Privacy Policy

Privacy Policy

Backline, Inc.

Last updated: July 21, 2026

This Privacy Policy describes how Backline, Inc. ("Backline," "we," "us") collects, uses, and protects personal data when visitors browse our marketing site, when users create accounts and operate the Backline platform, and when venue staff use Backline on the door, VIP floor, production line, or show control desk. By using the Service, you agree to the practices outlined here.

Who we are and how we handle roles

For venue and organization customers who use Backline to manage guest lists, tables, talent advancing, and show control, Backline acts as a data processor. Those customers are the data controllers responsible for the lawful basis of processing, transparent notices to their guests, and honoring their own regulatory requirements.

For website visitors, people who sign up for Backline accounts, billing and support contacts, and anyone interacting with Backline outside of a venue's own data, Backline acts as the data controller. We determine the purposes and means of processing this information and comply with applicable privacy laws.

Information we collect

Account & Profile Data

We collect name, email, role, organization, contact details, and authentication data when you create or manage an account. Credentials are handled by WorkOS AuthKit, our authentication provider, so Backline does not store raw passwords. AuthKit manages sign-in, session lifetimes, MFA, and device approvals.

Operational Data (entered by customers)

Customers load guest lists, VIP reservations, artist advancing details, show control timelines, incidents, and internal notes into Backline. This may include guest names, contact information, tiers, RSVP status, table spend and comps, artist riders, hospitality counts, travel info, security notes, and production cues. Backline processes this data only to provide the contracted services and does not sell or repurpose it.

Usage & Device Data

When you access Backline we collect IP address, device type, operating system, browser, app version, timestamps, logins, feature interactions, error diagnostics, and local device identifiers used for approvals. This helps secure accounts, prevent abuse, and keep audit trails.

Analytics & Experimentation Data

We use PostHog to gather aggregated product analytics and run experiments. Events like page views, feature usage, and experiment assignments are sent to PostHog with pseudonymous identifiers to measure performance. PostHog does not use this data for cross-site tracking.

Payment & Billing Data

Polar processes subscription checkout, billing, invoices, and receipts. Stripe processes table-service reservation deposits. Backline stores the provider identifiers and payment or subscription status needed to operate those workflows, not full card numbers or CVVs.

Communication Data

When you email support, send feedback, or receive transactional emails (account invites, device approvals, alerts), we process message content, attachments, and metadata. Resend delivers these operational emails and stores recipient, subject, delivery timestamps, and error metadata to ensure delivery.

Cookies & Similar Technologies

We use cookies, local storage, and similar technologies to maintain sessions, remember device approvals, record analytics metrics, and support authenticated product behavior. We do not use third-party advertising pixels or sell cookie data.

Device access and local storage

Authorized devices may store session identifiers, preferences, and limited product data needed for authenticated use. This data is tied to authenticated accounts and venue access controls. When a user or device loses access, Backline blocks future product access through the application. Venue administrators must maintain physical control over devices to protect this data.

How we use your information

  • Provide, operate, and maintain door, VIP, talent advancing, and show control workflows.
  • Authenticate and secure access via WorkOS AuthKit, including device approvals and session management.
  • Process subscriptions and invoicing through Polar and table-service reservation deposits through Stripe.
  • Send transactional communications through Resend for invites, alerts, and operational notices.
  • Analyze usage, run experiments, and improve reliability with PostHog.
  • Detect and prevent abuse, investigate incidents, and maintain audit trails.
  • Comply with legal obligations, accounting rules, and requests from authorities where appropriate.

Legal bases for processing (EEA/UK users)

  • Contractual necessity: Delivering the Backline platform to customers and their teams.
  • Legitimate interests: Securing the service, running analytics, improving features, and ensuring business continuity.
  • Consent: Collecting certain cookies, sending optional marketing communications, or handling data beyond contractual needs.
  • Legal obligation: Retaining invoices, responding to lawful requests, and maintaining security records.

Service providers and sub-processors

We rely on service providers to operate specific parts of Backline. Depending on how the Service is used, these providers may process account, operational, payment, file, analytics, or communication data for us.

  • Vercel: Hosts the Backline web application and its web-server routes.
  • Convex: Provides the application backend, realtime database, server functions, and storage for product data and some uploaded files.
  • Cloudflare R2: Provides object storage for selected uploaded files and public media.
  • WorkOS AuthKit: Authentication and user management platform handling logins, MFA, and device approvals.
  • Polar: Payment processor for subscriptions, invoicing, and receipts.
  • Stripe: Payment processor for table-service reservation deposits.
  • PostHog: Analytics and experimentation platform that handles product metrics, feature tests, session replay, and application logs.
  • Sentry: Error monitoring, diagnostics, and user feedback tooling.
  • Resend: Email delivery provider for transactional and operational emails.

Data may be stored in the United States or European Union depending on the provider. Where required, we rely on Standard Contractual Clauses or equivalent safeguards to enable international transfers.

How long we keep your data

  • Account and profile data remain while an account is active and for a reasonable period afterward to satisfy legal and contractual obligations.
  • Operational data (guest lists, reservations, advancing records, incidents) persists for the duration of a customer's subscription unless the customer requests deletion or anonymization.
  • Audit logs and security records are kept as long as necessary to investigate issues and comply with legal requirements.
  • PostHog retains analytics events according to their data retention policies; aggregated metrics may be stored longer to evaluate product performance.

How we protect your data

  • Network connections between clients and Backline's hosted services use HTTPS/TLS.
  • Vercel, Convex, Cloudflare, WorkOS, Polar, Stripe, PostHog, Sentry, and Resend maintain their own security programs for the services they provide.
  • Backline limits internal access using least-privilege, enforces device approvals, and uses role-based access controls.
  • We monitor for suspicious activity, maintain audit trails, and review logs for incidents.
  • We regularly update dependencies and infrastructure to address vulnerabilities.

International data transfers

Our service and sub-processors may store or process data in the United States, the European Union, or other locations where they operate. When transferring personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on Standard Contractual Clauses or other appropriate safeguards to ensure an adequate level of protection.

Your rights

EEA/UK individuals

You have the right to access, correct, or delete your personal data; restrict or object to certain processing; receive a copy of your data in a portable format; and lodge a complaint with your local supervisory authority. Where we act as a processor, please contact the relevant venue or organization to exercise your rights, they control the operational data stored in Backline.

California and US individuals

You have the right to know what categories of personal information we collect, request deletion (subject to exceptions), and not be discriminated against for exercising your rights. Backline does not sell personal information. To submit a request, contact us at privacy@getbackline.app.

Children's privacy

Backline is not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a minor has provided data to us, please contact privacy@getbackline.app so we can remove it.

Your choices

  • Update account and organization settings within the app.
  • Manage marketing email preferences via unsubscribe links or by contacting us.
  • Control cookies and local storage through browser settings, though disabling certain cookies may impact functionality.

Contact us

If you have questions about this Privacy Policy or would like to exercise your rights, email us at privacy@getbackline.app.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, if the changes are material, we will provide additional notice such as via email or in-app messaging.