Privacy Policy
How Backkr collects, uses, stores, and safeguards your information.
Effective Date: 16 August 2026 · Last Updated: 18 August 2026
Backkr Limited ("Backkr", "we", "us", or "our") is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our AI-powered marketing analytics platform and website at backkr.com (collectively, the "Services"). It also describes your rights and how to exercise them.
By accessing or using our Services, you agree to the practices described in this policy. If you do not agree, please do not use our Services.
Who We Are
Backkr Limited is a company incorporated in New Zealand. We provide an AI-powered marketing analytics SaaS platform that connects to third-party data sources (including Google Analytics 4, Google Search Console, and Meta) to generate plain-English customer insights, audience personas, and growth playbooks for small service businesses.
- Backkr Limited
- Ministry of Awesome, Christchurch, New Zealand
- Email: team@backkr.com
- Phone: +64 27 766 4199
- Website: backkr.com
Scope of This Policy
This policy applies to:
- All visitors to backkr.com
- Trial and paying subscribers to the Backkr platform
- Data processed by Backkr on behalf of our customers through connected integrations (Google Analytics 4, Google Search Console, Meta, LinkedIn, TikTok)
- Users accessing Backkr through our reseller and agency partners
This policy does not apply to third-party platforms and services (such as Meta, Google, LinkedIn, or TikTok) whose own privacy policies govern their data practices. We encourage you to review those policies directly. This policy also does not apply to any third-party websites linked from our Services.
Data We Collect
1. Information You Provide
When you register, subscribe, or contact us, we collect:
- Name and email address
- Business name, website URL, industry type, products and services offered, and marketing goals
- Business tone and messaging preferences from your onboarding responses
- Billing information (processed securely through Stripe; we do not store full card details)
- Communications and support requests you send to us
2. Authentication & Session Data
We collect and store:
- Authentication tokens stored in secure, httpOnly cookies
- OAuth refresh tokens (expire after 30 days maximum)
- Browser local storage data for preserving signup progress and account preferences
- Login credentials managed through our third-party authentication service provider, Clerk
3. Google Analytics 4 and Google Search Console Data
When you authorise Backkr to access your Google Analytics 4 and Google Search Console accounts, we receive and process aggregated data via official Google APIs. This includes core metrics, engagement data, detailed analytics, e-commerce data, demographics, and temporal patterns.
We do not receive individually identifiable visitor data from GA4. Data is aggregated and processed in accordance with Google's data policies and the Google API Services User Data Policy.
4. Meta (Facebook & Instagram) Marketing API Data
When you authorise Backkr to access your Meta ad account, we receive and process data via Meta's Marketing API, including ad account performance, audience insights, campaign metrics, and organic page analytics.
We access only data for which you have granted Backkr explicit permission through Meta's OAuth flow. Backkr does not access your personal Facebook or Instagram profile, personal messages, or individual user-level customer data.
5. Meta Pixel and Retargeting Disclosure
IMPORTANT: If you use Meta Pixel on your website (to track your own customers), that data is collected and processed directly by Meta under Meta's privacy policy. Backkr does not have access to Meta Pixel data and does not use it for training, retargeting, or audience building.
Backkr's access to Meta Marketing API data (your ad account performance) is separate from and independent of Meta Pixel. For more information about Meta Pixel, see Meta's privacy policy at https://www.facebook.com/privacy/explanation.
6. LinkedIn and TikTok Data
We may access sponsored content and campaign performance data from LinkedIn and TikTok only with your explicit authorisation. This data is accessed only to generate insights within your Backkr account.
7. Website Content Analysis
To understand your brand and generate relevant recommendations, we analyse publicly available content from your website (page text, titles, calls-to-action, forms) and your connected social media. We do not analyse or store content from websites you do not own or have not authorised us to analyse.
8. Website Visitor Data (backkr.com)
Backkr uses Google Analytics 4 to track visits to backkr.com. GA4 tracking is conditional on your acceptance of non-essential cookies via our cookie consent banner. If you do not accept non-essential cookies, no data will be collected. You can withdraw cookie consent at any time.
Backkr respects the Global Privacy Control (GPC) signal and disables tracking for users who have enabled GPC in their browser.
9. Automatically Collected Data
When you visit our website, we automatically collect:
- IP address (for region detection and pricing localisation)
- Browser type, operating system, and device information
- Pages visited, time spent, and clickstream data
- Referral source and UTM parameters
- Session and cookie identifiers
10. Retargeting Technologies
We use Meta Pixel and Microsoft Clarity on our website for retargeting purposes. These technologies help us understand how users interact with our website and deliver more relevant advertisements to you on other platforms. Your use of these technologies is subject to your cookie consent preferences.
