Zeltra Yazılım
This policy covers the internal publishing tool operated by Zeltra Yazılım. It is separate from the privacy policy of zeltrayazilim.com.
Last updated: 28 September 2026
Zeltra Yazılım operates an internal tool that prepares and publishes Pinterest Pins on behalf of a small number of business clients who have engaged us to manage their Pinterest presence. The tool is not a public product. It is not offered for sale, download, or sign-up, and no one outside Zeltra Yazılım operates it.
Each client connects their own Pinterest account through Pinterest’s standard OAuth authorization screen. We never ask a client for their Pinterest password, and we never log in as a client.
user_accounts:read) —
the connected account’s username and account type, used only to confirm that the
correct account was connected.boards:read) — board names and IDs, so
that a Pin is published to the board the client chose.pins:read, pins:write) — we
create Pins that the client has approved, and read back the resulting Pin ID to record
that publishing succeeded.We request no other scopes. We do not access a client’s followers, private messages, secret boards beyond what the board list returns, purchase history, or any data belonging to Pinterest users other than the connected account holder.
Tokens are never written into logs, screenshots, source code, or any document shared with
a third party. The authorization callback page at
social.zeltrayazilim.com/callback is a static page: it reads the
authorization code from the browser address bar and displays it for the client to copy.
It transmits nothing and stores nothing.
To prepare Pin content before publishing, the tool sends the client’s own product material (product photographs, product descriptions, and brand notes supplied by the client) to image-generation and text-generation providers. No Pinterest tokens, no Pinterest account identifiers, and no data read from the Pinterest API are sent to those providers.
A client may disconnect at any time from Pinterest’s own settings (Settings → Security and permissions → Apps), which immediately revokes our access. A client may also ask us to delete their data; when they do, we delete their stored tokens and publishing records within 30 days. Tokens are deleted immediately when an engagement ends.
Access to the systems running this tool is limited to authorized Zeltra personnel. Credentials are held in environment configuration outside of source control. If we become aware of an incident affecting a client’s Pinterest data, we will notify the affected client and revoke the relevant tokens.
Zeltra Yazılım — Türkiye
koray@zeltrayazilim.com