Legal

Privacy Policy

Northpin INC operates Shotwisp. This policy explains what information we process, why we use it, when we disclose it, and the choices available to you.

Effective and last updated: August 11, 2026

1. Scope and roles

This policy applies to Shotwisp websites, accounts, dashboards, APIs, image-sharing, screenshot and PDF services, contact forms, and related support. It does not apply to a third-party website merely because you ask Shotwisp to capture it or follow a link to it.

For account, billing, product usage, contact, and website information, Northpin INC generally determines why and how the information is used. When you use Shotwisp to process content for someone else, you are responsible for deciding whether you have authority to do so and for any privacy notices or permissions that apply to that content.

2. Information we collect

Account and identity information

We collect your name, email address, account role, plan, verification state, onboarding state, and account timestamps. For password accounts, we store a one-way password hash rather than the password itself. If you use Google or GitHub sign-in, we receive a verified email, profile name, provider name, and provider account identifier. OAuth access tokens are used to obtain identity information during sign-in and are not retained by Shotwisp.

Content and service instructions

We process images and files you upload; filenames, formats, sizes, storage keys, expiry choices, view counts, and share-link identifiers; public URLs you ask us to capture; screenshot or PDF options; generated files; and error and duration information. API keys are stored as cryptographic hashes with a short identifying prefix. You should not place secrets in filenames, capture URLs, or contact messages.

Billing and usage information

For paid plans, we receive and store Stripe customer and subscription identifiers, plan and subscription status, billing-period dates, cancellation state, enabled overages, and metered usage records. Stripe—not Shotwisp—collects and processes full payment-card details through its hosted checkout and billing tools.

Communications and reports

We collect the name, email, subject, and message you submit through the contact form. Abuse reports may include the reported link, reason, details, network address, status, and timestamps. Please do not include passwords, API keys, or unnecessary sensitive information in a message or report.

Device, network, and technical information

We process request timestamps, IP or other network identifiers, request source, authentication and security events, and technical request or error information needed to deliver and protect the service. Some rate-limit identifiers are shortened cryptographic hashes rather than raw network addresses. We also use the essential cookies described in our Cookie Policy.

3. How we collect information

  • From you, when you create an account, submit content, configure a capture, buy a plan, contact us, or report abuse.
  • Automatically, when our servers authenticate requests, meter usage, apply rate limits, store files, and record security or operational events.
  • From service providers, including Google or GitHub for sign-in and Stripe for billing and subscription events.

4. Why we use information

  • Provide, authenticate, maintain, and support Shotwisp.
  • Store, expire, serve, render, and delete content as requested.
  • Administer plans, process billing, meter quotas, and prevent fraud.
  • Verify email addresses and send essential account or retention notices.
  • Respond to contact messages, privacy requests, and abuse reports.
  • Protect users, enforce our terms, debug failures, and improve reliability.
  • Comply with law, valid legal process, and our recordkeeping obligations.

Where data-protection law requires a legal basis, we rely as appropriate on performance of our contract with you, compliance with law, consent, and our legitimate interests in operating, securing, supporting, and improving the service. We balance legitimate interests against the rights and interests of affected individuals.

5. When information is disclosed

We may disclose relevant information to:

  • Infrastructure and service providers that host the app or database, store files, render pages, send email, validate email addresses, process payments, or help secure and operate Shotwisp. Current product integrations may include Cloudflare, Amazon SES, MailSift, Stripe, Google, and GitHub.
  • People you choose to share with. Anyone with a working public share link may access the associated content.
  • Authorities or affected parties when reasonably necessary to comply with law or valid process; protect rights, safety, and security; investigate abuse; or enforce our agreements.
  • Transaction participants in connection with a financing, reorganization, merger, acquisition, or sale, subject to appropriate confidentiality and notice where required.

We do not sell personal information. Shotwisp uses the Google tag (gtag.js) for Google Ads conversion measurement, which sets Google advertising cookies and shares limited visit data (such as your IP address, the page visited, and an ad click identifier) with Google, as described in our Cookie Policy. We also use TrackHaven, a cookieless analytics service, to measure page visits with random identifiers kept in your browser's local storage; this visit data is not used for advertising. We do not use other advertising or analytics cookies.

6. Public links and captured websites

Content at a Shotwisp share link is intended to be retrievable by anyone who has the URL. Search engines or recipients may copy, cache, or redistribute content outside our control. Deleting or expiring our copy cannot delete copies held by others. Website captures may reproduce third-party personal information; only capture and share pages you are lawfully permitted to use.

7. Retention and deletion

  • Anonymous uploaded links expire within 24 hours, and Free-account upload links within 30 days. A paid link created without an expiry may remain active while paid access continues; if paid access ends, it may be deleted after a 30-day grace period.
  • Account screenshots, PDFs, and related records are generally retained until you delete them, delete the account, or an operational, legal, security, or policy reason requires earlier or longer retention.
  • Login sessions expire after 30 days. Temporary OAuth security cookies expire after about 10 minutes, and the dashboard preference cookie after 7 days.
  • Contact messages, abuse reports, billing records, usage events, security records, and backups are kept only as long as reasonably necessary for the purposes described above, including dispute, fraud, tax, accounting, and legal obligations.

You can delete your account in dashboard settings. That process removes the account and associated stored objects from active systems, subject to temporary backups, records we must retain, content previously copied by others, and failures outside our reasonable control.

8. Security

We use safeguards designed for the nature of the information we process, including hashed passwords and API keys, single-use hashed recovery tokens, protected session cookies, access controls, origin checks, input validation, rate limits, and restricted administrative views. No internet service is completely secure, so we cannot guarantee absolute security. Notify us promptly through the contact form if you believe your account, key, or content has been compromised.

9. International processing

Northpin and its providers may process information in the United States and other countries whose laws may differ from those where you live. Where required, we use a legally recognized transfer mechanism or other safeguards for international transfers.

10. Your privacy choices and rights

You may update your name or email, change your password, revoke API keys, delete content, cancel billing, and delete your account through Shotwisp. Depending on where you live and subject to exceptions, you may also have a right to know or access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, appeal a decision, or complain to a data-protection authority. We will not discriminate against you for exercising an applicable privacy right.

Submit a request through our contact form with “Privacy request” in the subject. Describe the right you want to exercise and the account email or share link involved. We may need to verify your identity and authority before acting. An authorized agent may submit a request where law allows, but we may ask for proof of authorization. We do not sell personal information. Where the Google Ads measurement described in our Cookie Policy is treated as sharing for advertising purposes under your local law, you can opt out by blocking the Google cookies in your browser or via Google Ads Settings.

11. Children

Shotwisp is not directed to children and is available only to people at least 18 years old. We do not knowingly collect personal information from children under 13. If you believe a child provided personal information, contact us so we can investigate and delete it as appropriate.

12. Changes and contact

We may update this policy as Shotwisp or the law changes. We will revise the effective date and provide additional notice for material changes when required. Questions, privacy requests, and concerns can be sent to Northpin INC through the contact form.