Legal
AirtableBackup Privacy Policy
Version 0.9, under legal review. Effective date to follow.
Effective date: [EFFECTIVE DATE]
This policy explains what AirtableBackup (operated by [LEGAL ENTITY NAME], a California [ENTITY TYPE] doing business as [ENTITY], [ADDRESS]; "we", "us") collects when you use airtablebackup.com and app.airtablebackup.com (the "Service"), why, where it is kept, for how long, who sees it, and what you can do about it.
Two kinds of data pass through the Service. Your Airtable data, which we hold on your behalf and process only on your instructions (we are a "processor" of it; you are the "controller"). And the account data we need to run the Service for you, which we decide how to use (we are the "controller" of it). This policy covers both.
1. What we collect
1.1 Your Airtable data (held on your behalf)
When you connect a base, the Service reads and stores from it, through Airtable's API:
- records and field values, and every change to them that the Service observes;
- attachments (files in attachment fields), stored by their content;
- record comments;
- the base schema: tables, fields, field options, view names and types;
- where Airtable makes them available: automation configuration including the source code of script actions, form definitions, and interface page metadata;
- the names and email addresses of the base's collaborators, which Airtable returns with the base and which the Service uses to decide which account members may see the base.
What is in your base is up to you. It may include personal data about your own customers, staff or contacts. We do not know what it holds and we do not look, except as described in section 3.
1.2 Account data (ours to run the Service)
- Your name and email address, from Airtable when you sign in, and the email addresses of people you invite and of your chosen alert recipients.
- OAuth tokens that Airtable issues when you sign in, connect a base, grant write access for a restore, or turn on the nightly restore test. These are stored encrypted (section 6). A restore grant lives for at most one hour and only in an encrypted browser cookie.
- Settings: the bases you connected, the restore workspace you chose, the backup speed, alert preferences, the account's members and roles.
- Billing status and events as Paddle reports them (subscription status, dates, the Paddle customer and subscription identifiers). Payment card details are entered on Paddle's checkout and never reach the Service.
- Usage and error logs: which account did what and when (restores, settings changes, sign-ins), Airtable API responses and errors, and the Service's own operational records. Logs are kept on the server and, for operational alerts, posted in summary form to our private operations channel with the account identifier (never your Airtable data).
- Emails we send you (alerts, the nightly report, billing notices) and the delivery status Amazon SES reports.
1.3 What we do not collect
- No payment card numbers (Paddle holds them).
- No analytics or advertising trackers on the console. If we add a product-analytics tool later we will name it here first.
- Nothing from your Airtable workspace beyond the bases you ticked on Airtable's consent screen.
2. Why
- To back up your bases, keep their change history and let you restore them: this is the Service.
- To show each base only to the people who may see it in Airtable.
- To alert you to problems and send the reports you opt into.
- To bill you (through Paddle) and apply the account state your subscription gives you.
- To operate, secure and support the Service, and to investigate misuse.
- To meet legal obligations.
The legal bases, where EU/UK law applies, are performance of our contract with you (the Service and billing), our legitimate interests (security, operations, support, defending claims), and legal obligation. Processing of your Airtable data is on your documented instructions under the Data Processing Addendum.
3. Who at AirtableBackup can see your data
The Service is operated by a very small team. Access to the production system is limited to the people who run it, under individually assigned credentials with multi-factor authentication. They do not open your backups except to support you at your request, to investigate a fault or a security event, or where the law requires, and such access is logged.
4. Where your data is kept
All data is stored and processed in Amazon Web Services' us-west-1 region (Northern California, United States): on EC2 compute, in S3 object storage, with encryption keys managed by AWS KMS. Email is sent through Amazon SES from the same AWS account. Billing data is held by Paddle in its own systems. If you are outside the United States, your data is transferred to and stored in the United States (see section 10).
5. How long we keep it
5.1 Your Airtable data and account
While your account is in trial, active, or within its payment grace period, backups accumulate: every change the Service observes and a full copy every night, with the whole history kept. The storage keeps every version of every object (versioning) so that an accidental or malicious deletion can be reversed.
When a subscription ends:
| From the end of the subscription | State | What exists |
|---|---|---|
| Day 0 to day 30 | Read-only | Everything; you can browse and export |
| Day 30 to day 90 | Retained | Everything, but not readable by you; kept only so it can be restored if you subscribe again |
| After day 90 | Deleted | Your Airtable data, change history and account records are removed under our Retention and Deletion Policy |
An account whose trial ended, or whose payment was not recovered within 14 days of grace, becomes read-only. [COUNSEL / PRODUCT: as built today it stays read-only without a deletion clock; see the Terms, open question 2.]
You may ask for deletion sooner at any time (section 8).
5.2 Operational copies and logs
- A nightly copy of the account registry (settings, members, encrypted tokens, billing state) is kept for 14 days for disaster recovery.
- Server logs are kept for [LOG RETENTION] and then discarded.
- Billing records are kept by Paddle and by us for as long as tax and accounting law requires.
