There are no public user accounts, advertising trackers, or data sales. The Pinterest integration is for our own authorized business account, uses documented authorization, and is designed around item-by-item operator approval. The full policy below controls.
1. Who we are
Michiel de Ruiter, trading as LuxuriaPrintStudio in the Netherlands, is the data controller and operates Luxuria Publisher (the “App”) as a private internal content-publishing tool. In this policy, “we,” “us,” and “our” refer to Michiel de Ruiter trading as LuxuriaPrintStudio.
For questions or privacy requests, email [email protected]. You can also contact the operator through the LuxuriaPrintStudio storefront.
2. Scope
This policy covers:
- this public Luxuria Publisher website;
- messages sent to the contact address listed above; and
- the App’s internal workflow for preparing and publishing our own product content to authorized business channels, including the planned Pinterest API integration.
It does not replace the privacy policies of Pinterest, Etsy, or any other third-party service you visit.
3. Information we process
Website request information
When you visit this website, hosting and security providers may process standard request information such as your IP address, browser and device type, requested page, date and time, referring page, and security signals. We do not use this information to build advertising profiles.
Correspondence
If you email us or send a storefront message, we receive the contact details and message content you choose to provide, together with any later correspondence.
App content and publishing instructions
The internal App processes content selected by its operator, such as product images, titles, descriptions, destination URLs, locally authored board instructions, intended channels, and requested publishing times. This is LuxuriaPrintStudio content or content that we are licensed to use. Pinterest-returned account, board, and Pin identifiers are not stored with this content.
Authorized platform connection data
When a platform connection is authorized, the App may process an access token, refresh token, granted scopes, token expiry information, and a local status indicating whether the connection is active. Pinterest-returned account, board, and Pin identifiers are not persisted as connection records. Tokens are credentials and are treated as secrets. The App does not ask for or collect Pinterest passwords or session cookies.
Pinterest API response data
The App may process account references, board details, Pin identifiers, and delivery status returned by the Pinterest API only transiently in memory to complete an operator-requested action. This response data is not persisted to an application database, log, or cache. Current information is requested again from the API when needed. We retain only authorization credentials and the minimum token metadata supported by Pinterest’s authentication documentation.
4. Why we use information
We process the information described above to:
- deliver and secure this website;
- respond to questions, privacy requests, and security reports;
- authenticate an authorized business account using the platform’s documented authorization flow;
- prepare, validate, and publish the specific content deliberately selected by the operator;
- prevent duplicate, erroneous, or abusive publishing;
- diagnose an operator-reported failure; and
- meet legal, security, and platform-policy obligations.
5. Legal bases
Where European data-protection law applies, we rely on the following legal bases as appropriate:
- Legitimate interests: operating and securing a small business website and internal publishing workflow, provided those interests are not overridden by your rights.
- Performance of the operator-requested service and legitimate interests: connecting the business account and carrying out the specific publishing action requested by its authorized operator. Platform authorization controls access to the account; it is separate from consent as a data-protection legal basis.
- Legal obligation: retaining or disclosing limited information where the law requires it.
6. Pinterest-specific commitments
Our intended Pinterest use is limited to publishing organic Pins for LuxuriaPrintStudio’s own authorized Pinterest business account. For this integration, we commit to the following:
- Every Pin is specifically selected and reviewed by an authorized operator before publishing.
- Authorization uses Pinterest’s documented OAuth process and the minimum scopes necessary for the workflow.
- We do not collect Pinterest login credentials or session cookies.
- We do not scrape Pinterest or use Pinterest information for competitor research, off-platform advertising, engagement manipulation, or data brokerage.
- We do not sell, rent, or share Pinterest information with data brokers or advertising networks.
- We do not use Pinterest content or API information to train, fine-tune, or develop artificial-intelligence or machine-learning models.
- We do not combine Pinterest account information with information from unrelated people or services to build profiles.
8. International transfers
Some infrastructure, email, and platform providers may process information outside the European Economic Area. Where required, we rely on an adequacy decision, contractual safeguards, or another lawful transfer mechanism provided by the relevant service.
9. Retention and deletion
- Authorization tokens: kept only while the connection remains authorized and needed. They are revoked or deleted when access ends.
- Pinterest API response data: processed transiently in memory and not persisted to an application database, log, or cache. It is discarded after the requested API operation completes.
- Locally authored publishing content: kept while it remains part of our own catalog or a pending operator-approved workflow. This does not include persisted Pinterest-returned account, board, or Pin identifiers.
- Correspondence: normally kept for up to 24 months after the issue is resolved, unless a longer period is needed for a legal claim or required record.
- Technical logs: we do not enable advertising analytics or application-level visitor logs. Our hosting service may retain limited edge and security request data only for the period it reasonably needs to deliver the site, prevent abuse, and investigate security incidents. We do not use that data to create visitor profiles.
The practical revocation and request process is explained on our data deletion page.
10. Security
We use proportionate technical and organizational measures designed to protect information. Platform secrets and tokens are kept out of public source code and browser-delivered pages, access is restricted, transport encryption is used, and the publishing workflow includes duplicate and destination checks. No method of storage or transmission is completely risk-free.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, and to object to certain processing or withdraw consent. To make a request, email [email protected]. We may ask for limited information to verify that the request is legitimate.
If European data-protection law applies, you also have the right to complain to your local data-protection authority. In the Netherlands, that authority is the Autoriteit Persoonsgegevens.
13. Children
The website and App are business tools and are not directed to children. We do not knowingly collect personal information from children under 13.
14. Changes to this policy
We may update this policy when the App, our providers, the law, or platform requirements change. The effective date at the top will be revised, and material changes will be described clearly before the changed use begins where required.
15. Contact
Controller: Michiel de Ruiter, trading as LuxuriaPrintStudio, Netherlands
Email: [email protected]
Online shop: etsy.com/shop/LuxuriaPrintStudio