Data processing terms
For developers whose customers are in jurisdictions that require one, including the EU and the UK. These terms form part of the terms of service and require no separate signature.
Last updated 13 September 2026.
1. Roles
For the data of people passing through your funnel — visitors and subscribers — you are the controller and Passback (Projekt Studio) is the processor. For your own account data we are the controller, and the privacy policy covers that.
2. What we process, and why
| Data | Purpose | Kept |
|---|---|---|
| Anonymous visitor id, screens viewed, answers given, source of the visit | Serving the funnel; your analytics and split tests | 90 days, then aggregated |
| Subscriber email, Stripe customer and subscription ids, plan, status | Telling your app who has paid | Life of the subscription, plus your records period |
| Device id (if your app supplied one) | Recognising the device that paid | With the subscriber record |
| Ad click ids; hashed email on payment | Reporting a payment to the ad network you connected | Sent once; the click id kept with the visit |
We process only on your documented instructions, which are: the configuration of your funnels, and the use of the dashboard. We do not use this data for our own purposes, and we do not sell it.
3. Sub-processors
Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email). Meta and TikTok receive payment events only when you connect your ad account, and then as your processors under your agreement with them. We will notify account holders by email at least thirty days before adding a sub-processor. You may object; if the objection cannot be resolved you may terminate the agreement.
4. Security
The measures on the security page: TLS everywhere, row-level security in the database, secrets kept out of the browser, hashed API keys, sealed tokens, verified webhooks. We will keep them at least at this level.
5. Personnel
Access is limited to personnel who require it to operate the service, and all are bound by confidentiality obligations.
6. Assistance
If one of your customers exercises a right — access, deletion, correction — and asks us rather than you, we will pass it to you within five working days and help you answer. We will help you with a data protection impact assessment or a regulator's question to the extent it concerns our processing.
7. Incidents
We will tell you about a personal data breach affecting your customers without undue delay after we become aware of it, and within 72 hours at most, with what we know and what we are doing.
8. Data location and transfers
The database region is the one your Supabase project is in — for Passback's production instance, the United States. Where data moves from the EU or UK to the United States, the sub-processors above rely on the EU–US Data Privacy Framework and the UK extension where certified, and on standard contractual clauses otherwise. We will provide copies on request.
9. Audits
We will complete a reasonable written security questionnaire once per year. We do not currently hold an independent audit report.
10. Termination
On closure of your account we delete your customers' data within thirty days, except where retention is required by law. An export is provided on request made before closure.
If your organisation requires a countersigned DPA, contact us.
Terms of service · Privacy policy · Data processing terms · Contact