Who controls your data
The data controller for Backly is Ivan Bottigelli, Via Casteggio, 5/A, 21052 Busto Arsizio, Italy.
Backly acts as the data controller for account information, service usage data, and communications that are necessary to operate the platform.
For privacy requests, complaints, or questions about this policy, contact support@getbackly.app or testbottyivan@gmail.com.
What data we collect
We collect the information you provide directly, including email address, authentication identifiers, profile details, and data you submit while creating or managing subscription groups across the web and mobile applications.
- Account and profile data such as email address, Supabase authentication identifier, display name, avatar URL, and similar profile preferences you choose to provide.
- Subscription workspace data such as service names, member assignments, billing metadata, and operational notes.
- Technical data such as IP address, device information, app version, request logs, and security events.
- Mobile application data such as push-notification token or equivalent device messaging identifier if mobile notifications are enabled.
- Support and contact data when you email us or request assistance.
Why we use personal data
We use personal data only where we have a valid legal basis, including performance of a contract, compliance with legal obligations, legitimate interests in keeping the service secure, and consent where required.
- To create and maintain user accounts and authenticate sessions.
- To provide collaborative subscription management features.
- To prevent fraud, abuse, unauthorized access, and platform misuse.
- To respond to support requests and operational notices.
- To comply with tax, accounting, or lawful disclosure obligations when applicable.
Children and minors
Backly is not intended for children who are not legally able to use the service under the Terms of Service. As stated in the Terms, users must be at least 18 years old, or the age of legal majority in their jurisdiction if higher, unless use is permitted with the involvement and authorization of a parent or legal guardian under applicable law.
We do not knowingly seek to collect personal data from children in violation of applicable law. If you believe that a child has provided personal data to Backly without proper authorization, contact support@getbackly.app or testbottyivan@gmail.com so that we can review the case and take appropriate action.
How long we keep data
We keep personal data only for as long as needed to provide the service, resolve disputes, enforce agreements, and comply with legal obligations.
Account, profile, and subscription-management data are generally retained for as long as your account remains active. Data linked to shared subscriptions may also remain until the relevant subscription is removed or changed by the owner or another authorized user acting within the service.
When an account is deleted, we aim to remove the application profile and related membership or ownership records from our primary application database, and we separately delete the corresponding authentication account from Supabase Auth. Limited residual records may remain temporarily in infrastructure logs, backups, or security systems for a restricted period where required for resilience, fraud prevention, incident investigation, or legal compliance.
Account deletion and data erasure
If you request account deletion through the service, Backly initiates deletion of the user record and associated relational data stored in the application database, including records that depend on your user profile through configured cascade deletion rules.
The service also deletes the corresponding authentication account in Supabase Auth so that you can no longer sign in with that account. If deletion cannot be completed immediately because of a technical failure or a legal retention requirement, we may retain only the minimum data necessary until the issue is resolved or the retention obligation expires.
Sharing and processors
We may share data with processors that help us run the service, including Google Firebase and Google Cloud for application hosting and related infrastructure, and Supabase for authentication and PostgreSQL database infrastructure. These providers process personal data on our behalf to host the service, secure access, store account and subscription data, and maintain operational availability.
Where mobile notifications are enabled, Google services may also be involved in delivering push notifications to Android devices and, depending on implementation, to other supported mobile platforms through notification infrastructure.
We may also use additional providers for support, email, monitoring, and security operations. Those providers may process data only under appropriate contractual and security controls.
We do not sell personal data. We may disclose data if required by law or when necessary to protect rights, security, or platform integrity.
Data location and international transfers
Backly is designed to operate with infrastructure located in the European Union or European Economic Area. Based on the current configuration, hosting and database services are intended to run in EU-based environments.
If personal data is nevertheless transferred outside your jurisdiction or outside the EU or EEA, we rely on appropriate safeguards such as standard contractual clauses or equivalent legal mechanisms where required.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or export your personal data, and to withdraw consent where processing depends on consent.
You may also have the right to lodge a complaint with a supervisory authority. To exercise your rights, contact support@getbackly.app or testbottyivan@gmail.com.
Security
We use reasonable technical and organizational measures to protect data against unauthorized access, disclosure, alteration, and loss. No system is completely secure, so you should also protect your credentials and notify us if you suspect misuse.
Policy updates
We may update this policy from time to time. Material changes will be reflected by updating the effective date and, where appropriate, by providing additional notice inside the service or by email.