Privacy Policy



Privacy Policy
Effective Date: 1 August 2025  Last Updated: 17 November 2025
Backkr ("we," "our," or "us") is committed to protecting your privacy and handling your personal information responsibly.
This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our marketing analytics platform.

1. Information We Collect
We may collect the following personal and business information:
Personal and Contact Information
  Your name, email address, and any other contact details you provide  
Authentication information managed through our third-party authentication service provider

Account Information
  Login credentials, subscription details, and account preferences  
Authentication tokens stored in secure, http Only cookies
Business Information
  Company name, website URL, and business details you choose to share  
Industry type, products and services offered, and marketing goals   Business tone and messaging preferences from your onboarding responses

Technical Data
  IP address for region detection and pricing localization  
Browser cookies (authentication and session management)  
Browser local storage for preserving signup progress  
Device type, browser type, and operating system information

Communication Data
  Records of your interactions with our platform and support team
Google Analytics and Google Search Console Data
When you connect your accounts, we collect data via the Google Analytics and Google Search Console APIs, including:
Core Metrics: Active users, sessions, page views, conversions, transactions, and revenue
Engagement Metrics: Session duration, bounce rate, engaged sessions, event counts
Detailed Analytics: Geographic location (country/region), traffic sources, campaigns, devices, browser/OS preferences, landing pages, page paths, content engagement
E-commerce Data: Purchases, categories, items, and transaction details
Demographics & Ads Data: Age ranges, gender, and keyword queries (where available)
Temporal Patterns: Usage by time of day and day of week

Website Content
To understand your brand and context, we analyze publicly available content from your website, including:
  Page text, meta descriptions, and titles  
Page structure and calls-to-action  
Forms and conversion elements
We only analyze publicly available information accessible to any internet user.

2. How We Use Your Information
Our primary purpose is to generate personalized marketing strategies and insights.
Specifically, we use your information to:
  Analyze your Google Analytics data to identify patterns and opportunities  
Generate customized strategy recommendations in your Backkr dashboard  
Produce reports and performance visualizations  
Suggest marketing content and SEO improvements based on website analysis  
Process payments and manage subscriptions   Authenticate your account and maintain secure access  
Detect your geographic region for appropriate pricing  
Send service-related communications and support responses
To create marketing content and SEO recommendations:
  Backkr scans your public-facing website to understand your brand  
This information, along with any content you choose to type in, may be sent to third-party AI tools to help generate relevant content  
The data shared includes information you provide and publicly available website content

3. AI-Powered Insights
We use third-party AI services to generate marketing recommendations and content.

What Data is Shared with AI Services:
  Aggregated Google Analytics metrics and behavioral patterns (user counts, session metrics, conversion rates, engagement data)  
Your website URL, business name, and industry - These are shared to provide context for personalized recommendations  
Publicly scraped website content including page text, headings, and calls-to-action  
Geographic data at country/region level (not individual user addresses)  
Business information you provide during onboarding (products, services, goals, tone preferences)

Important Clarifications:
  Individual user-level session data (specific visitor identities) is NOT shared  
Your website URL and business name ARE shared with AI services as necessary context  
Only aggregated, summarized analytics data is processed by AI tools  
Raw Google Analytics API responses are never directly transmitted to AI services

AI Data Handling
  No training use: Third-party AI services claim to not use your data to train their models  
Data deletion: AI services delete processed data within 30 days per their policies  
No direct raw data transfers: Original Google Analytics data never leaves our secure systems without aggregation

4. Data Sharing
We do not sell, rent, or trade your personal information.
Data is shared only in the following limited cases:

With Trusted Service Providers:
We work with carefully selected third-party service providers to deliver our services:
  Authentication Services: For secure user login and account management  
Payment Processors: For subscription billing and payment handling  
AI Services: For generating marketing insights and content recommendations  
Email Services: For transactional emails and marketing communications (if you opt in)  
Cloud Hosting and Infrastructure: For secure data storage and platform operations  

Analytics API Providers (Google): For accessing your Google Analytics and Search Console data
These service providers are contractually obligated to protect your data and use it only for the purposes we specify.
When Required by Law: To comply with legal obligations, protect rights and safety, or respond to valid legal requests
Google API Services Compliance
Backkr's use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically regarding Google data:
  Access tokens are stored securely with encryption and refreshed automatically  
OAuth refresh tokens are stored in our database and expire after 30 days maximum  
Google data is only accessed when you actively use our service  
You can revoke Backkr's access at any time through your [Google Account settings](https://myaccount.google.com/permissions) or your Backkr dashboard

5. Data Retention and Deletion
Google Analytics data: Retained for up to 3 years to enable historical trend analysis
User account data: Retained until account deletion or 2 years of continuous inactivity
AI-generated insights: Retained for 12 months
Website content analysis: Retained for 6 months or until updated
Authentication tokens: OAuth tokens expire and are automatically deleted after 30 days
Retention Enforcement: Retention periods are enforced through periodic automated data purges and manual reviews.

