Data Practices Register
Our current vendor, retention, and international-transfer inventory. It supplements the Privacy Notice and is updated when the deployed data flow changes.
Aaron Whitfield · Last updated 22 August 2026
1. Vendors and other recipients
| Recipient and role | Purpose and data categories |
|---|---|
| Lovable — application hosting and connected platform services (processor/service provider) | Hosts the BackflowPass application and its server functions. It may process request, account and application-content data needed to deliver the hosted service. |
| Supabase — database, authentication and private report storage (processor/service provider) | Stores account, workspace and report records; authenticates users; and holds private report files. It processes the data users enter into synced records. |
| Paddle — Merchant of Record (independent controller) | Processes subscription purchases, payments, invoices, tax, refunds, fraud checks and subscription management. BackflowPass receives limited subscription identifiers and entitlement status, not full payment-card data. |
| Cloudflare Web Analytics — disabled pending counsel classification | The hosting environment may otherwise inject its beacon, but BackflowPass sends a document Content-Security-Policy that permits only first-party scripts and Paddle’s checkout loader. That blocks the Cloudflare analytics script, so it is not an active analytics recipient. Re-enable only after counsel approves its classification and any required consent configuration. |
| BackflowPass first-party product analytics (controller) | Only after the visitor selects Allow: an anonymous session identifier, approved event name, page path, plan label and timestamp. The event contract excludes test readings, contact data, addresses, signatures and report files. |
| Resend — potential reminder-email provider (not active) | No automated reminder email is currently sent through Resend. The delivery code and queues are hard-disabled pending recipient unsubscribe/suppression, sender identification, delivery-event handling and notice review. |
| Google OAuth — sign-in provider when you choose “Continue with Google” (independent provider) | Google receives the authentication request and returns the account identity information needed to create or sign in to a BackflowPass account. BackflowPass does not offer Apple or Microsoft sign-in in its current interface; do not enable additional OAuth providers without updating this register and notice. |
| Google Fonts — not an active recipient | The application uses a system-font stack and does not load Google Fonts. If a future release adds a third-party font CDN, it must be added here before deployment. |
| Your chosen email or sharing application (independent recipient/service) | When you choose to share a PDF report, BackflowPass prepares it locally and opens your chosen mail/share application. BackflowPass does not operate a report-email delivery service or receive delivery/open/click events for that action. |
2. Enforced retention schedule
The following limits are implemented by a privileged database purge routine on every analytics/feedback write and by an independent daily database job. They are operational limits and do not replace records a provider must retain under its own legal obligations.
| Data | Retention and deletion method |
|---|---|
| Account, workspace, synced test and private report-file data | While the account is active, unless you delete cloud content or close the account. Account closure deletes cloud content and login after it confirms Paddle future renewal is stopped. |
| Anonymous first-party analytics | 30 days from creation; database purge. Events are not associated with an account, so they are not included in an account export. |
| Feedback messages | 180 days from creation; database purge. Account-linked feedback is included in export and erased on account closure; anonymous feedback expires on this schedule. |
| Hashed rate-limit counters | One day from the rate-limit window; database purge. |
| Unsent/canceled reminder jobs | Unsent jobs are canceled while delivery remains disabled. Terminal queue records are purged 30 days after update. |
| Local Paddle event ledger and account-closure tombstones | 91 days. The limited tombstone prevents a delayed or replayed provider webhook from recreating entitlement after closure, then is purged. Paddle retains its own payment, invoice and tax records under its notice. |
3. International transfers and verification status
- BackflowPass operates from the United States. Hosting, database, payment and hosting-analytics providers may process data in the United States or other countries, depending on the provider and account configuration.
- Before relying on a UK, EEA or Swiss transfer mechanism, we maintain the provider’s current contract, processing location and appropriate-transfer documentation in our internal vendor record. This public page does not represent that a particular adequacy decision, SCC module or other safeguard applies unless that record has been verified.
- Paddle is an independent controller for Merchant-of-Record activities; its own privacy notice explains its processing and transfer practices.
4. Changes and contact
We update this register before introducing a new material data recipient or changing an enforced retention period. Read the Privacy Notice for your rights and account controls, or contact [email protected] with “Privacy Register” in the subject line.