[brackets]) filled in, before Backstop takes its first payment.This Privacy Policy explains how [LEGAL ENTITY NAME] (“Backstop”) collects, uses, and protects information when you use the service. For business data you route through Backstop, you are the controller and Backstop is a processor acting on your instructions; see the Data Processing Addendum.
| Category | Examples | Why |
|---|---|---|
| Account data | Name, email, organization | To create and administer your account |
| Connection credentials | Platform API tokens | To read prior state and execute writes/undo. Stored encrypted (see §4). |
| Journal data | Prior and written state of the records your agent changes — which may include personal data held in your CRM or store (names, emails, order details) | To make writes reversible, previewable, and auditable |
| Change-feed data | Object ids and timestamps of observed writes | To correlate protected vs unprotected writes and compute fidelity |
| Billing data | Plan, subscription status, Stripe customer id | To bill you. Card details are handled by Stripe, not stored by us. |
| Usage/technical data | Timestamps, request metadata, logs | Security, debugging, and reliability. We never log tokens or record values. |
To provide, secure, and improve the service; to enable undo, preview, diff, and audit; to detect unprotected writes; to bill you; and to communicate about your account (including degradation notices when billing lapses). We do not sell your data. We do not use your journal data to train models.
You may designate fields that Backstop will never journal for restore, diff, or write back. Use this for data you do not want recorded (for example, sensitive notes or identifiers). Excluded fields are honored across the write, restore, diff, and conflict paths.
Platform tokens are encrypted at rest using envelope encryption (AES-256-GCM with a per-tenant data key wrapped by a master key). Tenant data is isolated at the database level with row-level security. Access to the MCP endpoints requires a bearer token; the operator console requires separate authentication. All traffic is over TLS. Tokens and record values are never written to logs.
We use a small set of sub-processors to run the service:
| Sub-processor | Purpose |
|---|---|
| Fly.io | Application hosting and managed Postgres database |
| Stripe | Payment processing and subscription billing |
The platforms you connect (HubSpot, Shopify) are your own systems, not our sub-processors. We will give notice before adding a sub-processor. [Confirm the current list before publishing.]
Journal data is retained for your plan's retention window; a downgrade preserves it for a 14-day grace window first. On cancellation, data is kept for 30 days (export available) then deleted. You may request immediate hard deletion of your recorded history at any time, and you may delete connections to stop further journaling.
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Because much of the personal data Backstop holds belongs to your customers and is processed on your behalf, we will assist you in responding to such requests as described in the DPA. To exercise rights in data we control, contact us below.
Data may be processed in the region(s) where our infrastructure runs. Where required, transfers are made under appropriate safeguards. [Specify regions and mechanisms with counsel.]
The service is for businesses and is not directed to children.
We may update this Policy; material changes will be communicated. Questions or requests: privacy@[DOMAIN] · [LEGAL ENTITY NAME], [ADDRESS].