Data processing terms

For developers whose customers are in jurisdictions that require one, including the EU and the UK. These terms form part of the terms of service and require no separate signature.

Last updated 13 September 2026.

1. Roles

For the data of people passing through your funnel — visitors and subscribers — you are the controller and Passback (Projekt Studio) is the processor. For your own account data we are the controller, and the privacy policy covers that.

2. What we process, and why

DataPurposeKept
Anonymous visitor id, screens viewed, answers given, source of the visitServing the funnel; your analytics and split tests90 days, then aggregated
Subscriber email, Stripe customer and subscription ids, plan, statusTelling your app who has paidLife of the subscription, plus your records period
Device id (if your app supplied one)Recognising the device that paidWith the subscriber record
Ad click ids; hashed email on paymentReporting a payment to the ad network you connectedSent once; the click id kept with the visit

We process only on your documented instructions, which are: the configuration of your funnels, and the use of the dashboard. We do not use this data for our own purposes, and we do not sell it.

3. Sub-processors

Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email). Meta and TikTok receive payment events only when you connect your ad account, and then as your processors under your agreement with them. We will notify account holders by email at least thirty days before adding a sub-processor. You may object; if the objection cannot be resolved you may terminate the agreement.

4. Security

The measures on the security page: TLS everywhere, row-level security in the database, secrets kept out of the browser, hashed API keys, sealed tokens, verified webhooks. We will keep them at least at this level.

5. Personnel

Access is limited to personnel who require it to operate the service, and all are bound by confidentiality obligations.

6. Assistance

If one of your customers exercises a right — access, deletion, correction — and asks us rather than you, we will pass it to you within five working days and help you answer. We will help you with a data protection impact assessment or a regulator's question to the extent it concerns our processing.

7. Incidents

We will tell you about a personal data breach affecting your customers without undue delay after we become aware of it, and within 72 hours at most, with what we know and what we are doing.

8. Data location and transfers

The database region is the one your Supabase project is in — for Passback's production instance, the United States. Where data moves from the EU or UK to the United States, the sub-processors above rely on the EU–US Data Privacy Framework and the UK extension where certified, and on standard contractual clauses otherwise. We will provide copies on request.

9. Audits

We will complete a reasonable written security questionnaire once per year. We do not currently hold an independent audit report.

10. Termination

On closure of your account we delete your customers' data within thirty days, except where retention is required by law. An export is provided on request made before closure.

If your organisation requires a countersigned DPA, contact us.


Terms of service · Privacy policy · Data processing terms · Contact