Privacy Policy
This Privacy Policy explains how NAAX TECHNOLOGIES CORP. (“Boopy,” “we,” “us”) collects, uses, and protects your personal data when you use the Boopy web app and website (the “Service”). This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Philippine Data Privacy Act of 2012 (Republic Act No. 10173 / “RA 10173”) and its Implementing Rules and Regulations.
1. Who is the data controller
NAAX TECHNOLOGIES CORP., a corporation registered in the Philippines.
For any privacy question or to exercise a right under this policy: privacy@boopy.app
2. What data we collect, and why
We only collect what we need to run the Service.
Account data
Email address, name, password hash (or Google OAuth identifier), workspace name.
Purpose: to create and secure your account.
Legal basis (GDPR): contract — Art. 6(1)(b)
Legal basis (RA 10173): fulfilment of a contract — Sec. 12(b)
Subscription data you enter
Service names, amounts, currencies, renewal dates, cadences, group/cost-centre tags, notes, attached receipts or invoices.
Purpose: to provide the core tracking and reminder functionality you signed up for.
Legal basis (GDPR/RA 10173): contract
Notification preferences
Email reminder settings, push notification endpoints (Web Push / VAPID), reminder lead times.
Purpose:to send you the renewal alerts you've configured.
Legal basis: contract
Billing data
Plan, billing cycle, Paddle customer ID, invoice history. We do not store your card number — Paddle handles that as our Merchant of Record.
Purpose: to process payment for the Pro plan.
Legal basis: contract
Integration data (only if you enable it)
Google OAuth tokens (Calendar / Drive scopes); file metadata from a Drive folder you explicitly name; calendar event IDs we've created on your behalf.
Purpose: to sync renewals to your calendar and import subscriptions from your invoices.
Legal basis: contract; you can disconnect at any time.
Usage analytics
Anonymised product events (which features you use, error states, performance). Collected via PostHog.
Purpose: to improve the Service.
Legal basis (GDPR): legitimate interests — Art. 6(1)(f); you can opt out via the cookie banner.
Legal basis (RA 10173): legitimate interests of the controller — Sec. 12(f)
AI assistant interactions
Questions and context you send to “Ask Boopy” or the landing-page chat. Processed by OpenAI; not used to train their models (we use the API, not consumer products).
Purpose: to answer your questions.
Legal basis: contract
Technical logs
IP address, user agent, request timestamps, error traces. Held in Sentry (errors) and Axiom (server logs).
Purpose: security, debugging, abuse prevention.
Legal basis: legitimate interests
3. What we don't collect
- We don't load advertising trackers
- We don't sell or share data with data brokers
- We don't profile you for marketing
- We don't read your Google Drive beyond the single folder you name for invoice imports
- We don't store your payment card details (Paddle holds those)
4. How long we keep your data
- Active account: for as long as your account exists
- After you delete your account: account, subscription, group, and notification data is deleted immediately and irreversibly (hard delete with database cascade)
- Billing records: retained by Paddle and in our records for 7 years to meet tax and accounting law
- Server logs and error traces: retained for 30 days, then purged
- Analytics events (PostHog): retained for 12 months in anonymised form
5. Your rights
We've built each right into the product so you don't need to email us to exercise them.
| Right | How to use it |
|---|---|
| Access (GDPR Art. 15 / RA 10173 Sec. 16) | Settings → Account & Privacy → “Export my data” — downloads a JSON file with everything we hold |
| Portability (GDPR Art. 20) | Same export — machine-readable JSON |
| Rectification (GDPR Art. 16 / RA 10173 Sec. 16) | Edit your workspace, subscriptions, and groups directly in the app at any time |
| Erasure / Blocking (GDPR Art. 17 / RA 10173 Sec. 16) | Settings → Account & Privacy → “Delete my account” — cancels Paddle, hard-deletes data, removes your auth user |
| Restriction (GDPR Art. 18) | privacy@boopy.app |
| Object (GDPR Art. 21 / RA 10173 Sec. 16) | privacy@boopy.app — applies to processing based on legitimate interests |
| Withdraw consent | Disable PostHog analytics via the cookie banner; disconnect Google integrations from Settings |
You also have the right to lodge a complaint with your local data protection authority:
- Philippines (RA 10173): National Privacy Commission (NPC) — privacy.gov.ph
- European Union: Your local EU supervisory authority
- United Kingdom: Information Commissioner's Office (ICO)
6. California residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA / CPRA) grants you additional rights:
- Right to know what personal information we collect, use, disclose, or sell — see Section 2 above. We do not sell personal information.
- Right to delete personal information we hold about you — use the in-product account deletion flow or email privacy@boopy.app.
- Right to opt-out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising.
- Right to non-discrimination — exercising your privacy rights will not affect your access to the Service.
To submit a verifiable request under the CCPA, email privacy@boopy.app. We will respond within 45 days.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU region available |
| Paddle | Payment processing (Merchant of Record) | UK / US |
| Resend | Transactional email (renewal reminders) | US |
| PostHog | Product analytics (anonymised) | EU region available |
| OAuth login, Calendar sync, Drive invoice import | US / EU | |
| OpenAI | AI assistant and landing-page chat support | US |
| Vercel | Hosting and serverless compute | US / EU |
| Sentry | Error monitoring | US |
| Axiom | Server-side logging | US |
For transfers outside the EEA or the Philippines, we rely on Standard Contractual Clauses (SCCs), adequacy decisions where applicable, or the sub-processor's own data transfer mechanisms as recognised under applicable law.
8. Security
All data is encrypted in transit (TLS) and at rest. Row-Level Security (RLS) in our database means your workspace data can only be accessed by you. OAuth tokens are stored encrypted and never exposed in data exports. We use short-lived JWTs for authentication sessions.
9. Children
The Service is not intended for users under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact privacy@boopy.app and we will delete it promptly.
10. Changes to this policy
If we make material changes, we will notify you by email at least 14 days before the change takes effect. Non-material changes (e.g. updating sub-processor lists) take effect on the “Last Updated” date. Continued use of the Service after the effective date constitutes acceptance.
11. Contact
For any privacy question: privacy@boopy.app
NAAX TECHNOLOGIES CORP., Philippines