss, and unauthorised access, modification or disclosure.
No method of storage or transmission is completely secure, but we keep our practices current as Pincite grows.
7. Personal data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay, and tell you:
- (a) what happened and what data was involved;
- (b) what we are doing about it; and
- (c) what you should do to protect yourself.
These are legal obligations under Articles 33 and 34 of the UK GDPR, not voluntary commitments. We will also notify the OAIC where the Australian Notifiable Data Breaches scheme applies, and we will follow this clause whether or not that scheme strictly applies to us.
8. Cookies and analytics
Our Website uses cookies and similar technologies through:
- (a) Google Analytics — to understand traffic and how visitors use our Website;
- (b) Vercel Analytics — to monitor Website performance and usage; and
- (c) Clarity — to record how visitors move through our public pages.
These may collect your IP address, device and browser type, pages visited, and general location. You can control or disable cookies through your browser settings, though some parts of Pincite may not work properly if you do.
8.1 What Clarity records. On our public pages Clarity records user clicks and mouse movement. This will be used to find the places where our pages confuse people, so that we can fix them.
8.2 Where Clarity does not run. Clarity does not run on the citation generator, on your saved Projects, or on your Account settings. Your citation work is never recorded. We have also configured those parts of Pincite so that their contents are withheld from Clarity even if you move into them from a public page during the same visit.
8.3 What is excluded from Clarity. Anything typed into a sign-up, sign-in or password form, or any page accessed on your dashboard or settings, is not recorded.
8.4 Turning it off. Most browsers offer tracking protection, and content-blocking extensions will also block these services. Either will stop Clarity and our other analytics tools from recording your visit.
9. Your data is held and processed outside the United Kingdom
This clause matters more to a UK user than any other in this policy, so it is stated plainly.
We are an Australian company. All of your personal data is held and processed outside the United Kingdom — none of it is stored in the UK. Our database is in Australia, and several of the services we rely on are provided by companies based in the United States.
The UK GDPR restricts transfers of personal data outside the United Kingdom unless appropriate safeguards apply (Articles 44–49). Where your data is transferred to or between our service providers, we rely on contractual safeguards — including privacy, confidentiality, security and breach-notification obligations, appropriate controls over subcontractors, and international data transfer terms where required — so that your data receives protection materially equivalent to this policy wherever it is processed.
| Service | Used for | Location(s) — all outside the United Kingdom |
|---|---|---|
| Pincite Pty Ltd | Operating Pincite, responding to your support and privacy enquiries | Australia |
| Supabase | Database hosting — your Account and Projects | Database is in Sydney, Australia. Supabase Inc. is a US company, so limited technical and support access may occur from the United States |
| Upstash | Rate limiting and abuse prevention | Data is stored in the Sydney, Australia region. Upstash is a US company, so limited technical and support access may occur from the United States |
| Stripe | Payment processing | United States (Stripe operates internationally) |
| Vercel | Website hosting | United States |
| Resend | Sending transactional and service emails, such as verification, receipts, renewal reminders and security notices (Resend receives your email address and the contents of those emails) | United States |
| Google Workspace | Receiving and managing support and privacy enquiries you send us by email | United States (Google operates internationally) |
| Google Analytics | Website analytics | United States |
| Clarity (Microsoft) | Recording how visitors move through our public pages, as described in clause 8 | United States (Microsoft operates internationally) |
What this means for you. Personal data held in another country is subject to that country's laws, and an overseas authority may in some circumstances be able to require access to it. Australia has a national privacy law of long standing, and we remain accountable to you under the UK GDPR for our own handling of your data wherever it is held. Using Pincite does not reduce any rights you have under UK or Australian data protection law. We encourage you to review each provider's own privacy policy.
10. How we use and disclose your data
10.1 Purposes. We use your personal data for the purposes it was collected for, and for closely related purposes you would reasonably expect (the purpose limitation principle in Article 5), such as:
- (a) responding to support requests;
- (b) sending you service emails (renewal reminders, receipts, security notices);
- (c) detecting and preventing fraud or misuse; and
- (d) improving Pincite, as described in clause 5.
We take reasonable steps to keep your personal data accurate, complete and up to date.
10.2 Disclosure. We only disclose personal data to:
- (a) the service providers listed in clause 9, to the extent needed for them to perform their function;
- (b) anyone else with your consent; or
- (c) where required or authorised by law.
10.3 Direct marketing. We will only send you marketing emails if you have consented, and every one will contain an unsubscribe link, as required by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (UK). Service emails (billing, security, renewal reminders) are not marketing, and you will receive them while you hold an Account. You have the right to object to direct marketing at any time, and we will stop.
11. If our business is sold
If Pincite is sold, merged, or restructured, your personal data may transfer to the purchaser, successor or relevant related body corporate as part of that transaction. In that event:
- (a) before any transfer of personal data takes effect, we will take reasonable steps to require the recipient to handle that data in accordance with this policy, or under a privacy policy that provides materially equivalent protection, and — where the recipient is outside the UK — to meet the UK GDPR's transfer requirements;
- (b) we will take reasonable steps to require the recipient not to use your Projects, your citation content, or other content you submit through Pincite to train, fine-tune, evaluate or develop any artificial intelligence or machine learning model;
- (c) we will give you reasonable notice by email before a material transfer takes effect, where reasonably practicable, so that you can export your Projects or delete your Account first if you would prefer; and
- (d) if a future owner proposes a material change to the commitments in clause 4, it must give you notice and obtain any consent required by law before using your personal data in the changed manner.
