Privacy policy
This policy covers developers with a Passback account, customers purchasing through a funnel, and visitors to this website. What we hold about each is different, so each is described separately.
Last updated 13 September 2026.
Who we are
Passback is operated by Projekt Studio (“we”). We are the controller for developer account data described below, and a processor acting on the developer's instructions for their customers' data, as set out in the data processing terms.
If you have a developer account
We hold:
- Your email address and a password hash, held by Supabase Auth on our behalf.
- Your Stripe Connect account id. Not your keys, not your bank details.
- The funnels, screens, plans and settings you create.
- Your billing subscription with us, on Stripe, under your email.
- Sign-in session cookies (httpOnly), and a theme preference cookie.
We use this information to operate your account and bill you. We email you about failed payments on your funnels, about your billing with us, and in reply to your messages. We do not send marketing email without your consent.
If you are paying for an app through a funnel
The funnel is the developer's. The payment is between you and the developer's Stripe account; your card details go to Stripe and never to us. Stripe tells us the email you gave at checkout, a customer id and a subscription id, and we store these so the developer's app can recognise you as subscribed.
While you move through a funnel we record which screens you saw and what you answered, against a random visitor id in your browser's session storage — not your name or email. If the app opened the funnel with a device id, we store that id so the app can ask whether this device paid. If you arrived from a Meta, TikTok or Google ad, the click id in the address is kept so the developer can tell that network the ad worked; with your payment, we send that network the click id and a hashed email, and nothing about what you answered.
Questions about your subscription, including refunds, cancellation and your data, should go to the developer whose app you purchased; they hold the customer relationship and the Stripe account. If you cannot reach them, contact us and we will help.
If you are just reading this website
We record visits: the page, the referring site, the device type, the country inferred from the request, and which links and buttons were used, against a random identifier held in your browser's session storage and discarded when the tab closes. We use no third-party analytics script, no advertising cookie and no fingerprinting. If you join the waitlist or use the contact form, we hold what you submitted.
Who else sees it
- Supabase hosts the database and authentication.
- Vercel hosts the application and serves requests.
- Stripe processes payments and holds card data.
- Resend delivers the emails we send.
- Meta and TikTok receive a payment event only when the developer has connected their ad account and the visitor arrived from their ad.
We do not sell data, and we do not share it beyond the list above.
How long
Account data for as long as the account exists and thirty days after it is deleted. Funnel events for ninety days, then aggregated. Subscriber records for as long as the subscription exists in Stripe plus the period the developer needs for their own records. Website visit records for ninety days. Contact and waitlist messages until dealt with, then deleted.
Your rights
You may request access to the personal data we hold about you, ask for it to be corrected or deleted, and object to its processing, under the GDPR in the EU and UK, the CCPA in California, and as otherwise provided by applicable law. Contact us; we respond within thirty days. Developers may request account deletion the same way, and it is completed within thirty days.
Changes
When this policy changes, the date at the top is updated. We will email account holders about any change that affects what we collect or how we use it.
Terms of service · Privacy policy · Data processing terms · Contact