BACKBONEAI SOLUTIONSLIVE · SCAN2STOCK
  • Home
  • Tools
  • Roadmap
  • About
  • Contact
Sign inContact us
01Home02Tools03Roadmap04About05ContactSign in →
BACKBONEAI SOLUTIONS

The backbone to any business. Nine integrated products across four categories. Built in public, shipping in public.

Operations

  • Backbone IMSLive
  • Scan2StockLive
  • Backbone POS
  • Backbone Mechanic

Finance & Growth

  • Accounting AI
  • Backbone Social
  • Backbone Farming

Intelligence

  • Backbone Intelligence
  • HobbyAI

Company

  • Tools
  • Roadmap
  • About
  • Contact
  • Sign in
© 2026 Backbone Solutions FZE · Milwaukee, WI · UAE
backbonesolutions.ai · Set in Geist
PrivacyTerms
Legal

Privacy Policy

Last updated: August 2, 2026

1. Introduction

Backbone Solutions ("Backbone," "we," "us," or "our") is a venture of Horizon Digital Marketing LLC (Milwaukee, Wisconsin, USA), which operates the Backbone IMS platform at app.backbonesolutions.ai and the website at backbonesolutions.ai. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to operators ("you") who use Backbone to run their inventory, storefront, order fulfillment, and social media posting.

Backbone is a multi-tenant SaaS — your business's data is logically isolated from every other Backbone tenant via row-level security in our database, and we do not aggregate, anonymize, or train on tenant data without explicit consent.

2. Information We Collect

Account information

When you create a Backbone account we collect your name, email address, password (stored hashed via Supabase Auth), business name, business address, and your role within the business.

Inventory and catalog data

Product names, variants, SKUs, barcodes, costs, prices, attribute schemas, images you upload, categories, vendors, brands, and stock levels at each of your locations. This is the data you put into Backbone — we hold it on your behalf so you can run your operations.

Sales and order data

When a customer buys one of your products through a Backbone-powered storefront, we receive the line items (variant ID + qty), the customer's shipping address (when provided for fulfillment), and the external transaction ID from your payment processor. We do not receive or store the customer's payment card details — those flow directly to Stripe.

Integration credentials

When you connect Clover POS, we store the OAuth access token Clover issues. When you connect Printify or Printful, we store the API token you provide. These tokens are scoped to your business in our database and are protected by row-level security; only authenticated members of your business can read them.

Usage data

We log which pages you visit, which features you use, and approximate timestamps so we can debug issues, measure feature adoption, and detect abuse. We do not use third-party analytics or behavioral advertising trackers.

What we do not collect

We do not collect biometric data, government-issued IDs, payment card numbers, social security numbers, health records, or any data unrelated to running your business.

3. How We Use Your Information

We use the information we collect to:

  • Operate the Backbone platform — show you your inventory, accept orders, route fulfillment, sync sales channels, send transactional emails
  • Forward orders for fulfillment — when a customer buys a print-on-demand variant, we send the order to your connected Printify or Printful account using the credentials you provided
  • Send service notifications — billing, security alerts, account changes, scheduled maintenance
  • Detect and respond to abuse, fraud, or unauthorized access
  • Improve the product — feature usage tells us where to invest engineering time

We do not sell your data. We do not share your data with advertisers. We do not train AI models on your inventory or customer data without explicit, opt-in consent surfaced in-product.

4. Third-Party Services We Use

To deliver Backbone, we integrate with these subprocessors. Each one has its own privacy policy.

  • Supabase — database + authentication hosting (all Backbone data, encrypted at rest, accessed via row-level security)
  • Render — application hosting (server logs only; no business data persisted on Render)
  • Stripe — subscription billing for your Backbone subscription, and optionally checkout for your customers
  • Anthropic (Claude API) — AI-powered features like invoice parsing
  • Resend — transactional email delivery
  • Cloudflare — DNS, CDN, edge caching (routing metadata only)
  • Clover (Fiserv) — Clover POS integration via OAuth 2.0
  • Printify — print-on-demand fulfillment (your token, your customers' shipping addresses for orders you forward)
  • Printful — alternative print-on-demand fulfillment
  • Meta Platforms (Facebook / Instagram) — when you connect an Instagram Business/Creator account, content publishing + Page/IG-account listing via the Facebook Graph API
  • X (Twitter) — when you connect an X account, posting tweets + media upload via the X API
  • LinkedIn — when you connect a LinkedIn account, sharing posts on your behalf via the LinkedIn API
  • TikTok — when you connect a TikTok account, publishing videos via the TikTok Content Posting API
  • Google (YouTube) — when you connect a YouTube channel, uploading videos via the YouTube Data API
  • Pinterest — when you connect a Pinterest account, creating pins + reading your board list via the Pinterest API

Adding a new subprocessor is a meaningful change. We update this list before bringing one online.

5. Connected Social Media Accounts

Backbone's social-posting feature lets you connect your own accounts on X, LinkedIn, Instagram, Facebook, TikTok, YouTube, and Pinterest so Backbone can publish content you create, or product posts you approve, to those accounts on your behalf.

