⚠️ TEMPLATE — not legal advice. Starting draft for a UK service under UK GDPR. Replace every[PLACEHOLDER], confirm your ICO position, and have it reviewed. Last updated:2 July 2026.
Data controller: [LEGAL NAME / COMPANY NAME], [REGISTERED ADDRESS]. Contact / data requests: [CONTACT EMAIL]. ICO registration: [NUMBER, if registered].
We designed SourceBack to hold as little of your data as possible. In short: your uploaded files and their outputs are processed to produce your result and then auto-deleted within 12 hours, and we never reuse your content or use it to train anything.
| Data | Why | Kept for |
|---|---|---|
| The file you upload + the output we generate | To convert it and let you preview/download | Auto-deleted within 12 hours; the uploaded source is deleted right after conversion |
| Payment info | To take payment | Handled by Stripe — we never see or store your card number. Stripe holds transaction records; see Stripe's privacy policy |
| Credit-pack token | To hold prepaid download credits | Stored in *your browser* (localStorage) + a balance in our database until spent |
| Operational logs & analytics | Reliability, abuse prevention, aggregate metrics | Event counts and job metadata (page counts, sizes, success/purchase events) — never anything derived from your file content. [Set a retention window, e.g. 30–90 days.] |
| IP address | Rate limiting / abuse protection | Short-lived hit records, purged on a rolling window |
We do not require an account, name, or email to use the service.
product; they exist only to produce your result and are then deleted.
abuse prevention, aggregate operational metrics), balanced against your rights.
[HOSTING PROVIDER] — runs the servers/storage that briefly hold your job.[Any error-monitoring/analytics provider you add, e.g. Sentry.]We use reputable providers and don't share your file content beyond what's needed to run the service. [Confirm any international transfers + safeguards.]
We don't use advertising or tracking cookies. We use your browser's local storage only to hold your credit-pack token so you can spend prepaid credits. [If you add any analytics that set cookies, disclose them and add a consent banner.]
Under UK GDPR you can ask to access, correct, erase, restrict, or object to our processing of your personal data, and to data portability. Because we auto-delete file content quickly and hold minimal personal data, some requests may have little to act on. To exercise a right, email [CONTACT EMAIL]. You can also complain to the Information Commissioner's Office (ICO), ico.org.uk.
The service isn't directed at children under [16] and we don't knowingly process their data.
We may update this policy; the current version is always at this URL, with the "last updated" date above.
[CONTACT EMAIL].