Privacy Policy
Last updated 2 August 2026
Ops Backroom is an operations dashboard for a business's own commerce and social-media data. It is built so that its automated pipelines never write down a shopper's name, email address, phone number or shipping address. This policy sets out what it does store, which third parties receive it, and — plainly — that data is kept until it is deleted by hand rather than on a schedule.
Who we are
Ops Backroom is operations software for small direct-to-consumer brands, built and operated by Brandon Karraa as a sole proprietor, based in California, United States. For anything in this policy, including access and deletion requests, contact bkarraa@opsbackroom.app.
In this policy, “you” means a business that uses Ops Backroom and the people it authorises to sign in. Ops Backroom is a business tool; it is not offered to consumers and is not directed at children.
What we deliberately do not collect
This is the design constraint the system is built around, so it comes first.
- Your customers' identities. When an order is ingested, its commercial fields are copied across using an explicit list of permitted fields rather than by removing known-bad ones. Names, email addresses, phone numbers, billing and shipping addresses and payment details are not on that list, so they are never written to our database — and a new personal field added by a platform in future is excluded by default rather than needing to be noticed.
- Payment instruments. No card numbers, bank details or payment credentials of any kind are stored. Order values are held only as whole-cent totals.
- The identities of people who follow, view or comment on your posts. We request counts, never identities. No commenter handle, no comment text and no individual follower record is ever fetched or stored.
- Uploaded files. Where a report is imported from a spreadsheet, the file itself is not kept — only its name, a checksum, the row count and the period it covers.
Two honest qualifications. First, where a platform sends us data by webhook, the full payload arrives at our server before it is filtered; the personal fields are discarded in memory and are never written to storage, which is a different statement from “they never reach us”. Second, these protections govern automated ingestion. They cannot govern what an authorised person types into a free-text box — see “Information you type in” below.
What we do collect
Account information
For each person authorised to sign in: an email address, an optional display name, an internal identifier and the date the account was created. Sign-in is passwordless — a one-time code is emailed to you — so we never receive, handle or store a password.
Commerce data
Orders and their line items, product and SKU identifiers, quantities, discounts, taxes, shipping charges, platform and payment fees, refunds, inventory movements and cost inputs — all monetary values as whole cents. Two items in this category are personal data and we call them out rather than bury them:
- A pseudonymous customer identifier. Each order carries the identifier the sales platform assigned to that shopper, both on the order record and in the order's stored audit copy. It contains no name or contact details and we cannot resolve it to a person, but the platform that issued it can — so it is personal data, and it is stored. It is used for one purpose only: telling repeat purchases apart from first purchases.
- Refund reasons. The note a member of your staff wrote when issuing a refund is stored as written. It is free text and is not filtered, so it will contain whatever was typed.
Creator records
If you use the creator-seeding features, the system stores details about the creators you work with: social handle, name, business contact details, audience size, pipeline status, shipment tracking references and your own notes. This is personal data about third parties that you enter and control. You are responsible for having a lawful basis to record it, and for telling those people if that is required where you operate.
Social media data — the accounts you connect
For each connected account we store: follower and following counts, post and video counts, and per-post metrics such as views, likes, comment counts, shares, saves, reach, watch time and interactions. We also store the caption text of those posts — copy that was written and published publicly — along with the post's link and short descriptive labels derived from the caption. For Instagram we additionally store the aggregate audience statistics the platform provides: age bands, gender split, countries, cities and hours of activity, each as bucket counts.
A connected account is not always the brand's own. Where a creator collaborates on posts with a brand, the platform serves those posts only to the account that published them, so the creator may connect their own account in order for their collaboration posts to be measured. When that happens we store the metrics, captions and links for the posts of that account that fall within the agreed scope, and the dashboard labels each item with the account that published it. That connection is authorised by the creator themselves and they can withdraw it at any time from within Instagram. Scope is agreed in advance; it is not a licence to read an account in full.
