Privacy Policy
Last updated: February 8, 2025
Paperbak Labs LLC ("Company," "we," "us," or "our") operates Paperbak Bridge (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described in this policy.
1. Information We Collect
We collect only the information necessary to provide and improve the Service:
- Account Information: When you register, we collect your name, email address, and a hashed version of your password. We never store your password in plain text.
- Third-Party Credentials: To perform sync operations, you provide Omeda API credentials and authorize access to your Google account. Omeda API keys are encrypted at rest. Google access tokens are stored securely and used solely to read and write to Google Sheets on your behalf.
- Bridge Configuration: We store the settings you configure for your bridges, including sheet IDs, webhook URLs, filter preferences, and scheduling options.
- Usage and Log Data: We collect basic usage information such as bridge run times, success/failure status, and record counts. This data is used for troubleshooting and service reliability.
- Payment Information: Payments are processed entirely by Stripe. We do not store your credit card number, CVC, or full billing details on our servers. We may receive and store limited information from Stripe such as the last four digits of your card and subscription status.
2. How We Use Your Information
We use collected information strictly for the following purposes:
- To provide, operate, and maintain the Service
- To authenticate your identity and manage your account
- To execute bridges between your connected services
- To process payments and manage your subscription
- To send transactional emails (account verification, password resets, bridge notifications)
- To diagnose technical issues and improve service reliability
We do not use your information for advertising, profiling, or any purpose unrelated to delivering the Service.
3. Minimal Data Retention
We believe in keeping only what we need, for only as long as we need it:
- Email deployment data retrieved from Omeda is processed in memory and written directly to your Google Sheet. We do not permanently store your email statistics, subscriber data, or deployment content on our servers.
- Sync run logs retain only metadata (timestamps, record counts, success/failure status) — never the underlying row-level data that was synced.
- Encrypted credentials are retained only while your account is active. Upon account deletion, all stored credentials are permanently destroyed.
- Account data is retained for the duration of your account. If you delete your account, all associated data is permanently removed from our systems within 30 days.
4. Third-Party Services
The Service integrates with the following third-party services, each with their own privacy policies:
- Google (Sheets API, OAuth): We request only the minimum scopes necessary to read and write to Google Sheets you designate. We do not access your Gmail, Google Drive files, or any other Google services beyond Sheets.
- Omeda: We use your API credentials to retrieve email deployment data on your behalf. We access only the data endpoints required for the sync operations you configure.
- Stripe: Handles all payment processing. Stripe is PCI DSS Level 1 compliant. See Stripe's Privacy Policy.
- Mailgun: Used to send transactional emails (verification, password reset). See Mailgun's Privacy Policy.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We do not share your data with outside parties except in the following limited circumstances:
- Service providers: We share data with the third-party services listed above solely to operate the Service (e.g., Stripe for payments, Mailgun for email delivery).
- Legal obligations: We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
6. Data Security
We take reasonable technical and organizational measures to protect your information, including:
- Encryption of sensitive credentials at rest
- HTTPS encryption for all data in transit
- Hashed and salted passwords
- Access controls limiting who can access production systems
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
7. Cookies
We use cookies only for essential functionality — specifically, to maintain your login session. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
8. Your Rights
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your account and all associated data
- Revoke third-party access (e.g., disconnect your Google account) at any time through the Service
To exercise any of these rights, contact us at joel@paperbak.com. We will respond to requests within 30 days.
9. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request its deletion. We do not sell personal information. To make a request, contact us at the email address above.
10. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes become effective immediately upon posting to the Website. We encourage you to review this page periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us at:
Paperbak Labs LLC
Email: joel@paperbak.com