Privacy Policy for The Clearing Pin Scheduler
Effective date: 7 August 2026
Last updated: 7 August 2026
1. About this policy
This privacy policy explains how The Clearing ("The Clearing", "we", "us" or "our") handles personal data in connection with The Clearing Pin Scheduler (the "Scheduler").
The Scheduler is a private, single-account tool used to prepare, approve, schedule, publish and measure original content for The Clearing's own Pinterest business account. It is not offered as a public service and is not affiliated with or endorsed by Pinterest.
Pinterest processes personal data under its own privacy policy when Pinterest services are used.
2. Data controller and contact details
The data controller for processing carried out through the Scheduler is:
The Clearing
Address: Malmo, Sweden
Email: hello@byclearing.com
Questions or requests concerning this policy or personal data can be sent to the email address above.
3. Personal data the Scheduler processes
Depending on the functions used, the Scheduler may process:
- Pinterest account data: the authenticated account identifier, account name and limited profile information needed to connect the correct Pinterest business account.
- Authentication data: Pinterest OAuth access and refresh tokens. The Scheduler does not request, collect or store Pinterest passwords, session cookies or verification codes.
- Content and scheduling data supplied by The Clearing: Pin images, titles, descriptions, destination links, board choices, proposed publication times and approval status.
- Pinterest board and Pin data: information needed to select a board, publish an approved Pin and confirm the result. Pinterest API data is read when needed and is not retained except where Pinterest's developer terms permit retention.
- Performance information: analytics for The Clearing's own account and Pins, such as impressions, saves, Pin clicks and outbound clicks.
- Limited operational records: timestamps, job status, request outcome and technical error information needed to operate, secure and troubleshoot the Scheduler.
The Scheduler does not intentionally collect sensitive personal data, data from other Pinterest accounts, or information about children.
4. Where the data comes from
Data is obtained:
- directly from content and scheduling instructions supplied by The Clearing;
- from The Clearing's Pinterest account after the account owner authorises access through Pinterest's OAuth process; and
- from technical events generated while the Scheduler performs an approved action.
5. Why data is processed and the legal basis
The data is processed to:
- connect and maintain the authorised Pinterest integration;
- show The Clearing's own boards where needed;
- publish Pins that have been individually selected and approved;
- keep the scheduling workflow accurate and prevent duplicate publication;
- measure the performance of The Clearing's own Pins;
- protect credentials, diagnose failures and maintain the Scheduler; and
- comply with legal obligations and Pinterest's applicable developer requirements.
The principal legal basis under the General Data Protection Regulation (GDPR) is The Clearing's legitimate interest in operating and measuring its own content-publishing workflow efficiently and securely (Article 6(1)(f)). Where consent is the appropriate legal basis, it may be withdrawn at any time, including by disconnecting the Pinterest integration. Withdrawal does not affect processing already carried out lawfully.
The Scheduler will not publish a Pin unless that specific Pin, its destination and its scheduled publication have been deliberately approved. It does not automate follows, comments, messages or other engagement activity.
6. Storage and sharing
The Clearing does not sell personal data or Pinterest API data.
Data may be disclosed only where necessary to:
- Pinterest, to authenticate the account, retrieve permitted account information, publish approved content and obtain permitted analytics;
- Microsoft OneDrive, when project files and non-secret scheduling records are synchronised or backed up through The Clearing's existing workspace;
- service providers that securely host or maintain the Scheduler, if such providers are introduced and this policy is updated before they process personal data;
- professional advisers or public authorities where disclosure is required by law or necessary to establish, exercise or defend legal claims.
OAuth tokens and other API credentials are not placed in Pin metadata, public pages or the project repository. They are kept in access-controlled secret storage.
7. International transfers
Pinterest, Microsoft or another approved service provider may process data outside Sweden or the European Economic Area. Where the GDPR applies, The Clearing will rely on an applicable adequacy decision, approved contractual safeguards or another lawful transfer mechanism. The relevant provider's privacy documentation explains its own processing and transfer arrangements.
8. Retention
Data is retained only for as long as necessary for the purpose for which it was processed:
- OAuth credentials are kept until the Pinterest connection is revoked, expires or is no longer required. Replaced or invalid credentials are removed promptly.
- Content, scheduling instructions and approval records created by The Clearing are retained while they remain useful as editorial and business records, and are reviewed periodically.
- Pinterest board and Pin information is requested from the API when needed rather than retained, except for analytics information that Pinterest permits The Clearing to store.
- Performance analytics are retained while needed for comparable content-performance analysis and are reviewed at least annually.
- Routine technical logs are normally deleted or anonymised within 90 days unless they are needed longer to investigate a security incident, resolve a fault or meet a legal obligation.
Data may be retained for a longer period where required by law or for the establishment, exercise or defence of legal claims.
9. Security
The Clearing uses reasonable technical and organisational measures appropriate to the limited nature of the Scheduler. These include least-privilege API permissions, OAuth rather than password collection, access-controlled credential storage, an explicit approval step before publication, limited logging and regular removal of credentials that are no longer needed.
No method of storage or transmission is completely secure. If a personal-data breach creates a risk to individuals, The Clearing will respond and provide any notifications required by applicable law.
10. Your data-protection rights
Subject to the conditions and exceptions in applicable law, individuals may have the right to:
- receive information about how their personal data is processed;
- request access to their personal data;
- have inaccurate or incomplete data corrected;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- receive eligible data in a portable format;
- withdraw consent where processing relies on consent; and
- lodge a complaint with a data-protection authority.
Requests can be made using the contact details in section 2. The Clearing may need to verify the requester's identity before acting on a request.
In Sweden, the supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): https://www.imy.se.
11. Children
The Scheduler is a private business tool and is not directed to children. It is not intended for use by anyone under 13, and The Clearing does not knowingly collect children's personal data through it.
12. Changes to this policy
This policy may be updated when the Scheduler, its service providers or applicable requirements change. The current version will be published at the privacy-policy URL shown in the Pinterest developer application. Material changes will be identified by updating the date at the top of this page.