Those audience statistics are supplied to us already aggregated and we never receive any individual follower's identity. We do note, for accuracy, that a bucket can be small — a city may show a count of one — so we describe the data as aggregate rather than as anonymous.
Information you type in
Several parts of the dashboard accept free-text notes: creator notes, marketing-spend notes, cash-position notes, social snapshot notes, reconciliation notes, inventory references and tracking numbers. These are stored exactly as entered and are not filtered or inspected. If personal information is typed into one of them, it will be stored.
Technical information
Our hosting provider records standard server information for requests to the site, including IP address and user agent. This is platform-level logging outside the application itself.
Cookies
The application sets only the strictly necessary cookies its authentication library uses to keep you signed in. There is no analytics, tracking or advertising cookie, no third-party script, no advertising pixel and no telemetry of any kind in the front end. Web fonts are bundled and served from our own domain, so viewing the site makes no request to a font provider. The public pages you are reading now set no cookie at all and require no session.
Who else receives data
We do not sell data, do not share it for advertising, and do not use one business's data to inform or benchmark another. Data reaches the following service providers because the product runs on them:
- Supabase — the database and authentication provider. Everything the product stores is stored there.
- Vercel — application hosting. Receives every request to the site and runs the scheduled jobs.
- Anthropic— a daily job sends the text of published post captions to the Claude API to classify them by hook, theme and call-to-action. This covers the captions of every account we track, including a collaborating creator's. One caption is sent per request as the only content in it, and nothing else goes with it: no customer data, no account details, no order data and no metric value.
- Meta (Instagram) and TikTok — the platforms whose accounts you connect. We send the access token you granted and receive the analytics described above.
- Shopify — where the commerce integration is configured, we send an API credential and receive order data.
- Brevo — relays the sign-in email containing your one-time code, and therefore receives the email address requesting it.
We may also disclose data where we are legally required to do so.
How long we keep it
Plainly: indefinitely, until it is deleted on request. There is no automatic expiry, scheduled purge or retention timer anywhere in the system, and the historical series the dashboard depends on are designed to accumulate rather than roll over. We would rather state this than publish a retention period the software does not implement.
Access tokens are the exception: they are refreshed in place and cease to work when they expire or when you revoke them at the platform.
Deleting data, and asking what we hold
Email bkarraa@opsbackroom.app and we will action it manually. We describe it that way deliberately: there is no self-serve deletion button in the product today, so a request is carried out by hand against the database rather than by a feature. We aim to respond within 30 days.
You can also cut off future collection yourself at any time, without involving us, by revoking Ops Backroom's access in your Instagram, TikTok or Shopify settings. That stops new data arriving; it does not remove what has already been stored.
Removing a person's sign-in access is immediate. Note that records they created — a note they wrote, a movement they logged — remain, with the authorship reference cleared, because deleting them would silently change historical figures.
How it is protected
- Sign-in is by emailed one-time code. There are no passwords to leak, and public sign-up is disabled — an account has to be created for you.
- Every database table enforces row-level security, so an unauthenticated or unauthorised request returns nothing rather than returning data.
- Platform access tokens live in a dedicated table that no client-side credential can read: it carries no access policy at all and every client privilege on it is revoked. The administrative database key is confined to a single server-only module, and an automated test fails the build if it appears anywhere else.
- Scheduled jobs authenticate with a bearer secret compared in constant time.
- Data is encrypted in transit, and at rest by our hosting providers. We do not apply an additional layer of application-level encryption to stored tokens — they are protected by the access controls above.
One limitation worth stating rather than glossing: access to a business's dashboard is currently all-or-nothing. Anyone you authorise can see all of that business's data; there are no per-person roles or partial views. Authorise accordingly.
International transfers
Ops Backroom is operated from the United States and the service providers listed above process data in the United States and elsewhere. If you are outside the United States, using the service involves transferring data there.
Changes
If this policy changes we will update the date at the top of this page, and we will tell users directly where the change is material. Continuing to use the service after a change means you accept the updated policy.
Contact
bkarraa@opsbackroom.app — or see the Terms of Service.