Privacy policy
Last updated 1 October 2026
This policy explains how Pinpoint Online ("we", "us") handles personal data in VEGA, the software service at https://vegai.online for advertising and marketing agencies. It covers the people who use VEGA, the clients and contacts whose details agencies keep in it, and visitors to its public pages. Questions: mabuadas@pinpoint.online.
1. Who is responsible
The agencies' data. Each company that uses VEGA decides what it stores about its own clients, contacts, leads and staff. For that data the company is the controller and we are its processor: we handle it only to run VEGA for that company, on its instructions. If your details are in an agency's VEGA space, contact that agency first; we will help it answer you.
Our own data. For account details, billing, support and security records we are the controller.
2. What we collect
Account details: name, email address, job title, role, password (stored only as a bcrypt hash, never in readable form), language preference and the companies you belong to.
What a company puts into VEGA: clients and their contacts, leads and opportunities, tasks, projects, timesheets, files, messages and comments, estimates, invoices and other finance records, people and payroll records, briefs and AI studio outputs, and brand material such as logos and guidelines.
Messages handled for a company: emails, SMS, WhatsApp messages and call recordings sent or received through the channels the company connects, and replies to its web forms.
Connected ad accounts: when a company connects Google Ads, Google Analytics or Meta ads, see section 5.
Billing: the company's billing name, address, tax number and email, its plan and its invoices. Card details are entered on our payment providers' own pages; VEGA never receives or stores the card number.
Security and usage records: sign-in times, an audit log of important changes (who changed what, when), the address and browser of a request where needed to protect the service, and a delivery log for platform email that keeps a one-way hash of the recipient's address, not the address itself.
3. Why we use it
to provide VEGA: sign-in, the features each company switches on, and sending the email, SMS and WhatsApp messages a company asks it to send (performance of our contract with the company);
to keep VEGA secure, prevent abuse and keep an audit trail (our legitimate interest, and the companies' own record-keeping);
to bill for paid plans and keep tax records (contract and legal obligation);
to answer support requests and tell account owners about important changes (contract and legitimate interest).
We do not sell personal data, we do not use it for advertising, and we do not use a company's content to train AI models.
4. AI features
When someone in a company runs an AI feature, the material it needs (a brief, a client profile, post text, lead emails or messages to summarise, reference images such as a logo) is sent to the AI provider that handles the request. That is either a provider the company connected with its own key, or the provider the platform supplies: Ollama (text), OpenAI, Google Gemini or Higgsfield (images and video). Each provider processes the material under its own terms and privacy policy. For Higgsfield, reference images are first uploaded to a temporary address so the provider can read them, and Higgsfield keeps its results for 7 days. The results come back into the company's VEGA space.
5. Google and Meta data
A company can connect its Google Ads, Google Analytics and Meta (Facebook and Instagram) advertising accounts so VEGA can show campaign performance in its reports.
Google: we ask for the scopes
adwords,analytics.readonly,openidandemail. VEGA reads campaign, ad group, ad, asset group and search term details and their performance metrics, and Analytics reports. It does not create, change or delete anything in the connected accounts.Meta: we ask for
ads_readand, optionally,business_management. VEGA reads the ad accounts you choose, their campaigns, ad sets, ads (including the ad text, images and links) and their insights, and the names of the businesses they belong to. It does not create, change or delete anything.The access tokens are stored encrypted (AES-256-GCM) and used only for the company that connected them. The data is shown only to people in that company who are allowed to see reports. It is never sold, never used for advertising and never shared with anyone else.
VEGA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deleting this data. In VEGA, go to Settings → Integrations, open the ad connection and choose Disconnect. This deletes the stored tokens straight away; tick the option to also revoke access and we withdraw it at Google or Meta as well. You can also remove VEGA at any time from your Google account (myaccount.google.com → Security → Third-party connections) or Facebook (Settings → Business integrations). To have the ad data already copied into VEGA deleted, email mabuadas@pinpoint.online from the account owner's address; we delete it within 30 days and confirm by email.
6. Who else processes data
We use these service providers, each only for the purpose shown:
| Provider | Purpose |
|---|---|
| Hostinger | the server VEGA runs on, its database and stored files |
| Resend, or the company's own email server | sending email |
| Twilio | SMS, WhatsApp and voice, only when a company connects its own Twilio account |
| Network International, Stripe | taking card payments for paid plans |
| Ollama, OpenAI, Google (Gemini), Higgsfield | AI text, image and video generation (section 4) |
| Google, Meta | the ad accounts a company connects (section 5) |
| Serper, Google PageSpeed | web search and page-speed checks, only with the company's own key |
| Browser push services (Google, Apple, Mozilla) | delivering notifications you switched on: a title, a short line and a link, never client work |
A company can also send its own data to systems it chooses through webhooks it sets up. We may disclose data when the law requires it, and always tell the company affected unless the law forbids it. Some of these providers work outside the country you are in, including in the United States; where the law requires it, we rely on appropriate safeguards such as standard contractual clauses.
7. Cookies and tracking
VEGA uses one cookie for signed-in people, vega_session, which keeps you signed in. It is strictly necessary, cannot be read by scripts, and lasts until you sign out or for up to a year (the platform default). Platform administrators have a second sign-in cookie for the administration area. There are no analytics, advertising or tracking cookies or scripts in VEGA. Its offline support (service worker) stores only the app's own static files on your device, never your data.
Marketing emails that a company sends through VEGA can contain open and click tracking links and always an unsubscribe link; those are the company's campaigns, and it decides whether to send them.
8. Security
encrypted connections (HTTPS) everywhere;
each company's records separated by row-level security in the database, so one company cannot read another's;
passwords stored as bcrypt hashes; keys and tokens for connected services encrypted at rest;
files served only to signed-in people with access, or through share links that expire and can be revoked;
nightly backups, checked by a restore drill when they are made.
No system is perfectly secure. If a breach affects your personal data, we will tell the companies concerned and the authorities where the law requires it, without undue delay.
9. How long we keep data
Company data: for as long as the company uses VEGA. When a company space is closed it is kept for a grace period (currently 30 days) so a mistaken closure can be undone, then permanently deleted. The final export prepared for the owner is deleted 30 days after that.
Audit log: 2 years. Email delivery log: 180 days.
Data exports: downloadable for 7 days.
Backups: the last 14 nightly backups; older ones are overwritten.
Billing records: as long as tax law requires.
10. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its use, receive it in a portable format, and complain to your data protection authority.
If an agency holds your details in VEGA, ask that agency; it can export, correct or erase them, and we help it do so.
For your own VEGA account or anything else in this policy, email mabuadas@pinpoint.online. We answer within 30 days.
A company owner can export all of the company's data at any time from Settings.
11. Children
VEGA is a business tool and is not meant for anyone under 16. We do not knowingly collect children's data.
12. Changes
We will update this policy when VEGA changes. The date at the top shows the latest version, and we tell account owners about material changes before they apply.
13. Contact
Pinpoint Online
Email: mabuadas@pinpoint.online
See also the terms of service.