12. Anonymity
You can browse our public pages anonymously. To use most Pincite features you will need an Account, so full anonymity is not possible for those.
13. How long we keep your data
We do not keep personal data for longer than we need it for the purposes it may lawfully be used for (the storage limitation principle in Article 5).
13.1 Cancelled subscriptions. If you cancel your subscription but keep your Account, we keep your Account and Projects so that you can return to them. Cancelling does not delete anything.
13.2 Inactive accounts. If an Account has no login activity for 24 months, we may delete it and its data, but we will never do so without warning you. We will email you 30 days before deletion, and again seven days before deletion, each time with a link to keep your Account and a link to export your Projects. If you log in at any point, the 24-month period resets. We will not delete an Account under this clause while you have a current paid subscription, unless the Account is suspended or terminated under our Terms and Conditions.
13.3 Deleting your account. Before deleting your Account, you can export your Projects from your Account settings. If you delete your Account, we remove your Account and Projects from our live production systems and disable access to them. Copies may remain in encrypted database backups after deletion; these are not available for ordinary use, and we access them only where reasonably necessary to restore the service after a failure. Backups are overwritten within 30 days after deletion, unless a longer period is required by law or is reasonably necessary for disaster recovery, security or legal purposes. Once overwritten, the data cannot be recovered. If we restore a backup after you delete your Account, we will take reasonable steps to ensure your deleted Account and Projects are not returned to active use.
13.4 Erasure on request. You have the right to ask us to erase your personal data (Article 17). We will complete a verified request within one month after we receive it, and may take reasonable steps to confirm you are the Account holder before acting. Our erasure obligations are subject to clause 13.5.
13.5 Retention required by law or for limited purposes. After your Account is deleted, we may retain only the minimum personal data reasonably necessary to:
- (a) comply with a legal, tax, accounting or record-keeping obligation;
- (b) establish, exercise or defend legal claims;
- (c) investigate or address fraud, security incidents, payment disputes or misuse of Pincite; or
- (d) keep a record that we completed your deletion request.
We will not retain your Projects, and will not use retained personal data for ordinary product, marketing or analytics purposes, after your Account is deleted, unless the law requires it or you give us separate consent. Any data retained under this clause is access-restricted, kept only for the period reasonably necessary for the relevant purpose, and securely deleted or de-identified when it is no longer required.
14. Your rights over your data
You have legal rights over your personal data under the UK GDPR, not as a courtesy. They include the right to:
- (a) access your personal data and receive a copy (Article 15);
- (b) rectify inaccurate or incomplete data (Article 16);
- (c) erase your data in the circumstances Article 17 describes — see clause 13.4;
- (d) restrict processing in certain circumstances (Article 18);
- (e) data portability — receive the data you provided to us in a structured, commonly used, machine-readable format (Article 20). You can export your Projects yourself, at any time, from your Account settings; and
- (f) object to processing based on legitimate interests, and to direct marketing at any time (Article 21).
Ask us using the details in clause 16. We will respond as soon as reasonably practicable, and no later than one month after we receive your request (extendable by two further months for complex requests, in which case we will tell you within the first month). We will not charge a fee unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting, so that we do not disclose your data to someone else.
15. Complaints — you have two routes
If you are unhappy with how we have handled your personal data:
- (a) Contact us first. Write to us using the details in clause 16. We will acknowledge your complaint within five business days and aim to resolve it within 30 days.
- (b) The Information Commissioner's Office (United Kingdom). You can complain to the ICO at https://ico.org.uk or on 0303 123 1113. The ICO will usually ask whether you have raised the matter with us first, so coming to us is often the quickest route — but you are not required to, and you can approach the ICO at any time.
- (c) The OAIC (Australia). Because we are an Australian company, you may instead complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au or on +61 1300 363 992.
You are never required to come to us first, and you may choose either regulator. You also have the right to an effective judicial remedy in the UK courts.
16. Contact
Pincite Pty Ltd Email: privacy@pincite.com.au ACN 700 309 753 | ABN 43 700 309 753 A company incorporated in Australia
17. Changes to this policy
We may update this policy as Pincite grows or our practices change. The current version is always available on the Website.
- (a) For minor changes, we will update the "Effective" date.
- (b) For material changes — anything that meaningfully affects how we handle your data — we will give you at least 30 days' notice by email before they take effect.
- (c) We will never weaken the commitments in clause 4 without first asking for your express opt-in consent. Continuing to use Pincite is not consent to that.
Previous versions are available on request.
18. Definitions
In this policy:
Account means the account you create to access Pincite.
Clarity means Microsoft Clarity, the third-party service we use to record how visitors move through our public pages.
Data Protection Act 2018 means the Data Protection Act 2018 (UK).
Google Workspace means Google Workspace, the service we use to receive and manage email you send to us.
ICO means the UK Information Commissioner's Office.
OAIC means the Office of the Australian Information Commissioner.
personal data has the meaning given in the UK GDPR.
Projects means the citation work you save in your Account.
Resend means Resend, our third-party email delivery provider.
Stripe means Stripe, our third-party payment processor.
Terms and Conditions means our Terms and Conditions governing the Pincite citation tool, available at https://pincite.co.uk/terms, as updated from time to time.
UK GDPR has the meaning given in the Data Protection Act 2018 (UK).
Upstash means Upstash, our third-party provider of rate-limiting and abuse-prevention infrastructure.
Website means the Pincite website at https://pincite.co.uk and its subdomains and pages.
you and your mean the individual whose personal data we hold.