5.3 Note on the operator's own data
The same software also backs up [ENTITY]'s own Airtable bases. Those bases carry a five-year retention schedule that [ENTITY] applies to its own records under California employment-records law. That schedule applies only to [ENTITY]'s own data. It does not apply to any customer's account, which follows section 5.1.
6. How we protect it
- Encryption in transit: every connection to the console, to Airtable, to AWS and to Paddle uses TLS.
- Encryption at rest: backups are stored in S3 with server-side encryption. Airtable tokens are encrypted field by field with AES-GCM under a data key generated for that row and wrapped by a key in AWS KMS; the server may only generate and unwrap such keys, and no component decrypts a token except the one that needs to call Airtable.
- Deletion is denied by policy: the storage bucket's policy denies deletion to every identity except a separate "break-glass" role that the running service cannot assume. A person must assume that role, with multi-factor authentication, to delete anything, and the action is audited.
- Isolation between customers: each base's backup lives under its own storage prefix, is captured by its own process, and the engine answers "not found" for any base that is not the signed-in account's.
- Access follows Airtable: a base is visible only to account members who are collaborators on it in Airtable.
- Least privilege: the service's own credentials cannot delete backups, cannot administer encryption keys and can send email only from @airtablebackup.com.
- Write access to your Airtable is short-lived: a restore requires a fresh Airtable sign-in whose token lives at most an hour; backing up never needs write access.
We do not hold a third-party security certification (such as SOC 2) at this time and do not claim one.
7. Who we share it with
We share data only with the service providers below ("subprocessors"), each to the extent needed for its purpose. We do not sell personal data, do not share it for advertising, and do not use your Airtable data to train or improve anything.
| Provider | Location | Purpose |
|---|---|---|
| Amazon Web Services, Inc. | us-west-1 (Northern California, USA) | Compute (EC2), storage (S3), key management (KMS) |
| Amazon Web Services, Inc. (Amazon SES) | us-west-1 (USA) | Sending alert, report and billing emails |
| Paddle [PADDLE ENTITY] | [PADDLE LOCATION: UK/USA] | Checkout, payment, tax, invoicing and subscription management as merchant of record |
| Airtable, Inc. | USA | The source system your data comes from and is restored to; receives API calls on your behalf under the access you granted |
We may also disclose data where the law requires, to protect the rights, property or safety of us, our customers or others, or to a successor in a merger or sale of the business (with notice to you).
8. Your rights and choices
- Access and export: you can browse your backups and export any table as a CSV file from the console at any time while your account is active or read-only.
- Correction: your name and email come from Airtable; change them there. Members, recipients and settings are editable in the console.
- Deletion: write to support@airtablebackup.com from an owner's address to have your account and its data deleted before the windows in section 5.1. Deletion is also automatic after those windows. We confirm by email when it is done.
- Disconnecting: you can revoke the Service's access to Airtable at any time from Airtable's account settings or from the console's Settings page.
- Email: alerts and reports can be set to "problems only" or "no email" in Settings. Billing and security notices are sent regardless, because they concern your account.
Requests about personal data that is inside a base you connected should go to the organisation that connected it; we will assist them under the Data Processing Addendum.
8.1 California residents
If the California Consumer Privacy Act applies to you, you have the right to know what personal information we hold about you, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA. Make a request at support@airtablebackup.com; we will verify it through the email address on the account. [COUNSEL: confirm whether the CCPA's thresholds are met and whether this section is needed at launch.]
8.2 EU, EEA, UK and Swiss residents
[COUNSEL: keep or cut this section.]
If the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is based on consent. You may complain to your local supervisory authority. For data in a base you connected, the organisation that connected it is the controller and your request should go to them. We have not appointed an EU or UK representative [COUNSEL: whether Article 27 requires one]. See section 10 for transfers.
9. Cookies
The console sets a session cookie to keep you signed in, a short-lived cookie that carries the state of an Airtable sign-in while it is in progress, a cookie that remembers which base you are looking at, and, during a restore, an encrypted cookie holding your hour-long Airtable write token. All are necessary for the Service to work. There are no advertising cookies and no third-party analytics cookies. Paddle's checkout, when you open it, may set its own cookies under Paddle's privacy policy.
10. International transfers
The Service runs in the United States. If you use it from the EU, EEA, UK or Switzerland, your data is transferred to the United States. [COUNSEL: state the transfer mechanism — Standard Contractual Clauses and the UK Addendum in the DPA; whether the EU-US Data Privacy Framework applies to any subprocessor (AWS and Paddle positions to be confirmed).]
11. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 [COUNSEL: 13 or 16]. If a base you connect contains data about children, you are responsible for the lawful basis for it.
12. Changes to this policy
We may update this policy. For a material change we will email the account's owners before it takes effect and show the new effective date at the top. Earlier versions are available on request.
13. Contact
support@airtablebackup.com [LEGAL ENTITY NAME], [ADDRESS] [DATA PROTECTION CONTACT, if one is designated]