Privacy Policy

Last updated: August 27, 2026

1. Data We Collect

Plinto collects the following categories of personal data to provide our compensation job matching service:

  • Account Information: Email address, full name, and company affiliation provided during registration or invitation.
  • Job Matching Data: Job titles, departments, functions, levels, and descriptions uploaded by your organization for matching purposes.
  • Usage Data: Actions performed within the platform (project creation, match editing, validations) stored in audit logs.
  • Technical Data: IP address, browser type, and device information collected automatically for security and analytics.
  • Billing Information: Payment details processed by Stripe. We do not store credit card numbers directly.

2. How We Use Your Data

  • Job Matching: Processing uploaded job data through our AI-powered matching pipeline to generate survey benchmark matches.
  • Validated Records: Storing analyst-confirmed matches as your company's reference record of what was decided (validated data is never shared across tenants, and is not used to train or tune any model).
  • Billing: Processing subscription payments through Stripe.
  • Security: Maintaining audit logs and monitoring for unauthorized access.
  • Communication: Sending service-related emails (invitations, password resets, GDPR request confirmations).

3. Data Retention

  • Project Data: Retained until the user or admin deletes the project.
  • Validated Matches: Retained as your company's reference record of analyst decisions until you delete the project or your account.
  • Match Result Exports: Generated on demand and delivered straight to your browser. We do not retain the file; only a record of the export (file name, size and timestamp) is kept, and it is deleted with the project.
  • Audit Logs: Retained under our log-retention policy for as long as needed for security and regulatory compliance. Records of data-subject requests are kept as accountability evidence and are never purged.
  • Account Data: Retained until account deletion is requested and confirmed.

4. Data Sharing

We do not sell your data. We share data only with the following third-party services necessary to operate Plinto:

  • Stripe: Payment processing for subscription billing.
  • Supabase: Database hosting and authentication services.
  • OpenAI: AI model processing for job matching. We send the job-description fields you upload — title, blurb and description, function, department, job family, career stream, organisational layer, level and typical years of experience — and never employee names, identifiers or pay data.

Your company's data is strictly isolated from other tenants. No cross-company data access is possible, enforced at the database level through Row-Level Security policies.

5. Your Rights

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of Access (Article 15): You can download a complete copy of all your personal data at any time from Settings > Privacy & Data.
  • Right to Erasure (Article 17): You can request account deletion from Settings > Privacy & Data. Your personal data will be anonymized while preserving data integrity for existing projects.
  • Right to Data Portability (Article 20): Your data export is provided in standard JSON format, allowing you to transfer your data to another service.
  • Right to Rectification (Article 16): You can update your personal information in your account settings at any time.
  • Right to Restriction (Article 18): Contact us to request restriction of processing for your data.

6. Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Row-Level Security (RLS) for tenant data isolation
  • JWT-based authentication with secure session management
  • HTTPS encryption for all data in transit
  • Database encryption at rest
  • Rate limiting on authentication endpoints
  • Webhook signature validation for all integrations
  • Comprehensive audit logging of all sensitive operations

7. GDPR Compliance

Plinto is designed with GDPR compliance as a core requirement. Our multi-tenant architecture ensures complete data isolation between companies. All data processing is performed with a lawful basis, and we maintain detailed audit logs of all data access and modifications.

For data processing agreements (DPA) or compliance questions, contact our Data Protection Officer at the address below.

8. Contact Information

For privacy-related inquiries or to exercise your data rights, contact us at:

Email: privacy@plinto.io

Subject: GDPR Data Request - [Your Company Name]

We will respond to all data requests within 30 days as required by GDPR.

9. Cookies & Tracking

Plinto uses only essential cookies required for the service to function:

  • Authentication Session: A secure cookie that maintains your login session.

We do not use any marketing, analytics, or third-party tracking cookies. No data is shared with advertising networks or social media platforms through cookies.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or an in-app notification. The "Last updated" date at the top of this page indicates when this policy was last revised.