Privacy Policy

Last updated: April 7, 2026

1. Who We Are

MRRback ("we", "us", "our") is a SaaS churn-recovery platform available at www.mrrback.com. This Privacy Policy explains how we collect, use, store, and share information when you use our service.

2. Information We Collect

2.1 Account Information

When you sign up we collect your name, email address, and business name. We use Supabase for authentication and may allow sign-in via Google OAuth, which provides your name and email only.

2.2 Billing Provider Data

When you connect a billing provider (Stripe, Polar, Paddle, or Lemon Squeezy) via OAuth or API key, we receive webhook events containing customer identifiers, email addresses, names, subscription status, and subscription amounts. We use this data solely to trigger and manage churn-recovery sequences on your behalf.

2.3 Gmail Integration (Google API Data)

If you choose to connect your Gmail account, we request the gmail.send scope, which allows MRRback to send emails from your Gmail address on your behalf. We do not request permission to read, modify, or delete your emails or any other Gmail data.

MRRback's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data (OAuth tokens) to send recovery emails that you have configured.
  • We do not use Google user data for advertising, market research, or any purpose unrelated to providing the MRRback service.
  • We do not allow humans to read your Google user data unless (a) we have your explicit consent, (b) it is necessary for security purposes, (c) it is required by law, or (d) the data is aggregated and anonymized for internal operations.
  • We do not transfer Google user data to third parties except as necessary to provide the service, as required by law, or as part of a merger or acquisition with prior user notice.

2.4 Payment and Subscription Data

We process subscription payments through Polar.sh. When you subscribe to a paid plan, Polar handles all payment processing. We do not store your credit card number or full payment details. We receive from Polar your subscription status, plan, and customer identifier to manage your account.

2.5 Usage Data

We collect standard analytics data (page views, feature usage) via Vercel Analytics. We use Tawk.to for live chat support, which may collect your IP address and browser information.

3. How We Use Your Information

  • To provide and operate the MRRback service
  • To send recovery emails and SMS to your churned customers on your behalf
  • To process payments and manage your subscription
  • To send you product updates and support communications
  • To detect and prevent fraud or abuse
  • To comply with legal obligations

4. Data Retention

Customer data collected via webhook events is retained according to your plan tier: 30 days (Free), 90 days (Recover), or 365 days (Scale). After the retention period, data is automatically deleted. You may also request deletion of specific customer data at any time from your dashboard.

If you delete your account, all associated data (business information, recovery sequences, webhook events, customers, and stored OAuth tokens including Gmail credentials) is permanently deleted.

5. Third-Party Services

We use the following third-party services to operate MRRback:

  • Supabase — Authentication and user management
  • Polar.sh — Subscription billing and payment processing
  • Resend — Transactional email delivery (when Gmail is not connected)
  • Twilio — SMS delivery for recovery sequences
  • Google Gmail API — Sending recovery emails from your Gmail (optional, only with your explicit consent)
  • Inngest — Background job orchestration
  • Vercel — Hosting and analytics
  • Stripe, Polar, Paddle, Lemon Squeezy — Billing provider integrations (your customers' data, received via webhooks)

6. Data Security

We use industry-standard security measures to protect your data. All data is transmitted over HTTPS. OAuth tokens (including Gmail refresh tokens) are stored encrypted at rest in our database. Access to production systems is restricted to authorized personnel only.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Revoke Gmail access at any time from your MRRback settings or your Google Account permissions
  • Disconnect any billing provider integration at any time
  • Export your data

To exercise any of these rights, contact us at hello@mrrback.com.

8. Cookies

We use essential cookies for authentication (Supabase session cookies). We do not use advertising or tracking cookies. Vercel Analytics uses privacy-friendly, cookieless analytics.

9. Children's Privacy

MRRback is not directed to children under 13. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of MRRback after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy, contact us at hello@mrrback.com.