Privacy Policy

Effective: July 10, 2026Last updated: July 10, 2026

01Who we are

Andrey Tech (“Andrey Tech”, “we”, “us”, “our”) is an independent software development studio. We build Telegram bots, websites, web platforms and business automations for our clients.

For the purposes of the EU General Data Protection Regulation (GDPR), Andrey Tech acts as a data controller for data about people who contact us directly, and as a data processor when we access a client’s third-party accounts — including Pinterest — on that client’s behalf and under their instructions.

You can reach us at any time at mazurkaandrey@gmail.com.

02Scope of this policy

This policy covers:

  • Our website at andreytech.dev.
  • Our Pinterest API application, which we use to build reporting and automation tools for clients who explicitly authorize it.
  • Correspondence with us over email or Telegram.

It does not cover third-party services you may use alongside ours, such as Pinterest itself. Pinterest’s handling of your data is governed by the Pinterest Privacy Policy.

03Data we collect

We collect only what we need to deliver the service we were hired for. We do not buy data, and we do not build advertising profiles.

Contact data
Your name, email address or Telegram handle, and the contents of messages you send us.
Authorization data
OAuth access tokens and refresh tokens issued by Pinterest when you connect your account.
Pinterest account data
Your Pinterest user ID, username, account type and profile image URL.
Pinterest content data
Metadata about your boards and Pins: titles, descriptions, links, media URLs, board names and creation dates.
Pinterest analytics data
Aggregate metrics such as impressions, saves, outbound clicks and engagement, by Pin, board and time period.
Technical data
Server logs from our backend: IP address, timestamp, request path and error traces.

We never receive your Pinterest password. Authorization happens entirely on Pinterest’s own OAuth screen. We only ever see the token that Pinterest hands back to us, and only for the permissions you approved.

04Pinterest data

Our Pinterest application requests read-only access. We do not create, edit, publish or delete Pins, boards or advertising campaigns. The permissions we request are:

  • user_accounts:read — to identify the connected account and confirm the authorization worked.
  • boards:read — to list boards so a client can choose which ones to include in a report.
  • pins:read — to read Pin metadata belonging to the connected account.
  • Analytics read access — to retrieve performance metrics for the connected account’s own Pins and boards.

We access Pinterest data only for the account that authorized us, and only to produce reports, dashboards and automations for the owner of that account.

What we will never do with Pinterest data

  • Sell, rent or license it to anyone.
  • Use it to train machine learning or AI models.
  • Use it for advertising, retargeting or audience building.
  • Merge it with data from other sources to profile individuals.
  • Share it with any client other than the account owner who authorized us.
  • Access it after you disconnect the application.

Compliance

Our use of Pinterest data complies with the Pinterest Developer Terms, the Pinterest Developer Guidelines, and the Pinterest Advertising Services Agreement where applicable. Where those terms are stricter than this policy, those terms govern.

Revoking access

You can disconnect Andrey Tech from your Pinterest account at any time, without contacting us first, from your Pinterest settings under Settings → Security and permissions → Apps. Revocation invalidates our token immediately. We delete any data cached for that account within 30 days. You can also email us and we will do it sooner.

05How we use data

  • To deliver the service. Generating the reports, dashboards and automations a client asked us to build.
  • To keep tokens working. Refreshing OAuth tokens so a scheduled report does not break overnight.
  • To cache for performance. Storing fetched content and metrics so we can render historical trends without hammering the Pinterest API on every page load.
  • To operate and debug. Reading server logs to diagnose failures and prevent abuse.
  • To communicate. Answering your messages and sending service notices about outages or changes.
  • To comply with the law. Meeting our legal, tax and regulatory obligations.

We do not use your data for automated decision-making that produces legal or similarly significant effects on you.

07Sharing and disclosure

We do not sell your personal data. We share it only in these cases:

  • Infrastructure providers who host our servers and databases, acting as subprocessors under contract and processing data only on our instructions.
  • The account owner who authorized the connection, since the data is theirs.
  • Legal compulsion — where we are required to disclose by valid legal process. Where we are legally permitted to, we will tell you first.
  • Business transfer — if the business is sold or reorganized, subject to this policy continuing to apply.

08Retention and deletion

OAuth tokens
Until you disconnect the app or the token expires, whichever comes first. Then deleted.
Cached content and analytics
Up to 12 months, so year-over-year reporting works. Deleted within 30 days of disconnection or a deletion request.
Server logs
90 days, then rotated out automatically.
Correspondence
As long as needed for the client relationship, plus any statutory record-keeping period.

To request deletion, email mazurkaandrey@gmail.com from the address associated with your account. We confirm in writing once it is done.

09Security

  • All data in transit is encrypted with TLS.
  • OAuth tokens are encrypted at rest and are never written to logs, error traces or analytics.
  • Access to production systems is limited to personnel who need it, protected by multi-factor authentication.
  • We request the narrowest set of API permissions that the task requires.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant supervisory authority without undue delay, and within 72 hours where GDPR requires it.

10Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your data (“right to erasure”).
  • Restrict or object to our processing.
  • Port your data to another provider in a machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Opt out of sale or sharing — though we do neither, so there is nothing to opt out of.

Email mazurkaandrey@gmail.com to exercise any of these. We respond within 30 days and never charge a fee for a first request. We will not discriminate against you for exercising a right.

If you are in the EEA or UK and believe we have mishandled your data, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address it first.

11International transfers

Our infrastructure providers may process data in countries other than yours, including outside the EEA. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and take supplementary measures where needed.

12Cookies

Our website sets no cookies. We run no analytics, no advertising pixels and no third-party trackers on it.

Where a client-facing dashboard requires a session cookie to keep you logged in, that cookie is strictly necessary, holds no tracking identifiers, and expires when your session ends.

13Children

Our services are built for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email us and we will delete it.

14Changes

We may update this policy as the service evolves or the law changes. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle your data, we will notify affected clients by email before it takes effect.

15Contact

Questions about this policy, data requests, or anything else — one email, one human, no ticket queue.

Andrey Tech
Email: mazurkaandrey@gmail.com
Telegram: @ma_andrej
Website: andreytech.dev