Legal
Privacy Policy
What personal data we collect, why, and the control you have over it under the GDPR. We keep it minimal, we never sell it, and analytics are opt-in.
Last updated · July 8, 2026
The short version
- · To pledge, we only need an email so we can tell you if a round opens. A handle is optional.
- · Analytics cookies are off until you opt in. You can change your choice any time.
- · We never sell your data, and we never see or store your money — there is no payment on Backrail.
- · You have full GDPR rights: access, correction, deletion, and more.
1. Who we are
Backrail ("Backrail", "we", "us", "our") operates the platform at backrail.io and is the controller of the personal data described here. Backrail is an independent project operated from Spain; it is not yet incorporated, and this policy will be updated with the operating entity's registered details once it is formed. We process personal data in line with the EU General Data Protection Regulation (GDPR) and Spanish data-protection law. For any privacy matter, contact us at hello@backrail.io.
2. What we collect
We deliberately collect as little as possible. Depending on how you use Backrail, that may include:
- Pledge details — the email you give us so we can contact you about a round, an optional public handle/name, the amount and the listing you pledged to, and the fact you agreed to our terms and risk notice.
- Account details — if you sign in, your email (magic link) or the basic profile from X (Twitter) or GitHub OAuth, such as your handle, display name, and avatar.
- Founder & listing details — for founders, the business information you submit and the reference to your Stripe connection (see section 6).
- Usage & device data — if you consent to analytics, aggregated information about pages viewed, approximate location, browser/device, and referrer.
- Communications — the content of any email or message you send us.
We do not intentionally collect special-category data (such as health, political, or biometric data). Please don't send it to us.
3. Where it comes from
Most data comes directly from you (when you pledge, sign in, list a business, or contact us). Some comes from third parties you choose to connect — X or GitHub when you use them to sign in, and Stripe when a founder connects an account. Usage data is generated by your interaction with the site, and only collected beyond what's strictly necessary if you opt in to analytics.
4. How we use it
- to run the platform — record your pledge, show listings, leaderboards, and progress;
- to contact you about a pledge or round — for example, to notify you if a round opens or is ready to execute;
- to authenticate you and keep your account secure;
- to compute and display verified revenue metrics for founder listings;
- to prevent fraud, abuse, and fake pledges, and to keep the platform safe and lawful;
- to understand and improve how Backrail is used (only with your analytics consent); and
- to comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not use it for automated decisions that produce legal effects on you.
5. Legal bases
Under the GDPR, we rely on:
- Contract / steps at your request — to record and act on your pledge, run your account, and provide the service you ask for;
- Consent — for analytics/marketing cookies and any optional marketing emails; you can withdraw it at any time;
- Legitimate interests — to secure the platform, prevent fraud and abuse, and improve the product, balanced against your rights; and
- Legal obligation — where we must keep or disclose data to comply with the law.
6. Founders' Stripe data
When a founder connects Stripe, they use a read-only (restricted) key. We use it only to compute revenue metrics such as MRR. We store the resulting aggregated snapshots — not your customers' personal data — and we keep the key itself encrypted in a secure vault, accessible only to our server, never exposed in the browser. A founder can revoke the key from Stripe at any time, which stops any further access. If you are a customer of a founder's SaaS, Backrail does not create a profile of you; only aggregate figures are displayed.
7. Who we share it with
We share personal data only with service providers ("processors") that help us run Backrail, under contract and only as needed:
- Supabase — database, authentication, and secure secret storage;
- Stripe — to read founder revenue data via read-only keys;
- Google Analytics — usage analytics, only if you opt in;
- our hosting and email providers — to serve the site and send transactional emails.
We may also disclose data if required by law, to protect our rights or users' safety, or in connection with a future reorganisation of the project. If and when real-money rounds proceed through a licensed crowdfunding service provider, that provider would act as its own controller for the data it needs (for example, KYC/AML), under its own privacy notice. We never sell your data.
8. International transfers
Some providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an adequacy decision — so your data keeps an equivalent level of protection.
9. How long we keep it
We keep personal data only as long as needed for the purposes above. Pledge and account data are kept while your account or pledge is active and for a reasonable period afterwards; we then delete or anonymise it, unless a longer period is required to comply with the law or resolve disputes. Analytics data is retained per the settings of our analytics provider. You can ask us to delete your data sooner (see section 11).
10. Cookies & analytics
We use a small number of strictly necessary cookies to keep the site working and to remember your cookie choice (for example, a consent cookie stored for up to 180 days). Analytics and marketing cookies are off by default and load only after you accept them in our cookie banner. You can accept all, reject all, or change your choice at any time via the banner, and you can also block cookies in your browser settings.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy;
- correct inaccurate or incomplete data;
- have your data deleted ("right to be forgotten");
- restrict or object to certain processing, including profiling and direct marketing;
- data portability — receive your data in a portable format; and
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, email hello@backrail.io. We'll respond within the time limits set by law. You also have the right to lodge a complaint with your local supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD, aepd.es).
12. Security
We take reasonable technical and organisational measures to protect your data — including encryption in transit, encrypted storage of sensitive secrets such as Stripe keys, and access controls that keep those secrets on the server and out of the browser. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a breach where the law requires it.
13. Children
Backrail is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a minor has given us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. When we do, we'll change the "last updated" date above and, for material changes, take reasonable steps to let you know. Please check back periodically.
15. Contact
For any privacy question or to exercise your rights, reach us at hello@backrail.io. See also our Terms of Service.