Privacy Policy
Last updated 2 October 2026
Who we are
Pingado is operated by Tag Concierge sp. z o.o., ul. Józefa Sarego 18 lok. 1, 31-047 Kraków, Poland ("Pingado", "we"). Pingado is an ad tracking and attribution service: it records how visitors reach our customers' sites, receives our customers' conversions from their payment providers, and sends those conversions to the ad platforms our customers connect.
This policy covers two groups of people, and our role is different for each:
- Our customers, the people and companies who sign up for Pingado. For their account data we are the controller.
- Visitors to our customers' sites. For the data the Pingado snippet collects on a customer's site, the customer is the controller and we process it on their behalf, under our data processing terms. If you visited a site that uses Pingado, that site's privacy notice applies, and requests about your data are best sent to that site.
Data about our customers
What we collect
- Account data: your email address, and the sites and team members you add.
- Connection data: access tokens and webhook secrets for the ad accounts and payment providers you connect. We encrypt them and never show them back in the app.
- Billing data: your plan, invoices and payment status. Payments go through Stripe Managed Payments, where Stripe, through its Link service, is the merchant of record. Stripe collects your payment details and billing address under its own privacy policy; we never see your card details.
- Access requests: what you enter in the request access form, such as your email address, website and ad setup, used to reply to your request.
- Usage and support: what you do in the app, needed to run it, and messages you send us.
Why we use it
- To provide the service you signed up for (performance of a contract).
- To bill you and keep financial records (contract and legal obligation).
- To keep the service secure and to fix problems (legitimate interests).
- To send you product updates, which you can turn off at any time (legitimate interests or consent, where required).
Data about visitors to our customers' sites
We collect this on our customers' instructions, and use it for no other purpose than providing Pingado to that customer.
What the snippet collects
- A random visitor ID, and the first page of each visit with its referrer and time. Later pages of the same visit are not sent to us.
- UTM parameters and ad click IDs in the landing page's address.
- Cookies set by ad platforms on the customer's site, such as
_fbp,_fbc,_ttp,_rdt_uuidand_gcl_aw. - An email address and name entered in a form. The browser masks them (for example a****b@g***l.com and Adam L.) and hashes them before sending; the full email address and name never reach us.
- The last IP address and browser user agent, and the country derived from the IP address.
- The visitor's consent choices, when the site uses Google Consent Mode.
What we receive from payment providers
When a visitor starts a trial or pays on a customer's site, the customer's payment provider sends us the type of payment, its value and currency, the provider's IDs for the order, and the buyer's email address and name, which we mask and hash on receipt. We never store them in full.
What we keep about visitors
We do not store visitors' full email addresses or names. We keep them in two forms: masked (for example a****b@g***l.com and Adam L.), so our customers can recognise their own leads and buyers in Pingado, and as one-way hashes, to match a purchase to an earlier visit and to send to ad platforms. The rest is random IDs we generate, ad platforms' click IDs and cookie values, the last IP address and user agent, and the country.
A masked email and name can identify a person to someone who already knows them, and the hashes and IDs can identify a person when matched with other data, such as an ad platform's own records. So we treat all of it as personal data and protect it as described here. Keeping only masked and hashed forms means that even if this data were ever exposed, it would not include anyone's full email address or name.
What we send to ad platforms
For the conversions a customer chooses, and only for visitors who allowed ad tracking, we send the conversion with its value and currency, the hashed email and name, a hashed visitor ID, the platform's click ID and cookies, the IP address and the user agent to the ad platforms the customer connected, such as Meta, Google, TikTok, Reddit and OpenAI. Each platform handles this data under its own terms with the customer.
Consent
The snippet follows Google Consent Mode as set by the customer's cookie banner. Without analytics consent it stores no visitor ID. Without ad consent it loads no ad platform pixels, stores no click IDs and sends nothing to ad platforms. Customers are responsible for asking for consent where the law requires it.
Cookies
On customers' sites the snippet sets pg_vid, a random visitor ID kept for up to 400 days, pg_ses, which marks the current visit and expires 30 minutes after the last page view, and, with ad consent, refreshes the ad platforms' own cookies listed above. The ad platforms' pixels that Pingado loads set their own cookies, described in each platform's policy.
These are how long the cookies stay in the visitor's browser. How long we keep visitor data on our servers is set separately, under How long we keep data.
Our website, pingadoapp.com, sets no cookies. When you sign in to the app, we set pg_session, a cookie on api.pingadoapp.com that keeps you signed in for up to 30 days.
Who we share data with
- Cloudflare, which hosts the Pingado service and its databases.
- Cloudflare Email Service, which sends sign-in links and account emails.
- Stripe, the merchant of record for Pingado subscriptions through its Link service. It processes payments, collects taxes and sends receipts and invoices, and handles the payment data it collects as a controller under its own privacy policy.
- Ad platforms and payment providers our customers connect, as described above, on the customer's instruction.
We do not sell personal data, and we do not use visitors' data to build profiles across our customers' sites.
International transfers
Our service providers and the ad platforms may process data outside the European Economic Area and the United Kingdom. Where they do, we rely on adequacy decisions or the European Commission's standard contractual clauses.
How long we keep data
- Account data: while your account is open, and up to 30 days after you close it.
- Visitor data on customers' sites: up to 90 days after the visitor's last interaction with the site that they consented to, or less if the customer chooses. Each new consented visit or conversion starts the 90 days again; without one, the data is deleted.
- Billing records: as long as tax law requires.
Security
Data is encrypted in transit. Access tokens and webhook secrets are encrypted at rest with keys held separately from the database. Access to production data is limited to the people who need it to run the service.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, to object to or restrict how we use it, and to withdraw consent. You can also complain to your data protection authority. In Poland, where we are based, that is the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw.
Customers can send requests to hello@pingadoapp.com. Visitors to a customer's site should contact that site; we help our customers answer those requests.
Changes
We will post changes to this policy on this page and update the date at the top. For significant changes we will email our customers in advance.
Contact
Tag Concierge sp. z o.o., ul. Józefa Sarego 18 lok. 1, 31-047 Kraków, Poland. KRS 0001056414, VAT ID PL6762650811. hello@pingadoapp.com.