§ Legal

Privacy Policy

Last updated: 20 April 2026

This policy explains how Pinch(“we”, “us”, or “our”) collects, uses, and protects your personal data when you use our website at pinchapp.co.uk or our mobile app. We are committed to protecting your privacy and complying with UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who we are

Pinch is operated by Pinch Ltd, a company registered in England and Wales. For any privacy-related questions, contact us at hello@pinchapp.co.uk.

For the purposes of UK data protection law, Pinch Ltd is the data controller of your personal data.

What data we collect

Waitlist (this website)

When you sign up to the waitlist, we collect your email address and the date and time you signed up. That’s it — we do not ask for your name, location, or any other details.

Mobile app (from launch)

When the Pinch mobile app launches, additional data may be collected, including:

  • Account details: email address, display name, and authentication tokens if you sign in using Google or Apple.
  • Preferences:household type, postcode prefix (e.g. “LS1” — the outward code only, not your full postcode), and category preferences.
  • Location data: approximate location only when you use the Radar feature or post a community find. You control this via your device permissions.
  • Usage data: anonymised analytics on which features you use, to help us improve the app.
  • Affiliate click data: when you tap a deal, we record the click so we can reconcile commission with retailers.

Why we collect it (lawful basis)

We rely on the following lawful bases under UK GDPR:

  • Consent — for waitlist sign-up, marketing emails, and access to device location. You can withdraw consent at any time.
  • Contract — to provide the Pinch service to you once you create an account.
  • Legitimate interests — for analytics, fraud prevention, and affiliate reconciliation. We balance these against your rights and only rely on this where appropriate.

How we use your data

  • To send you one email when Pinch launches (waitlist only).
  • To personalise deals based on your category preferences and postcode prefix.
  • To show nearby finds on the Radar feature.
  • To track affiliate clicks so retailers pay us the commission we’ve earned.
  • To understand which features work and which don’t, so we can improve the app.
  • To enforce our terms of service and prevent abuse or fraud.

We will never sell your data. We will never share it with third-party advertisers or data brokers.

Who we share data with

We share limited data with the following service providers, who process it on our behalf under contract:

  • Supabase (infrastructure and database hosting, EU-based) — stores your account and app data.
  • Vercel(website hosting) — serves the website you’re reading now.
  • Postmark (transactional email) — sends you launch notifications and account emails.
  • Stripe (payments, from launch of Pinch+) — processes subscription payments if you subscribe.
  • Affiliate networks (AWIN, Commission Junction) — receive click data so they can track and pay us commission on purchases you make via Pinch deals.

Each of these providers has its own privacy policy and data protection measures. We only share the minimum necessary data.

Affiliate relationships — our honesty principle

Pinch earns money through affiliate commissions when you buy something via a deal we feature. We always disclose this clearly in the app and on this website. We will never recommend a product we wouldn’t use ourselves, and we will always tell you when we earn a commission. This is non-negotiable and written into our brand principles.

How long we keep your data

  • Waitlist email: until we launch and send the launch email, then for a further 12 months in case you want to unsubscribe from future launch-related updates. After that, or sooner if you request, we delete it.
  • Account data: while your account is active and for a reasonable period after deletion to comply with legal obligations (typically 6 years for financial records related to affiliate commission).
  • Usage data: anonymised and retained indefinitely for trends analysis. No personally identifiable information is retained beyond what is needed.

Your rights

Under UK GDPR, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time, for any processing based on consent.
  • Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

To exercise any of these rights, email us at hello@pinchapp.co.uk. We’ll respond within one month.

Cookies and tracking

This website uses only essential cookies needed for the site to function. We do not use third-party tracking cookies or analytics cookies that identify you personally. The mobile app does not use cookies, but it does store authentication tokens locally on your device.

Children

Pinch is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it.

Data security

We use industry-standard security measures to protect your data, including encryption in transit (HTTPS), encryption at rest, Row-Level Security on our database, and secure credential storage. No system is perfectly secure, but we take protecting your data seriously.

International data transfers

Your data is stored primarily in the EU (Supabase eu-west-2, London). Some service providers (for example, affiliate networks) may transfer data outside the UK/EEA. Where this happens, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK government.

Changes to this policy

We may update this policy from time to time. Material changes will be notified to registered users by email. The “last updated” date at the top will always reflect when the policy was last changed.

Contact us

If you have any questions about this privacy policy or about how we handle your data, please contact us at hello@pinchapp.co.uk.