Pikkai · Effective August 8, 2026
Privacy Policy
This Policy explains the personal data Pikkai processes, why it is processed, the providers involved, and how to exercise privacy rights.
Questions or verified requests: support@pikkai.com
Data Pikkai processes
- Google-backed account identifiers, name, email, image, and session data.
- Submission text, website details, ownership, status, Logo, screenshots, and reports.
- Checkout email, provider identifiers, amount, currency, tax, payment, refund, dispute, and ledger facts. Pikkai does not receive full card numbers.
- Security, moderation, consent, diagnostic, device, browser, approximate location, referral, and usage events where the relevant provider supports them.
- Support messages and evidence supplied for privacy, billing, policy, or rights requests.
Purposes and legal bases
Pikkai processes data to provide accounts, Submissions, publication, payment, refunds, moderation, abuse prevention, support, security, analytics, legal compliance, and dispute handling. The applicable bases are performance of a contract, legitimate interests in operating and securing the directory, legal obligations, and consent for optional analytics storage where required. Consent can be withdrawn without affecting earlier lawful processing.
Providers and international processing
Neon provides authentication and Postgres. Vercel provides hosting, Workflows, logs, and Blob storage. OpenAI Moderation receives submitted text and may classify implemented safety categories. Stripe and Waffo process Checkout, payment, refund, and dispute facts. Google Analytics and Microsoft Clarity provide measurement. Cloudflare Turnstile checks anonymous abuse signals. These providers may process data across borders under their own infrastructure and legal safeguards.
Submission text and media may be processed for moderation. Pikkai does not sell personal data and does not train models on Submissions.
Analytics consent
Pending or denied optional analytics consent keeps optional browser storage disabled. Provider-supported limited cookieless measurement may still send constrained requests or aggregate signals. Pikkai does not describe this mode as zero-request measurement. On Production, use Privacy choices in the global footer to revisit or change the stored choice at any time.
Retention, Account Deletion, and Unpublish
A verified Account Deletion request immediately disables application access. Pikkai deletes or anonymizes personal account data, unsubmitted Drafts, and private media within 30 calendar days. The same email may name Published products for immediate Unpublish. Unpublished content and media stay privately recoverable for 90 days and are then removed unless a legal, security, or dispute hold applies.
Payment, refund, chargeback, and ledger facts are retained for seven years after the transaction. Closed report, security, and Operator audit facts are retained for two years. A documented legal or dispute hold may require longer retention. Provider records may follow the provider’s mandatory fraud, tax, and legal retention duties.
Your rights
Send a verified request to access, correct, delete, export, restrict, or object to processing, or to withdraw consent. Pikkai responds within 30 calendar days, subject to identity verification, applicable extensions, legal exceptions, and records that must be retained. Complaints may also be made to the competent privacy authority.