Pinned Privacy Policy

Hard-enduro ride recording for iPhone and Apple Watch

Effective: 2026-05-05 · Last updated: 2026-05-05

Pinned ("we", "us") is a ride-recording app for hard-enduro and trail dirt-bike riders. This policy explains what data the app collects, how we use it, and the choices you have. We try to keep it short and plain.

Data we collect

We do not collect: contacts, photo library beyond what you explicitly attach to a bike, microphone, advertising identifiers, browsing history, or third-party social-network data. We don't run any analytics SDK, attribution SDK, or advertising SDK.

How we use your data

We do not use your data for advertising, profiling, or training machine learning models, and we do not sell or rent your data.

Where your data is stored

Your account and ride data are stored on Supabase, our hosting provider, on servers located in the United States. Data is encrypted in transit (HTTPS) and at rest. Photos you attach to bikes are stored in private Supabase Storage with per-user folder access control — no one else can read them.

Some data also lives locally on your iPhone and Apple Watch: SwiftData stores your rides on-device for offline access, and refresh tokens for your session live in the iOS Keychain (this-device-only — they never sync via iCloud Keychain or device backups).

Subprocessors

We use a small number of vendors to deliver the service:

We don't share your personal data with anyone else. Subprocessors are bound by their own privacy commitments.

Your rights and choices

If you're in the EU, EEA, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA: access, rectification, erasure, restriction, portability, and objection. To exercise any of these, email privacy@cfandersen.com. We don't sell or share personal information for the purposes defined under CCPA.

Data retention

We keep your account and ride data for as long as your account is active. When you delete your account, all data is removed from our database immediately; backups are rotated out within 30 days.

Children

Pinned is not directed to children under 13 (or under 16 in the EU/UK), and we don't knowingly collect data from children. If you believe a child has signed up, contact us and we'll delete the account.

Security

We use HTTPS for everything, encrypt data at rest, and apply row-level security so each user can only access their own rides and bikes. Refresh tokens on your device are stored in the iOS Keychain with this-device-only protection. We rotate database access credentials and review access controls regularly.

Changes to this policy

If we materially change how Pinned handles your data, we'll update this page and bump the "Last updated" date at the top. For significant changes we'll also send a notification through the app.

Contact

Questions, requests, or concerns: privacy@cfandersen.com.


Pinned is built independently. We're not affiliated with Apple, Inc., the OpenStreetMap Foundation, or any motorcycle manufacturer.