Deletion Rights
  You may request deletion at any time through your account settings or by contacting us   Upon account deletion, all associated data is permanently deleted within 30 days   Consent for AI processing can be withdrawn at any time (though previously processed data cannot be reversed)   You can disconnect Google Analytics and Google Search Console accounts at any time

6. Data Security
While no system can be guaranteed to be completely secure, Backkr is committed to maintaining industry best practices to protect your information.
Safeguards in Place
Access Controls: Only authorized staff have access to personal information, protected by role-based permissions and multi-factor authentication
Data Minimization & Retention: We only collect the information necessary to deliver our services, and securely delete or anonymize data once no longer required
Monitoring & Auditing: Our systems are regularly reviewed to identify vulnerabilities and prevent unauthorized access or misuse
Secure Infrastructure: We use trusted hosting and storage providers that comply with international standards (ISO 27001, SOC 2)
Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest where applicable
Incident Response: In the event of a suspected data breach, we promptly investigate, mitigate risks, and notify affected users and regulators as legally required

Cookies
We use the following cookies:
Authentication cookies (httpOnly, secure): For maintaining your login session and security
OAuth tokens (httpOnly, secure): For Google Analytics API access (expires in 30 days maximum)
Session data: For preserving your signup progress and user preferences
You can control cookies through your browser settings, but disabling them will prevent you from using core features of our service.

7. Your Rights
You have the right to:
  Access the personal information we hold about you  
Request corrections or updates to your information  
Request deletion or data portability  
Withdraw consent for AI processing  
Object to processing of your data  
Lodge a complaint with a supervisory authority

Account Management
  Update account details in your Backkr dashboard  
Disconnect Google Analytics and Google Search Console accounts at any time  
Revoke Google access through your Google Account permissions  
Cancel your account (triggers full data deletion within 30 days)

8. Legal Basis for Processing
By creating an account and connecting your Google Analytics, you agree that:
  Backkr may access and process your Google Analytics and Google Search Console data  
Aggregated analytics data, along with your website URL and business context, may be shared with AI services for strategy generation   Publicly available website content will be analyzed to provide recommendations  
Your data will be handled according to this Privacy Policy
You maintain the right to disconnect your accounts and request data deletion  at any time through your dashboard or by contacting [team@backkr.com](mailto:team@backkr.com)

9. International Data Transfers
Your data may be processed and stored outside your country of residence.
When we transfer data internationally, we use appropriate safeguards such as:
  Standard contractual clauses approved by relevant authorities  
Ensuring third-party processors maintain adequate data protection standards  
Compliance with applicable data protection frameworks (GDPR, CCPA, etc.)

10. Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements.
  The "Last Updated" date will always reflect the current version  
Material changes will be communicated through our platform, email, or prominent notice  
Continued use of our services after changes indicates acceptance of the updated policy  
For significant changes, we may require renewed consent

11. Additional Disclosures
Children's Privacy
Our services are not intended for individuals under 18. We do not knowingly collect data from children.
If we become aware that we have collected data from a child, we will delete it promptly.

Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. The new entity will be bound by the same privacy protections, and you will be notified of any such transfer.

Legal Disclaimer
While we apply industry-standard security measures, no system is 100% secure. By using Backkr, you acknowledge and accept this inherent risk. We will notify you promptly of any data breaches as required by law.

Data Processing
For users in the European Economic Area (EEA), UK, or Switzerland: Backkr acts as a data controller for your account information and a data processor for your Google Analytics data.
You (the account holder) remain the data controller for your Google Analytics data.

12. Contact Us
For questions, requests, concerns, or to exercise your data rights, please contact:
Email: [team@backkr.com](mailto:team@backkr.com)  
Phone: +64 27 766 4199  
Address: Ministry of Awesome, Christchurch, New Zealand
For Data Subject Requests:  Please include "Privacy Request" in your email subject line and provide:
  Your full name and account email


Let’s connect 🔗

Thanks! We’ll reach out soon.
Whoops! Something went wrong.