PennyWall PennyWall ← Back to home

Privacy Policy

Last updated: September 2, 2026

PennyWall is a product of Pingr Intelligence Limited, a company registered in Ireland.

Plain-language summary (not a substitute for the policy below): We collect the minimum needed to run your account and screen your agents' payments: your email, a hashed password, hashed API keys, and the payment details your agents submit for scanning. We never store the actual personal information our scanner finds, only which categories it found. We don't sell your data, and we don't use it for advertising.

Contents

  1. 1. Introduction
  2. 2. Data we collect
  3. 3. Data we deliberately don't keep
  4. 4. How we use your data
  5. 5. Cookies and local storage
  6. 6. Sharing and third parties
  7. 7. Data retention
  8. 8. Security
  9. 9. Your rights
  10. 10. International transfers
  11. 11. Children's privacy
  12. 12. Changes to this policy
  13. 13. Contact

1. Introduction

This Privacy Policy explains what data Pingr Intelligence Limited ("Pingr Intelligence", "we", "us", or "our") collects through PennyWall, why we collect it, and what rights you have over it. It applies to our website, dashboard, and API (together, the "Service"). This policy should be read alongside our Terms & Conditions, which govern your use of the Service more broadly.

2. Data we collect

Account data

When you sign up, we collect your email address and a password, which we store only as a one-way bcrypt hash, never in plain text. We also generate a session token when you log in, so you don't need to re-enter your password on every page.

API keys

When you create an API key, we store a one-way hash of it, a short prefix (enough for you to recognise it in your dashboard), a label you choose, and timestamps for when it was created and last used. We never store the full raw key after the moment you create it.

Payment check data

Every time your agent sends a payment to PennyWall for review, we process the agent identifier you supplied, the payment amount, and any description, reason, or resource URL text included with it, in order to scan that text for personal information and check it against your spending limits. We keep a record of each check (the amount, whether it was allowed, and which categories of personal information, if any, were found) so it can appear in your dashboard's activity log.

Spending settings

We store the daily limit and per-payment limit you configure, along with a running total of how much each of your agents has spent, per day, so limits can be enforced accurately across restarts.

3. Data we deliberately don't keep

This is the whole point of the product, so it's worth stating plainly.

When PennyWall's scanner finds something that looks like an email address, phone number, card number, or similar identifier inside a payment description, we redact it before the payment goes through. Critically:

The entire reason PennyWall exists is to stop personal information from spreading. It would defeat the purpose if our own database became a place where it accumulated instead.

4. How we use your data

We use the data described above to:

We do not use your data to train third-party advertising products, and we do not sell it to data brokers or advertisers.

5. Cookies and local storage

PennyWall doesn't use tracking or advertising cookies. When you log in, your browser stores your session token in local storage so you stay logged in as you move between pages. This is functional, not tracking, it identifies your session, not you as an individual across other sites, and it's cleared when you log out.

6. Sharing and third parties

We don't sell your personal data. We share data only in the following limited circumstances:

7. Data retention

We keep your account data for as long as your account is active. If you delete your account, we delete your account data, API keys, and settings within a reasonable period, except where we're required to retain something for legal or security reasons. Activity log entries (which never contain raw personal information, only category names, as described above) may be retained for a limited period for security and product-improvement purposes even after related data changes.

8. Security

We take reasonable technical measures to protect your data, including one-way hashing for passwords and API keys, encrypted connections between your browser, our servers, and our database, and access controls limiting who can reach production systems. That said, no method of transmission or storage is completely secure, and we can't guarantee absolute security. See our Terms & Conditions for more on what PennyWall does and doesn't guarantee.

9. Your rights

Because Pingr Intelligence is based in Ireland, you have rights under the EU General Data Protection Regulation (GDPR) and Irish data protection law, regardless of where you're located. These include the right to:

To exercise any of these rights, contact us using the details in Section 13.

10. International transfers

Our infrastructure providers may process or store data in countries outside your own, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards, such as standard contractual clauses or a provider's own adequacy protections, to keep your data protected to a standard consistent with this policy.

11. Children's privacy

PennyWall is not directed at, and is not intended for use by, anyone under the age of 16. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we'll delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll take reasonable steps to notify you, such as posting a notice on the Service or emailing the address on your account. The "Last updated" date at the top of this page always reflects the current version.

13. Contact

Questions about this Privacy Policy, or requests relating to your data, can be sent by post to Pingr Intelligence Limited, County Laois, Ireland.