Effective date: 2026-08-11 · Version 2.0
Backstory Pty Ltd (ACN 689 322 941, ABN 37 689 322 941, "Backstory", "we", "our", "us"), of Australia (postal address available on request), operates the Backstory Analytics service at https://app.trybackstory.com (the "Service").
This policy has two parts. Part A (Core) covers Backstory's core product: cookieless, company-level website analytics. Part B (Contacts addendum) covers the optional Contacts add-on, which surfaces leads — named individuals with business contact details, at accounts your organization has identified — and is only active for organizations that have enabled it. If you don't use Contacts, Part B does not apply to you.
By using the Service you agree to this policy. If you disagree, do not use the Service.
Backstory Core identifies which companies (not individuals) are visiting a customer's website, and attributes their journey (pages viewed, referrer, UTM parameters) to that company. It does this without cookies, without device fingerprinting, and without resolving any visitor to a named person.
SHA-256(truncated IP + user agent + daily salt + 8-hour window)) to stitch a visitor's page views together for up to 8 hours. This hash is pseudonymous personal data under GDPR Article 4(5) — see our Legitimate Interest Assessment for the full three-part test.Account holders (you, our customer): email address, organization name, authentication credentials, billing details (processed by our payment processor — we never see full card numbers), and support communications.
Website visitors (via the tracking script): page paths, referrer domain, UTM parameters, coarse device/browser category, company/ASN identified from the visiting IP, and the ephemeral session hash described in Section 2. When a visitor submits a form using a company email address, we extract the company domain only (e.g. "acme.com" from "jane@acme.com") and discard the personal identifier; the prior 8-hour session is then attributed to that company.
Dashboard usage: feature usage and technical data (IP, browser, OS) when you access the dashboard yourself — this is ordinary web-application logging, distinct from the visitor-tracking script.
The Core tracking script does not use cookies or any client-side storage. See our Cookie / Cookieless Notice for the full statement, and the essential authentication cookies used by the dashboard itself.
Contacts is a separate, opt-in feature. When an organization enables it and accepts the Leads Data Processing Addendum, Backstory queries a third-party lead-data provider (currently GetProspect) on that organization's behalf to surface leads — named individuals (name, business email, job title, LinkedIn URL) who work at an identified company — matched against the organization's configured target job titles.
For Contacts processing, Backstory acts as a data processor and our customer acts as the data controller. Our customer is responsible for having a lawful basis for their own outreach to the individuals we surface (typically legitimate interest for B2B marketing under GDPR, or the equivalent under the Privacy Act/CCPA). Backstory processes this data only on the customer's documented instructions, per the Leads DPA.
Contacts data is siloed from Core: it is stored separately, gated behind the entitlement + the Leads DPA acceptance recorded for the organization, and is never merged into the Core, no-PII analytics dataset.
Revealed lead records are retained for the lifetime of the organization's account (or the Contacts add-on subscription) unless the organization deletes them or the individual exercises a deletion right (Section 12). Deletion requests relating to Contacts data should be sent to support@trybackstory.com and are actioned within 30 days.
We use a limited set of sub-processors to run the Service, including Cloudflare, ipapi.is, Supabase, Vercel, Sentry, Anthropic for Core account-identification analytics. The current, authoritative list is published on our Sub-processor list page, sourced from our Article 30 processor register. We will not add a new sub-processor that materially changes how your data is handled without updating that page.
Some sub-processors are located outside your country. Where we transfer personal data outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the International Data Transfer Addendum (IDTA) — see the Data Processing Addendum and Leads DPA for the transfer mechanisms and annexes.
If you are in the European Economic Area (GDPR) or the United Kingdom (UK GDPR): you have the right to access, rectify, erase, restrict, or port your personal data, and the right to object to processing based on legitimate interest (Article 21). To object to Core session-hash processing, email support@trybackstory.com — this is currently a manual process; we do not yet offer a self-serve opt-out toggle. You also have the right to lodge a complaint with your national supervisory authority (in the EU) or the ICO (in the UK).
If you are in Australia: the Privacy Act 1988 and the Australian Privacy Principles (APPs) give you rights to access and correct your personal information and to complain to the OAIC. Backstory's Core product identifies companies, not individuals, but where personal information is processed (e.g. your account details, or Contacts data), APP rights apply in full.
If you are in the United Kingdom: in addition to UK GDPR rights above, you may complain to the ICO.
If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect and disclose, to delete it (subject to exceptions), to correct it, and to opt out of "sale" or "sharing" — we do not sell or share personal information for cross-context behavioral advertising. Contact support@trybackstory.com to exercise these rights.
To exercise any right under this policy, email support@trybackstory.com. Data protection inquiries and formal notices can also be sent to legal@trybackstory.com. EU representative (GDPR Article 27): Backstory does not target or monitor individuals in the EU/EEA, so no EU Article 27 representative is appointed / required. Our privacy contact (Data Protection Officer, if any) is Natasha Postolovski (legal@trybackstory.com).
The Service is not intended for individuals under 18. We do not knowingly collect personal information from children.
We use encryption in transit (TLS) and at rest, access controls, and least-privilege service credentials. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
We will update the "Effective date" and version above when this policy changes, and will notify customers of material changes by email or in-product notice.
This policy is governed by the laws of Australia. Sections 10–12 describe additional rights that apply to you regardless of governing law, where mandated by GDPR, UK GDPR, the Privacy Act, or the CCPA/CPRA.
Backstory Pty Ltd — support@trybackstory.com (general/privacy requests) · legal@trybackstory.com (legal notices) · https://app.trybackstory.com.