Backstop
TermsPrivacyRefundDPA
DRAFT — not yet in force. These documents are templates grounded in how Backstop actually handles data. They must be reviewed and finalized by qualified legal counsel, and the placeholders (in [brackets]) filled in, before Backstop takes its first payment.

Privacy Policy

Effective date: [DATE] · Last updated: [DATE]

This Privacy Policy explains how [LEGAL ENTITY NAME] (“Backstop”) collects, uses, and protects information when you use the service. For business data you route through Backstop, you are the controller and Backstop is a processor acting on your instructions; see the Data Processing Addendum.

1. What we collect

CategoryExamplesWhy
Account dataName, email, organizationTo create and administer your account
Connection credentialsPlatform API tokensTo read prior state and execute writes/undo. Stored encrypted (see §4).
Journal dataPrior and written state of the records your agent changes — which may include personal data held in your CRM or store (names, emails, order details)To make writes reversible, previewable, and auditable
Change-feed dataObject ids and timestamps of observed writesTo correlate protected vs unprotected writes and compute fidelity
Billing dataPlan, subscription status, Stripe customer idTo bill you. Card details are handled by Stripe, not stored by us.
Usage/technical dataTimestamps, request metadata, logsSecurity, debugging, and reliability. We never log tokens or record values.

2. How we use it

To provide, secure, and improve the service; to enable undo, preview, diff, and audit; to detect unprotected writes; to bill you; and to communicate about your account (including degradation notices when billing lapses). We do not sell your data. We do not use your journal data to train models.

3. Field exclusions

You may designate fields that Backstop will never journal for restore, diff, or write back. Use this for data you do not want recorded (for example, sensitive notes or identifiers). Excluded fields are honored across the write, restore, diff, and conflict paths.

4. Security

Platform tokens are encrypted at rest using envelope encryption (AES-256-GCM with a per-tenant data key wrapped by a master key). Tenant data is isolated at the database level with row-level security. Access to the MCP endpoints requires a bearer token; the operator console requires separate authentication. All traffic is over TLS. Tokens and record values are never written to logs.

5. Sub-processors

We use a small set of sub-processors to run the service:

Sub-processorPurpose
Fly.ioApplication hosting and managed Postgres database
StripePayment processing and subscription billing

The platforms you connect (HubSpot, Shopify) are your own systems, not our sub-processors. We will give notice before adding a sub-processor. [Confirm the current list before publishing.]

6. Retention and deletion

Journal data is retained for your plan's retention window; a downgrade preserves it for a 14-day grace window first. On cancellation, data is kept for 30 days (export available) then deleted. You may request immediate hard deletion of your recorded history at any time, and you may delete connections to stop further journaling.

7. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Because much of the personal data Backstop holds belongs to your customers and is processed on your behalf, we will assist you in responding to such requests as described in the DPA. To exercise rights in data we control, contact us below.

8. International transfers

Data may be processed in the region(s) where our infrastructure runs. Where required, transfers are made under appropriate safeguards. [Specify regions and mechanisms with counsel.]

9. Children

The service is for businesses and is not directed to children.

10. Changes and contact

We may update this Policy; material changes will be communicated. Questions or requests: privacy@[DOMAIN] · [LEGAL ENTITY NAME], [ADDRESS].