How We Use Your Data
We use the data we collect for the following purposes:
- Provide, operate, and improve the Backkr platform and Services
- Analyse your GA4, GSC, Meta, LinkedIn, and TikTok data to identify patterns and opportunities
- Generate AI-powered insights, audience personas, and growth playbooks
- Authenticate your account and maintain security
- Detect your geographic region for appropriate pricing
- Process billing and manage your subscription
- Send transactional emails (onboarding, alerts, account notifications)
- Send product updates (all users; can be disabled in account settings)
- Send marketing and promotional content (only to users who opt-in; always includes unsubscribe link)
- Respond to support requests and customer enquiries
- Comply with legal obligations and enforce our Terms of Service
- Detect and prevent fraud, abuse, and security incidents
Email Communications
Backkr sends three categories of emails:
1. Transactional Emails
Account confirmations, password resets, billing notifications, and service alerts are sent to all users regardless of preference. These are essential for account security and cannot be unsubscribed.
2. Product Updates and Announcements
Feature announcements and product updates are sent to all users. You can disable these emails in your account settings at any time. Disabling does not affect transactional emails.
3. Marketing and Promotional Emails
Marketing emails are sent only to users who explicitly opt-in during signup or via account settings. Every marketing email includes a one-click unsubscribe link. Unsubscribing is effective immediately.
Google API Services Compliance
Backkr's use and transfer of information received from Google APIs strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements:
1. Limited Use of Google Data
Backkr uses Google user data only to provide analytics insights within your Backkr account. We do not:
- Use Google data for advertising, marketing profiling, or targeting
- Transfer Google data to third parties for any purpose
- Combine Google data with other advertising data for purposes other than analytics
- Use Google data to train third-party, general-purpose AI models
When logging into the Backkr app using your Google email address, Google Analytics is required for the core functionality of our service, and you cannot opt out of your anonymised data being processed by our AI for generating insights. This processing is essential for providing the AI-powered analytics platform.
2. Data Security for Google Data
We implement the following security measures for Google data:
- Encryption in transit: TLS/HTTPS
- Encryption at rest: AES-256
- Access controls: only authorised Backkr personnel can access production data
- Secure storage of OAuth tokens: httpOnly, secure cookies with automatic expiry
- No caching of raw Google API responses in unsecured storage
3. Data Retention for Google Data
Google Analytics and Search Console data is retained for up to 3 years. After 3 years, data is permanently deleted from active systems.
4. User Access and Revocation
You may revoke Backkr's access to your Google account at any time by visiting myaccount.google.com/permissions, finding "Backkr", and selecting remove. Revocation is effective immediately.
Meta Platform Policy Compliance
Backkr's use of Meta's Marketing API strictly adheres to Meta's Platform Policy:
1. Permitted and Prohibited Uses
We use Meta data only to: generate analytics and insights; create personalised recommendations; understand audience demographics and engagement.
We do NOT use Meta data to: retarget audiences; create lookalike audiences; build marketing databases; make advertising decisions on your behalf; share or sell data to third parties.
2. Data Security for Meta Data
- Encryption in transit: TLS/HTTPS
- Encryption at rest: AES-256
- Access controls: only authorised personnel
- Secure storage of access tokens: encrypted httpOnly cookies
3. Data Retention for Meta Data
Meta ad account data is retained for up to 2 years. After 2 years, data is aggregated or deleted.
4. User Access and Revocation
You may revoke Backkr's access to your Meta ad account anytime via Meta Business Manager. Revocation is effective immediately.
AI-Powered Insights and Data Processing
1. Data Anonymisation Before LLM
Before any data is sent to large language models (LLMs), Backkr anonymises and aggregates it. The specific method of anonymisation is proprietary to Backkr and is not disclosed, as it is part of our competitive advantage and trade secret.
Customers can be assured that: (1) individual user-level data is not transmitted to LLMs; (2) only aggregated, de-identified metrics are processed; (3) raw API responses from Google, Meta, or other platforms are never sent directly to LLMs.
2. AI Providers and Data Handling
Backkr uses OpenAI and Grok (xAI) to generate insights and recommendations. These services process only anonymised, aggregated data and are contractually prohibited from training their general-purpose models on Backkr customer data. Processed data is deleted by these services within 30 days.
3. Proprietary Model Training
Backkr trains its own proprietary in-house model using anonymised, aggregated data — including anonymised Google Analytics data — to reduce dependence on external LLM providers over time. This training data is anonymised using the same process described in Section 8.1 above; no individually identifiable data is used, and raw API responses are never used for training.
4. Persona and Recommendation Explainability
Backkr's personas and recommendations are generated by AI models and are provided for informational purposes. The step-by-step reasoning behind specific recommendations is not disclosed (LLMs are generally not explainable in this way). Recommendations should be treated as starting points for further testing and refinement, not as ground truth.
5. Potential Bias
Backkr uses machine learning models to generate insights. Users should be aware of potential limitations:
- Input data bias: If your GA4 or ad data reflects skewed audience demographics, generated personas may amplify that bias
- LLM bias: Large language models may reflect biases in their training data, including stereotypes or demographic assumptions
- Incomplete information: Personas are generated from analytics data only and do not reflect qualitative customer research, surveys, or actual customer interviews
- Lack of validation: Recommendations are not tested or validated before presentation. Users should A/B test in live campaigns
Backkr recommends treating generated personas and recommendations as hypotheses for testing, not as validated insights. Always validate with real customer research and live campaign performance.