How connecting works

You authorize each account through that platform's own official OAuth consent screen. You never give Backbone your social-media password — the platform hands us a token after you approve.

What we store

For each connection we store the access token (and a refresh token where the platform issues one), the minimum account identifier needed to post (e.g., your Instagram Business account ID and Facebook Page token, your Pinterest board ID, your LinkedIn member URN), and the label you choose for the connection. These tokens are encrypted at rest (AES-256-GCM) and are never exposed to your browser or to any other tenant.

What we access, and why

We request only the permissions needed to post:

  • Instagram / Facebook — instagram_content_publish to publish, and instagram_basic / pages_show_list / pages_read_engagement to list the Facebook Pages and linked Instagram Business accounts you administer so you can choose which to post to. We do not read your direct messages, comments, follower lists, or ads data.
  • X — permission to post and to upload media.
  • LinkedIn — w_member_social to share posts as you.
  • TikTok — video.publish / video.upload to publish videos.
  • YouTube — youtube.upload to upload videos to your channel.
  • Pinterest — pins:write to create pins and boards:read to list your boards.

What we do not do

We do not read your private messages, we do not post without your action (Creator mode) or your configured approval (auto-ad mode), we do not sell or share this data, and we do not build advertising or behavioral profiles from it.

Disconnecting

You can disconnect any social account at any time from the Backbone dashboard, which deletes the stored token immediately. You can also revoke Backbone's access from the platform directly (Instagram → Settings → Apps and Websites; Google → myaccount.google.com/permissions; X → Settings → Connected apps). Tokens are also deleted when you close your Backbone account.

Platform compliance

  • Backbone's use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.
  • Backbone's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Backbone's use of the TikTok and Pinterest APIs adheres to each platform's respective Developer Terms and Platform Policies.

6. Customer Personal Data

If your customer buys a product on a storefront powered by Backbone, the personal data we may receive about that customer is limited to: their name, shipping address, email address, and phone number — only when supplied for fulfillment.

We pass that data to the fulfillment provider you've connected (Printify, Printful, etc.). We do not market to your customers, build profiles of them, or share their data with anyone else. Your customers' personal data belongs to you. As the data controller, you are responsible for telling them how their data flows when they buy from your storefront — your customer-facing privacy policy should disclose Backbone as a processor.

7. Data Security

  • All connections use HTTPS / TLS 1.2+
  • Database access is gated by row-level security at the Postgres layer; an authenticated session can only read rows belonging to its own business
  • API tokens for connected services are stored at rest in our database with access restricted by row-level security
  • Internal admin access is logged and limited to the engineers who need it to keep the service running
  • We support multi-factor authentication via Supabase Auth — operators are encouraged to enable it

If we discover a security incident affecting your data, we will notify you without undue delay and within the timeframes required by applicable law.

8. Data Retention

  • Active account data is retained for as long as your account is active
  • After account closure, we retain data for 30 days, then delete or anonymize it
  • Backups are retained for up to 90 days for disaster recovery, then expire automatically
  • Audit logs (security-relevant events) are retained for 12 months
  • You can request immediate deletion at any time via the contact below; we will execute within 30 days

9. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a machine-readable format
  • Object to or restrict certain processing
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, email privacy@backbonesolutions.ai. We respond within 30 days.

You can disconnect any third-party integration (Clover, Printify, Printful) at any time from Settings → Connections. Disconnecting revokes the stored token immediately.

10. International Transfers

Backbone is operated from the United States. Our subprocessors may store and process data in other regions. By using Backbone you consent to your data being processed in the US and other regions where our subprocessors operate.

11. Children's Privacy

Backbone is a business-to-business service. It is not directed at individuals under 18 and we do not knowingly collect personal information from children.

12. Cookies and Tracking

The Backbone web application uses cookies for authentication and storing your interface preferences (sidebar state, view mode, density). We do not use advertising cookies, third-party trackers, or fingerprinting.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes (new subprocessors, expanded data collection, changed retention periods) are communicated via in-product banners and email at least 30 days before they take effect. Minor updates (clarifications, typo fixes) are posted here with the "Last updated" date refreshed.

14. Mobile Information and SMS

This section applies to consumers who contact a business operating on Backbone, including shoppers who submit a vehicle-inquiry form to Masari Motors at masarimotors.com. If you enter your mobile number and check the SMS consent box, we use that number only to reply to your inquiry and to confirm or update an appointment you booked with us. Message frequency varies. Message and data rates may apply. Reply HELP for help, or STOP to opt out at any time.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of personal data may be shared as described elsewhere in this policy, but text-messaging originator opt-in data and consent are not shared with any third parties.

The full program terms are in section 17 of our Terms of Service, and every way a customer can opt in is documented at backbonesolutions.ai/sms-opt-in.

15. Contact Us

Privacy questions, data access, deletion requests: privacy@backbonesolutions.ai
Security incidents, vulnerability reports: security@backbonesolutions.ai
General support: support@backbonesolutions.ai

Backbone — a venture of Horizon Digital Marketing LLC
Milwaukee, Wisconsin, USA