Privacy Policy
Effective date: 3 October 2026
This policy explains what personal data BackupLatte collects about its customers and website visitors, why, and what rights you have.
1. Who we are
The controller of the personal data described here is Stanislav Sysoiev, sole trader (CEIDG), ul. Lwowska 6G/25, 61-131 Poznań, Poland, NIP 7822934324, REGON 527330815, operating BackupLatte ("BackupLatte", "we"). Contact for any privacy matter: [email protected].
For the contents of Linear workspaces that customers back up with BackupLatte, the customer is the controller and we are its processor. That processing is governed by our Data Processing Addendum; see section 9 if your data is in someone else's workspace.
2. What we collect, where it comes from and why
| Data | Source | Why | Legal basis (GDPR) |
|---|---|---|---|
| Account: email, password (stored only as a bcrypt hash), sign-in refresh token (our database keeps only its hash), last login time | You | Create and secure your account, sign you in | Contract (Art. 6(1)(b)) |
| Linear connection: your Linear user ID, organisation ID, name and key, OAuth access and refresh tokens (encrypted with AES-256-GCM), backup schedule and retention settings | Linear, when you connect | Connect to Linear and run the backups and restores you ask for | Contract |
| Backup and restore records: time, status, size, item counts, error messages | Generated by the Service | Show your backup history, troubleshoot failures | Contract; legitimate interest in a reliable service (Art. 6(1)(f)) |
| Subscription: Paddle customer and subscription IDs, plan, status, billing dates, number of active users in your connected workspaces (counted via Linear) | Paddle; Linear | Enforce your plan and limits | Contract |
| Payment event records: Paddle event, transaction, subscription and customer IDs, event type and status | Paddle | Process and audit billing events | Contract; legitimate interest |
| Job diagnostics: for failed backup/restore jobs, the workspace, backup and restore IDs and the error message | Generated by the Service | Investigate and retry failures | Legitimate interest |
| Technical logs: IP address, request path, timestamps, error details | Your browser / our servers | Security, abuse prevention (rate limiting), debugging | Legitimate interest |
| Website analytics (landing page and blog, only if you agree): pages viewed, referrer, device and browser type, country and region, Google Analytics cookie identifiers | Your browser, through Google Analytics | Learn which pages help visitors, improve the site | Consent (Art. 6(1)(a)); you can withdraw it any time |
| Emails we send you: backup alerts (a backup failed or has gaps, or works again), with the workspace name and the reason | Generated by the Service | Tell you when your backups need attention; you can turn them off per workspace | Contract |
| Emails you send us | You | Answer support and legal requests | Contract / legitimate interest |
An email address and password are required to have an account, and a Linear connection is required to make backups; without them we cannot provide the Service.
Payments. Paddle is our Merchant of Record and collects your name, address, payment details and tax ID at checkout as an independent controller (see Paddle's privacy notice). We never receive your full card number or security code. We deliberately do not store the payment method details (such as card brand, last four digits or expiry) or billing address that Paddle's notifications contain — we keep only the identifiers and status listed above.
Apart from Google Analytics on the landing page and the blog, used only if you agree (section 3), we do not use analytics, advertising trackers or profiling, and we do not sell personal data.
3. Cookies and browser storage
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
refresh_token | Cookie (HTTP-only) | Keeps you signed in | 7 days |
linear_oauth | Cookie (HTTP-only) | Protects the Linear connection flow against forgery | 15 minutes |
| Access token | Session storage | Authenticates requests while the tab is open; usable until it expires | Until the tab is closed (the token itself expires after 15 minutes) |
| Workspace view | Local storage | Remembers whether you chose tiles or table view | Until you clear site data |
| Pending restore | Session storage | Remembers the restore you started while you connect the workspace to restore into | Until the restore starts or the tab is closed |
| Analytics choice | Local storage (landing page and blog) | Remembers whether you accepted or declined analytics | Until you change it or clear site data |
_ga, _ga_<ID> | Cookies (landing page and blog), only if you accept | Google Analytics: tell visits apart and count them | 2 years |
The app sets the items it needs only once you sign in or start the flow they belong to; they are strictly necessary for the Service or store a setting you chose, so we do not ask for consent. The documentation uses no analytics.
Analytics. If Google Analytics is offered on the landing page or the blog, we ask before using it. Until you accept, Google's script is not loaded and no analytics cookie is set. While analytics is offered, you can change your choice under Cookie settings at the bottom of those pages; declining removes the analytics cookies. We do not use Google Analytics for advertising: ads personalisation and Google signals are turned off, ad-related storage stays off, and Google does not collect city-level location or detailed device data for us.
Paddle's checkout opens only when you choose a plan or follow a payment link from Paddle. Paddle may set cookies in its checkout context, such as Cloudflare's bot protection cookie __cf_bm on paddle.com (30 minutes); Paddle's privacy notice applies to them.
