Log in Add catchAdd

Privacy policy

This policy explains which personal data the Pinfishing angling community collects, what it is used for, how long it is kept and how you can exercise your rights under the General Data Protection Regulation (GDPR).

1. Who is responsible for your data

Data controller: Balta pelė, MB (company code 304954688, VAT number LT100012008216), Skodinio g. 44, Šepetos k., LT-40335 Kupiškis district, Lithuania.

For anything about your privacy, write to info@pinfishing.com or use the contact page.

2. What we collect

  • Account. User name, e-mail address, password (stored only as a cryptographic hash), language and settings. If you sign in with Google or Facebook, we receive your name, e-mail address, profile picture and account identifier from them — never your password, and we do not keep their access tokens. On your profile you may add a town, a short bio and a photo.
  • Catches and other content. What you publish yourself: catch photos, species, weight, length, date and time, water, bait, technique, descriptions, comments, likes, private messages and forum posts.
  • Photos and their metadata. When you upload a photo we read the date and GPS position from its EXIF data to suggest the time and the water of the catch. We only keep what you confirm in the form, and the photo itself is stored without its GPS position and device details (make, model, serial numbers), so a published photo does not reveal where you took it.
  • Location. The water of a catch and, if you mark it, the exact spot on the map. Exact coordinates are shown to others only when you allow it in the catch's privacy settings. From your IP address we only derive an approximate location (town or region) to show nearby waters and weather forecasts: the last part of the address is removed first (only the network is used, e.g. 84.15.3.x), this shortened address is looked up with the IP-location service hostip.info, and the result is cached for at most 30 days. We do not collect your precise location unless you mark it yourself.
  • Premium membership. Payments are processed by a payment provider (Paysera or PayPal). We only receive the payment confirmation, amount, date and order number — never your card or bank login details.
  • Technical data. IP address, browser type, request times and error logs — for security, abuse prevention and fixing faults. The IP address stored with a catch, a comment and at sign-up (to investigate abuse) is deleted after 12 months.

3. Cookies and similar technologies

Necessary cookies are always on: the login session, protection against request forgery (CSRF), your language and theme and your consent choice (stored in your browser). The site cannot work without them, so they need no consent.

Optional cookies are used only with your consent: visitor statistics (Google Analytics 4) and advertising (Google AdSense). Consent is collected by Google’s certified consent dialog (IAB Transparency & Consent Framework v2.2). The statistics tool is not loaded at all until you allow it. Ads follow your choice: personalised ads only with your consent; if you decline, only non-personalised or limited ads without advertising cookies. Declining is as easy as accepting, and you can change your choice at any time with “Privacy settings” at the bottom of every page. Signed-in members see no ads.

4. Why we use your data and on what legal basis

  • Performance of a contract (GDPR Art. 6(1)(b)): running your account, publishing your content, delivering messages, Premium features (bite forecast, catch analyzer).
  • Legitimate interests (Art. 6(1)(f)): site security, fraud and spam prevention, improving the service from aggregated (de-identified) data such as which fish bite in which weather, and funding the site with non-personalised ads for visitors who are not signed in.
  • Consent (Art. 6(1)(a)): visitor statistics (Google Analytics 4) and personalised advertising. You can withdraw your consent at any time. We send no newsletters.
  • Legal obligation (Art. 6(1)(c)): keeping accounting records of payments.

5. Who sees your data

Public catches, comments and profiles can be seen by every visitor — that is what a community is for. For every catch you decide whether to show the water, the exact spot and the bait.

These service providers (processors) help us process data and use it only on our instructions, under data processing agreements:

  • E-data (Lithuania) — the web server (hosting): the database and uploaded photos.
  • Interneto vizija (Lithuania) — encrypted backups on a separate server.
  • Google Workspace — e-mail: each site sends from its own mailbox (kimba.lt — info@kimba.lt, pinfishing.com — info@pinfishing.com). These are system messages (sign-up confirmation, password reset, account deletion confirmation, new private message notice) and our correspondence with you.
  • Google Analytics 4 — visitor statistics, only with your consent (see section 3).

Independent controllers, who process data under their own privacy policies:

  • Google (AdSense advertising and the Funding Choices consent management platform) — ads for visitors who are not signed in: personalised only with your consent, otherwise non-personalised or limited ads without advertising cookies; the consent dialog stores your choice (see section 3).
  • Paysera, PayPal — Premium membership payments.
  • Google, Facebook (Meta) — if you sign in with them, they know that you signed in to our site.

Weather providers (MET Norway, Open-Meteo) only receive the coordinates of a water or of a catch spot, rounded to about 1 km, and a time — never who you are. The Lithuanian Hydrometeorological Service (LHMT, api.meteo.lt) only receives the code of its nearest weather station and a date — no coordinates. The IP location service hostip.info only receives a truncated IP address (see section 2). Map tiles are loaded from the OpenStreetMap Foundation's servers (United Kingdom), which therefore see your IP address and the map area you view; YouTube videos embedded in articles (youtube-nocookie.com) pass your IP address to Google.

We do not sell personal data. If data is transferred outside the European Economic Area (e.g. to Google or Meta group companies in the USA), this only happens with the safeguards the GDPR requires (the EU–US Data Privacy Framework or the European Commission's standard contractual clauses).

6. How long we keep it

  • Account data and content — as long as you have an account. You can delete your account in the settings: once you confirm by e-mail, the account, profile photo, settings and likes are erased at once, private catches are deleted and public catches are de-identified (no author, IP address or private bait). Your comments and the messages you sent stay with their recipients but are shown as from a deleted user, without your name or IP address — you can delete them yourself before deleting the account. Backups age out within at most 60 days.
  • Unconfirmed accounts that were never used (e-mail not confirmed, never signed in, no content) — 30 days after sign-up.
  • IP addresses stored with catches, comments and sign-ups — 12 months; failed sign-in records — 90 days; the IP-location cache — 30 days.
  • Technical logs — no longer than 12 months (server logs are usually overwritten within a few weeks).
  • Payment records (amount, date, order and transaction numbers) — as long as accounting law requires (10 years under Lithuanian law). The payer's name, e-mail and address in the payment providers' notifications are deleted after 90 days; after an account is deleted the payment record stays without a link to it.
  • Optional cookies — no longer than 13 months, or until you withdraw your consent.

7. Your rights

You have the right to access your data, to have it corrected or erased, to restrict its processing, to object to processing based on legitimate interests, to receive your data in a portable format and to withdraw consent at any time. You can view and change most of your data yourself in your profile settings, where you can also download your data (a JSON file: account, catches incl. coordinates, comments, likes, messages, payments) and delete your account; for anything else write to info@pinfishing.com — we reply within one month (in complex cases this can be extended, and we will tell you).

If you believe your data is processed unlawfully, you can lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt) or with the data protection authority of your country.

8. Children

You can create an account on your own from the age of 14 (or the age of digital consent in your country, if higher) — you confirm this when you sign up or first sign in with Google or Facebook. Younger children may only use the site with the consent of a parent or guardian. If we learn that we collected data of a younger child without such consent, we delete it.

9. Security

The site only runs over encrypted HTTPS, passwords are stored only as hashes, access to data is limited to those who need it for their work, and backups are kept on a separate, access-restricted server in Lithuania. We notify personal data breaches that may harm you as the law requires.

10. Changes to this policy

When the way we process data changes, we update this policy and its effective date. We announce significant changes on the site or by e-mail.

Menu

Theme