Privacy Policy

Last updated: March 31, 2026

1. What Data We Collect

Account information: When you create an account via Clerk, we store your user ID and authentication metadata. We do not store passwords — authentication is handled entirely by Clerk.

Uploaded files: CSV files you upload for processing are temporarily stored to generate results. Files are encrypted at rest and automatically deleted after your configured retention period.

Usage data: We log script runs (script type, row count, timestamps) for billing and audit purposes. We also maintain an audit log of account actions for security compliance.

2. How We Use Your Data

  • To process your CSV files using the scripts you select
  • To store results temporarily for download
  • To track credit usage and billing
  • To maintain audit logs for security and compliance
  • To improve service reliability (aggregate, anonymized metrics only)

3. Third-Party Processing

We use the following third-party services to operate BackOffice Scripts:

  • OpenAI API — Processes name/entity classification requests. Per OpenAI's API data usage policy, API inputs and outputs are not used for model training.
  • Supabase — Database and file storage (SOC 2 Type II certified).
  • Vercel — Application hosting (SOC 2 Type II certified).
  • Clerk — Authentication and user management.
  • Stripe — Payment processing. We never store credit card information on our servers.

4. Data Retention

Processed result files are retained for your chosen retention period (1, 7, or 30 days), after which they are automatically and permanently deleted. You can delete all your data immediately at any time from your Settings page.

Account metadata, usage records, and audit logs are retained for the lifetime of your account. Upon account deletion request, all data is purged within 30 days.

5. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — Request a copy of your data
  • Deletion — Request deletion of your data (available self-service in Settings)
  • Portability — Export your data in standard formats
  • Correction — Request correction of inaccurate data
  • Opt-out — We do not sell personal information

6. CCPA Disclosure

If you are a California resident, you have the right to know what personal information we collect, to delete your personal information, and to opt-out of the sale of your personal information. We do not sell personal information. To exercise your rights, use the self-service controls in Settings or contact us at support@backofficescripts.com.

7. GDPR Disclosure

If you are in the European Economic Area, our legal basis for processing is contract performance (providing the service you signed up for) and legitimate interest (security and fraud prevention). You may exercise your rights under GDPR by contacting us at support@backofficescripts.com.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact

For privacy-related inquiries, contact us at support@backofficescripts.com.