Legal Bases for Processing
We process your personal data on the following legal bases:
- Contract performance: to deliver the Services you have subscribed to
- Legitimate interests: to improve our Services, ensure security, and conduct analytics
- Consent: for marketing communications, non-essential cookies, and AI training questions
- Legal obligation: where required by law
No Automated Decision-Making
Backkr does not engage in automated decision-making that produces legal or similarly significant effects concerning our customers. Any decisions related to costs, advertising campaigns, or content generation will always require explicit approval and input from the customer before being implemented or going live. Our AI provides recommendations and insights, but the final decision-making authority rests with the user.
For UK/EEA users, processing is governed by the UK GDPR. For Australian users, by the Privacy Act 1988. For New Zealand users, by the Privacy Act 2020.
Data Sharing and Disclosure
We do not sell your personal data. We may share data in the following circumstances:
1. Service Providers and Sub-Processors
We engage trusted third-party service providers:
- Vercel (application hosting, SOC 2 Type II)
- AWS (cloud infrastructure and database, SOC 2 Type II)
- Clerk (authentication, SOC 2 Type II)
- Stripe (payments, SOC 2 Type II)
- Neon (PostgreSQL hosting, SOC 2 Type II)
- Sentry (application monitoring)
- OpenAI and Grok (xAI) (AI services)
A complete, current list of sub-processors is available on request. Email hello@backkr.com to request the current sub-processor list.
2. Third-Party Platform APIs
To deliver our Services, we transmit your OAuth tokens and API queries to Google, Meta, LinkedIn, and TikTok. These platforms process data under their own privacy policies.
3. Legal Requirements
We may disclose data if required by law, court order, or government authority, or if necessary to protect the rights or safety of Backkr or our users. Where legally permitted, we will notify you before disclosure.
International Data Transfers
Backkr is based in New Zealand. Some auxiliary services that the main application relies on are hosted in AWS ap-southeast-2 (Sydney). Data transfers are protected by Standard Contractual Clauses (SCCs) for UK/EEA users and contractual data protection obligations with all processors.
Data Retention
We retain your data as long as your account is active or as needed to provide the Services. Specific periods are:
- Google Analytics and Search Console data: up to 3 years
- Meta ad account data: up to 2 years
- AI-generated insights and outputs: 12 months
- Website content analysis: 6 months
- User account and business profile: until account deletion or 2 years of inactivity
- Billing and account data: 7 years post-closure for legal/tax compliance
- Support communications: 2 years
- Authentication tokens: expire after 30 days
- Website analytics: per GA4 retention settings (default 14 months)
You may request data deletion anytime by emailing team@backkr.com. Upon account deletion, personal data is permanently deleted within 30 days. Backups may retain data for up to 90 days before permanent deletion.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, secure transport, encryption for selected sensitive integration credentials, and logging of selected security and account events.
We review and improve these safeguards as the service evolves. However, no method of transmission or storage is completely secure.
Backkr implements appropriate security measures:
- Development and production environments are strictly separated; only authorised personnel can access production systems
- Encryption of data in transit: TLS/HTTPS
- Encryption of data at rest: AES-256
- All API credentials, database passwords, and secrets are encrypted in transit and at rest
- Access controls: role-based, with multi-factor authentication where applicable
- All infrastructure providers (AWS, Vercel, Neon, Clerk, Stripe) maintain SOC 2 Type II certifications
- Application monitoring via Sentry
- Cyber liability insurance
We will notify affected customers within 72 hours of confirming a breach that impacts your data.
Your Privacy Rights
New Zealand (Privacy Act 2020)
- Right to access your personal information
- Right to correct inaccurate information
- Right to complain to the Privacy Commissioner at privacy.org.nz
Australia (Privacy Act 1988)
- Right to access and correct personal information
- Right to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
United Kingdom & EEA (UK GDPR / GDPR)
- Right of access (Subject Access Request)
- Right to rectification
- Right to erasure (deletion)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any rights, email hello@backkr.com. We will respond within 30 days (or within timeframes required by law).
Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information as quickly as possible. If you believe that we might have any information from or about a child under 18, please contact us at hello@backkr.com.
Continuity and Data Export
If Backkr Limited ceases to operate the Service, we will: (1) Provide 30 days' notice in writing; (2) Allow you to export your data (reports, personas, insights) in standard formats (PDF/CSV); (3) Permanently delete all customer data after 30 days.
Data processing agreements (DPAs) are available on request. Email hello@backkr.com to request a DPA for your jurisdiction.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email. Continued use constitutes acceptance of updates.
Contact Us
If you have questions about this Privacy Policy or our data practices:
- Backkr Limited
- Ministry of Awesome, Christchurch, New Zealand
- Email: hello@backkr.com
- Phone: +64 27 766 4199
- Website: backkr.com
© 2026 Backkr Limited. All rights reserved. Last reviewed 18 August 2026.