4. How long we keep data
- Account, Linear connection and subscription data: while your account exists.
- Disconnected workspace: we delete its Linear tokens at once; the workspace record and its backups remain until you delete the workspace or your account, and backups expire as below.
- Backups: for the retention period you set (1–365 days, 7 by default), then deleted by a daily cleanup. Files copied from Linear are kept while at least one remaining backup contains them. A ZIP export of a backup is kept for up to 7 days, never longer than the backup. Deleting a workspace deletes its backups, files and exports from storage within 2 days.
- Payment event records: removed by the daily cleanup 90 days after they were processed, or 90 days after receipt if processing never succeeded.
- Job diagnostics: failed-job records are removed by the daily cleanup after 90 days. Our job queues also keep the last 100 finished and 100 failed jobs per queue (IDs and error messages); those of a deleted workspace are removed by an hourly cleanup, and a job still running at deletion is removed within an hour after it ends.
- Backup alert emails: our copy is kept 30 days after sending; one that could not be sent is dropped after 7 days.
- Support and legal correspondence: support messages are kept for 2 years after the last message in the conversation, so we can follow up on the same matter; complaints, legal notices and data-protection requests for 6 years after they are closed, the general limitation period for claims under Polish law. Messages stay with our mail provider and are not forwarded or copied elsewhere.
- Website analytics: kept in Google Analytics for 2 months; the cookies last up to 2 years unless you decline or clear them.
- Technical logs: our servers rotate logs by size (at most 30 MB per service); older entries are overwritten and not archived. Their age therefore depends on traffic.
- Disaster-recovery copies of our database: normally about 15 days. Local copies are removed by the next daily backup run after 14 days; copies in storage expire after 14 days and Cloudflare usually removes expired objects within a day.
- Accounting records: invoices to buyers are issued and kept by Paddle as seller. Our own accounting and tax records (Paddle statements, reverse invoices, payout and transaction reports, refund and chargeback records, bank confirmations) are kept for 7 years, or longer where a specific law requires it (legal basis: Art. 6(1)(c) GDPR). They identify buyers only by Paddle identifiers and transaction details where they do so at all.
- Account deletion: email [email protected] from your account address. We first make sure no subscription or payment can continue — including a payment Paddle is still processing — then delete your account, connected workspaces, subscription records, backups, job diagnostics and queue records within 30 days. Database recovery copies containing them normally expire about 15 days later, and payment event records (IDs and status only) within 90 days. Paddle keeps its own records under its policy.
5. Who we share data with
- Service providers (processors) that run our infrastructure — see Subprocessors. They may use the data only on our instructions.
- Paddle, as the independent controller of the checkout and payment.
- Google (Google Ireland Limited, with Google LLC), which provides Google Analytics on the landing page and the blog when you accept it.
- Linear, which you connect: we read from and, for restores you start, write to your own Linear workspace.
- Authorities or others where required by law.
6. International transfers
Our servers are in Falkenstein, Germany, and backups are stored in a Cloudflare R2 bucket under the EU jurisdiction setting, which keeps stored objects in the EU. Other processing may happen outside the EEA: Cloudflare's network handles requests globally, and Paddle and Linear may process data in the UK or the US. Our email provider is Zoho Mail on Zoho's EU data centre (zoho.eu), which stores support and legal correspondence in the EU. We have requested Zoho's data processing addendum; it is not yet signed.
Google Analytics data may be processed in the US by Google LLC under Google's data processing terms, with the EU Standard Contractual Clauses; Google LLC is certified under the EU–US Data Privacy Framework. Backup alert emails are sent through Resend (Plus Five Five, Inc.), which processes data primarily in the USA under its data processing addendum, with the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. Cloudflare's data processing addendum provides safeguards including the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. See Subprocessors for provider locations and transfer safeguards. You can ask us for details at [email protected].
7. Security
Linear tokens are encrypted at rest; passwords and sign-in refresh tokens are stored in our database only as hashes. Connections between your browser, Cloudflare, Linear and our storage are encrypted. Our backend does not expose ports to the internet: it is reached only through an authenticated Cloudflare tunnel, and its internal services talk over isolated private networks on the same server. If a breach affects your data we will notify you and the authorities as the law requires.
8. Your rights
Under the GDPR you can request access to, correction of, deletion of, or a copy (portability) of your personal data, restrict or object to processing based on legitimate interests, and withdraw any consent. Write to [email protected]; we answer within one month. You can also complain to a supervisory authority — in Poland the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl — or to the authority where you live or work.
9. If your data is in someone else's backup
If you are a member of a Linear workspace that another person or organisation backs up with BackupLatte, that customer is the controller of those backups. Please contact them first; we will pass on requests we receive and help them respond.
10. Children
The Service is not intended for anyone under 18.
11. Changes
We will post changes here and update the effective date. For material changes we will also notify account holders by email.