PRIVACY / LAST UPDATED: DEC 19, 2025

Privacy Policy

Effective Date: December 19, 2025

🔒 Privacy-First Commitment

BackNova is built on privacy-first principles. We do NOT store plain text email addresses or phone numbers. All personally identifiable information (PII) is hashed using SHA-256 before storage. We believe in transparent data practices and your right to privacy.

1. Introduction

This Privacy Policy explains how BackNova ("we," "us," or "our") collects, uses, discloses, and protects information when you use our services, website, and software (collectively, the "Service").

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

2.2 End-User Tracking Data

When your website visitors interact with BackNova's tracking SDK, we collect:

Data Type What We Collect How It's Stored
Email Email from forms SHA-256 hash only
Phone Phone from forms SHA-256 hash only
Browser Fingerprint User agent, screen, timezone, language Composite SHA-256 hash
Session ID Random session identifier Plain text (non-PII)
Page Info URL, referrer, title Plain text (non-PII)
UTM Parameters Source, medium, campaign, etc. Plain text (non-PII)
Technical Data User agent, viewport, timezone Plain text (non-PII)

2.3 Payment Information

We use Stripe for payment processing. We DO NOT store your credit card information. Stripe stores payment details securely according to PCI DSS standards. We receive only:

3. How We Use Your Information

3.1 To Provide the Service

3.2 To Improve the Service

3.3 To Communicate

4. Privacy-First Architecture

🔐 Zero Plain Text PII Storage

BackNova implements industry-leading privacy protections through client-side hashing, one-way encryption, no plain text storage, minimal data collection, and anonymous fingerprinting.

4.1 Email Hashing Process

When a user submits "user@example.com":

1. Email normalized in browser: "user@example.com" 2. SHA-256 hash calculated: "b4c9a289323b21a01c3c..." 3. Only hash sent to servers 4. Original email never leaves browser 5. We store: "fingerprint_email: b4c9a289..."

5. Data Sharing and Disclosure

5.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.2 Service Providers

We share data with trusted service providers:

5.3 Legal Requirements

We may disclose information if required by law, court orders, subpoenas, law enforcement requests, or to protect our rights.

6. Your Privacy Rights

6.1 GDPR Rights (EU Users)

6.2 CCPA Rights (California Users)

6.3 Exercising Your Rights

Contact us on Telegram with subject "Privacy Rights Request". We will respond within 30 days.

7. Data Retention

7.1 Active Accounts

We retain your data while your account is active and as necessary to provide the Service.

7.2 Deleted Accounts

When you delete your account, your personal data is deleted within 30 days, hashed identifiers are removed, and backup copies are overwritten within 90 days.

8. Data Security

8.1 Security Measures

8.2 Data Breach Notification

In the event of a breach, we will notify affected users within 72 hours, notify authorities as required, provide details about the breach, and offer assistance.

9. Cookies and Tracking

9.1 Cookies We Use

9.2 No Third-Party Tracking

We do NOT use Google Analytics, Facebook Pixel, third-party advertising cookies, or marketing cookies.

9.3 Do Not Track

We respect browser "Do Not Track" signals.

10. International Data Transfers

BackNova uses Cloudflare's global network. All transfers comply with GDPR requirements through Standard Contractual Clauses (SCCs).

11. Children's Privacy

BackNova is a B2B service not intended for children. We do not knowingly collect information from individuals under 18 years of age.

12. Changes to This Policy

We may update this Privacy Policy. When we make material changes, we will update the date, notify you via email, post a notice in the Service, and request consent if required by law.

13. Your Responsibilities

When using BackNova, you must provide clear privacy notices to your users, obtain proper consent, comply with GDPR/CCPA, honor opt-out requests, and use data for legitimate purposes only.

14. Contact Us

Privacy Questions?

If you have questions about this Privacy Policy or our data practices:

Telegram: @BackNova
Website: https://backnova.xyz

For GDPR/CCPA requests, message us on Telegram with subject "Privacy Rights Request". We will respond within 30 days.

Thank You

Thank you for trusting BackNova with your data. We are committed to protecting your privacy and maintaining transparent data practices.