BackNova is built on privacy-first principles. Lead data (name, email, phone) is routed directly to your PP/broker — we do not store it. For AI learning, we only store SHA-256 hashes of email and IP, plus email domain and GEO (country). Your tracker's sub IDs stay private — we only use click_id for postback matching.
This Privacy Policy explains how BackNova ("we," "us," or "our") collects, uses, discloses, and protects information when you use our services, website, and software (collectively, the "Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
When you create an account, we collect:
When your website visitors interact with BackNova's tracking SDK, we collect:
| Data Type | What We Collect | How It's Stored |
|---|---|---|
| Email from forms | SHA-256 hash + domain only (raw email goes directly to your PP) | |
| Phone | Phone from forms | Not stored (goes directly to your PP) |
| Name | Name from forms | Not stored (goes directly to your PP) |
| IP Address | Visitor IP | SHA-256 hash only + GEO (country code) |
| Click ID | Tracker click ID from URL | Plain text (for postback matching) |
| Browser Fingerprint | User agent, screen, timezone, language | Composite SHA-256 hash |
| Session ID | Random session identifier | Plain text (non-PII) |
| Page Info | URL, referrer, title | Plain text (non-PII) |
| UTM Parameters | Source, medium, campaign, etc. | Plain text (non-PII) |
| Behavioral Data | Time on site, scroll, clicks, etc. | Plain text (non-PII) |
We use Stripe for payment processing. We DO NOT store your credit card information. Stripe stores payment details securely according to PCI DSS standards. We receive only:
Lead data (name, email, phone) goes directly to your PP via the route URL you configured. BackNova never stores this raw data. We only store hashes for AI learning.
When a user submits a lead form:
We only capture click_id from your tracker URL for postback matching. Your sub IDs, pub IDs and other tracking parameters stay in your tracker — we don't see or store them.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We share data with trusted service providers:
We may disclose information if required by law, court orders, subpoenas, law enforcement requests, or to protect our rights.
Contact us on Telegram with subject "Privacy Rights Request". We will respond within 30 days.
We retain your data while your account is active and as necessary to provide the Service.
When you delete your account, your personal data is deleted within 30 days, hashed identifiers are removed, and backup copies are overwritten within 90 days.
In the event of a breach, we will notify affected users within 72 hours, notify authorities as required, provide details about the breach, and offer assistance.
We do NOT use Google Analytics, Facebook Pixel, third-party advertising cookies, or marketing cookies.
We respect browser "Do Not Track" signals.
BackNova uses Cloudflare's global network. All transfers comply with GDPR requirements through Standard Contractual Clauses (SCCs).
BackNova is a B2B service not intended for children. We do not knowingly collect information from individuals under 18 years of age.
We may update this Privacy Policy. When we make material changes, we will update the date, notify you via email, post a notice in the Service, and request consent if required by law.
When using BackNova, you must provide clear privacy notices to your users, obtain proper consent, comply with GDPR/CCPA, honor opt-out requests, and use data for legitimate purposes only.
If you have questions about this Privacy Policy or our data practices:
Telegram: @BackNova
Website: https://backnova.xyz
For GDPR/CCPA requests, message us on Telegram with subject "Privacy Rights Request". We will respond within 30 days.
Thank you for trusting BackNova with your data. We are committed to protecting your privacy and maintaining transparent data practices.