Privacy policy
Last updated 24 September 2026
ScaleBop (ABN 89 886 488 110) runs Pinch MCP. This policy explains what personal information we collect, why, and how we protect it. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
What we collect
- Your account: your name, email address and a hash of your password (never the password itself), and, for each signed-in session, when it started and the IP address and browser it came from.
- Your Pinch credentials: your Merchant ID or Application ID and Secret Key. The Secret Key is encrypted with keys held in AWS Key Management Service and is only decrypted to get a short-lived access token from Pinch. We never show it again or write it to logs.
- Requests your AI tools make: for each request, the tool used, when, how long it took, its outcome, which token or app made it, the AI tool's name and version, and the Pinch API endpoints it called. Tool inputs are stored with free text shortened or hashed (for example, only a hint of a search term is kept). We do not store the data Pinch returns, such as payer names or payment details.
- Billing: your billing details (name, and optionally company, ABN and address), your purchases and invoices, and your saved card's brand, last four digits and expiry. Card numbers go straight from your browser to Pinch Payments and never reach us.
- Security records: an audit log of important actions, such as adding Pinch credentials, creating tokens, connecting apps and changing auto top-up, with the IP address they came from.
How we use it
To run the service: signing you in, calling Pinch on your behalf, counting and charging calls, taking payments, issuing invoices, sending emails about your account (such as usage alerts, top-up notices and invoices), preventing fraud and abuse, and supporting you. We don't sell personal information or use it for advertising, and we don't use analytics or advertising cookies. The only cookie is the one that keeps you signed in.
Your Pinch data and your AI tool
When your AI tool asks for Pinch data, we fetch it from Pinch and pass it to that tool without keeping a copy. From there, the AI provider you chose (for example Anthropic, OpenAI, GitHub or Cursor) handles it under its own privacy policy. Pinch data can include your customers' personal information, so connect only tools you trust with it.
Where it's kept and who else is involved
- Everything we store, including backups and logs, is kept in Amazon Web Services' Sydney region (ap-southeast-2).
- Pinch Payments processes card payments and holds saved cards.
- Amazon Simple Email Service sends our emails.
How long we keep it
- Request logs: 90 days. After that, only daily totals of calls per tool are kept.
- Invoices, purchases and the credit ledger: kept as long as tax and financial record-keeping laws require.
- Everything else: until you delete your account. Deleting it removes your Pinch credentials, tokens, app connections and saved card straight away.
Security
Data is encrypted in transit and at rest. MCP tokens are stored only as keyed hashes and shown to you once. Access to production systems is restricted and logged. If a data breach is likely to cause you serious harm, we'll tell you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
Your choices and rights
You can see and correct your details in Settings, see your request log and purchases in the portal, and delete your account at any time. You can also ask us for a copy of the personal information we hold about you or to correct it: contact [privacy contact email]. If you're unhappy with how we've handled a complaint, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We'll post updates here and email you about material changes before they take effect.