Data Practices Register

Our current vendor, retention, and international-transfer inventory. It supplements the Privacy Notice and is updated when the deployed data flow changes.

Aaron Whitfield · Last updated 22 August 2026

1. Vendors and other recipients

Current service providers, external recipients, and processing roles
Recipient and rolePurpose and data categories
Lovable — application hosting and connected platform services (processor/service provider)Hosts the BackflowPass application and its server functions. It may process request, account and application-content data needed to deliver the hosted service.
Supabase — database, authentication and private report storage (processor/service provider)Stores account, workspace and report records; authenticates users; and holds private report files. It processes the data users enter into synced records.
Paddle — Merchant of Record (independent controller)Processes subscription purchases, payments, invoices, tax, refunds, fraud checks and subscription management. BackflowPass receives limited subscription identifiers and entitlement status, not full payment-card data.
Cloudflare Web Analytics — disabled pending counsel classificationThe hosting environment may otherwise inject its beacon, but BackflowPass sends a document Content-Security-Policy that permits only first-party scripts and Paddle’s checkout loader. That blocks the Cloudflare analytics script, so it is not an active analytics recipient. Re-enable only after counsel approves its classification and any required consent configuration.
BackflowPass first-party product analytics (controller)Only after the visitor selects Allow: an anonymous session identifier, approved event name, page path, plan label and timestamp. The event contract excludes test readings, contact data, addresses, signatures and report files.
Resend — potential reminder-email provider (not active)No automated reminder email is currently sent through Resend. The delivery code and queues are hard-disabled pending recipient unsubscribe/suppression, sender identification, delivery-event handling and notice review.
Google OAuth — sign-in provider when you choose “Continue with Google” (independent provider)Google receives the authentication request and returns the account identity information needed to create or sign in to a BackflowPass account. BackflowPass does not offer Apple or Microsoft sign-in in its current interface; do not enable additional OAuth providers without updating this register and notice.
Google Fonts — not an active recipientThe application uses a system-font stack and does not load Google Fonts. If a future release adds a third-party font CDN, it must be added here before deployment.
Your chosen email or sharing application (independent recipient/service)When you choose to share a PDF report, BackflowPass prepares it locally and opens your chosen mail/share application. BackflowPass does not operate a report-email delivery service or receive delivery/open/click events for that action.

2. Enforced retention schedule

The following limits are implemented by a privileged database purge routine on every analytics/feedback write and by an independent daily database job. They are operational limits and do not replace records a provider must retain under its own legal obligations.

BackflowPass data-retention schedule
DataRetention and deletion method
Account, workspace, synced test and private report-file dataWhile the account is active, unless you delete cloud content or close the account. Account closure deletes cloud content and login after it confirms Paddle future renewal is stopped.
Anonymous first-party analytics30 days from creation; database purge. Events are not associated with an account, so they are not included in an account export.
Feedback messages180 days from creation; database purge. Account-linked feedback is included in export and erased on account closure; anonymous feedback expires on this schedule.
Hashed rate-limit countersOne day from the rate-limit window; database purge.
Unsent/canceled reminder jobsUnsent jobs are canceled while delivery remains disabled. Terminal queue records are purged 30 days after update.
Local Paddle event ledger and account-closure tombstones91 days. The limited tombstone prevents a delayed or replayed provider webhook from recreating entitlement after closure, then is purged. Paddle retains its own payment, invoice and tax records under its notice.

3. International transfers and verification status

  • BackflowPass operates from the United States. Hosting, database, payment and hosting-analytics providers may process data in the United States or other countries, depending on the provider and account configuration.
  • Before relying on a UK, EEA or Swiss transfer mechanism, we maintain the provider’s current contract, processing location and appropriate-transfer documentation in our internal vendor record. This public page does not represent that a particular adequacy decision, SCC module or other safeguard applies unless that record has been verified.
  • Paddle is an independent controller for Merchant-of-Record activities; its own privacy notice explains its processing and transfer practices.

4. Changes and contact

We update this register before introducing a new material data recipient or changing an enforced retention period. Read the Privacy Notice for your rights and account controls, or contact [email protected] with “Privacy Register” in the subject line.