Privacy Policy
Last updated: July 30, 2026
Backpack Works LLC ("Backpack Works," "we," "us," or "our") provides design and development services, the backpack.works website, and the Backpack OS platform (together, the "Services"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.
By using the Services, you agree to this Policy. Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Who this Policy covers
- Website visitors at backpack.works.
- Prospects and clients who contact us or engage our services.
- Users of Backpack OS, our platform for planning, building, and managing websites and digital products.
Where we provide services to a business client, that client is the "controller" of end-user data they upload or connect, and we act as their "processor." This Policy describes our own practices; a client's own privacy notice governs their end users.
2. Information we collect
Information you provide: name, email, phone, company, billing details, and anything you send us (for example contact forms, support requests, account content).
Information collected automatically: IP address, device and browser type, pages viewed, referring pages, timestamps, and similar log and usage data, collected via cookies and similar technologies (see Section 8).
Platform data (Backpack OS): project and task records, site and brand information, generated content and design assets, analytics, and account settings you create or upload.
Connected-service data: when you authorize an integration (for example Webflow, Google, HubSpot, Marketo, Stripe, or a CMS), we access only the data permitted by the scopes you approve, to provide the features you request. You can disconnect an integration at any time, which revokes our access. Google integrations are described in detail in Section 5.
We do not intentionally collect special categories of personal data (for example health or biometric data) through the Services.
- Figma plugin data: Our Figma plugin, Backpack Works — Design Import, brings a design you saved in Backpack OS into Figma as editable layers. When you use it, the plugin sends your Backpack API key to us to authenticate the request, and we return the list of designs saved in your workspace and the HTML and brand palette of the design you choose to import. The key is stored by Figma on your own computer, not on our servers and not inside your Figma file. The plugin does not read or modify any existing layer in your Figma files and sends nothing from them to us. It adds a new frame to the page you are on, and creates a "Backpack Brand" variable collection to hold the design's colors. Rendering the design loads the fonts and images it references from their own hosts, in the same way opening the page in a browser would. Design content is not shared with any third party. You can disconnect at any time from within the plugin, which removes the stored key, and you can revoke the key itself in Backpack OS under AI Builder, Integrations.
3. How we use information
- Provide, operate, secure, and improve the Services.
- Create and manage accounts and authenticate users.
- Process payments and manage billing.
- Communicate with you about the Services, support, and (where permitted) marketing you can opt out of.
- Generate and deliver features you request, including AI-assisted content and design (see Section 6).
- Monitor performance, prevent fraud and abuse, and comply with legal obligations.
Legal bases (EEA/UK): performance of a contract, our legitimate interests (operating and improving the Services), consent (for example certain cookies and marketing), and compliance with legal obligations.
4. How we share information
We share personal information only as described here:
- Service providers and sub-processors who host and support the Services (for example cloud hosting, database, storage, analytics, payments, and AI providers), under contracts limiting their use of the data. A current list is available in our Trust Center (Section 9) or on request.
- Integrations you authorize, to exchange data with services you connect.
- Legal and safety reasons: to comply with law, enforce our terms, or protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use client or platform data to train third-party AI models.
5. Google user data
This section describes how Backpack Works accesses, uses, stores, and shares data obtained through Google APIs. It applies whenever you connect a Google account to Backpack OS.
5.1 What we access and why
We request access on a per-product basis. Connecting one Google product does not grant access to another, and each product is requested only when you choose to connect it.
Google service — Scope requested: What we do with it
- Sign-in — openid, email, profile: Identify you and label the connection with your Google account email.
- Google Search Console — webmasters.readonly: Read search performance data (queries, pages, impressions, clicks, average position) to report on and improve your site's organic search visibility. Read only.
- Google Analytics (reporting) — analytics.readonly: Read report data from properties you select, to answer your questions about traffic and conversions and to produce dashboards and reports. Read only.
- Google Analytics (configuration) — analytics.edit: Optional and requested separately. Create key events (conversions) and custom dimensions or metrics on a property, only when you ask us to and only after you confirm the specific change. Not requested unless you use this feature.
- Google Tag Manager — tagmanager.edit.containers, tagmanager.edit.containerversions, tagmanager.publish: Create and update tags and triggers, create container versions, and publish them, so that tracking changes you approve can be deployed without leaving the platform.
- Google Ads — adwords: Read campaign, ad group, keyword and search term performance for reporting and recommendations, and apply a limited set of changes (pause or enable a campaign, adjust a campaign budget, add negative keywords) that you have explicitly confirmed. Google does not offer a read-only Ads scope.
- Google Drive — drive.file: Create and edit only the files Backpack OS itself generates, for report export. This scope cannot see any other file in your Drive.
- Google Calendar — calendar.readonly: Read a Backpack Works employee's own calendar list and upcoming events — start and end times, event title, location, attendee names and email addresses, and any video-conference link — to display an "Upcoming meetings" view inside Backpack OS. Read only. This is never requested from customers of the platform: the connect route verifies the signed-in user is a Backpack Works employee and refuses anyone else, and it is not part of any customer-facing connection flow.
5.2 How changes to your Google accounts are authorized
Where a scope permits writing, Backpack OS never originates a change on its own. Every change begins with an instruction from you, and how it is authorized depends on the service.
Google Analytics configuration and Google Ads: the specific change is presented to you as a written proposal describing exactly what will happen, and a person must confirm it before we call the Google API.
Google Tag Manager: your typed instruction describing the tracking you want is the authorization for the edit. Backpack OS builds it in a container workspace and stages a container version, then stops. Nothing reaches your live site until that version is published. Publishing defaults to a separate, deliberate action taken by a person. A site can be switched to publish approved changes directly without that second click; this is an explicit per-site setting, off by default, and changeable only by an authorized user of your organization. Before any run that may publish, we record the container's currently live version so the change can be rolled back in one click, and Tag Manager retains its own version history independently of us.
Google Ads changes we apply are recorded in an audit log with the user who approved them, a timestamp, and the prior and resulting values where the change replaced an existing setting.
No scheduled or background job writes to your Google accounts.
5.3 How we store and protect it
Google user data is stored in our own database, hosted in the United States, isolated per customer organization and enforced at the database layer with row-level access controls. OAuth access and refresh tokens are encrypted at rest. Access by our personnel is limited to those who need it to operate or support the Services.
5.4 How we share it
We share Google user data only:
- with sub-processors that host or operate the Services on our behalf (cloud hosting, database, and AI providers), under contracts that limit their use of the data to providing the service to us;
- with you and other authorized users within your own organization;
- where required to comply with applicable law or legal process, or to investigate and prevent security incidents, fraud, or abuse;
- in connection with a merger, acquisition, or sale of assets, with notice to you.
We do not sell Google user data, we do not use it for advertising or to build advertising profiles, and we do not transfer it to any other party for those purposes.
5.5 AI processing of Google user data
Backpack OS uses AI models to answer questions and draft recommendations. Google user data reaches our AI provider in two situations. When you ask a question that requires it, the specific report data returned from the Analytics, Search Console, Google Ads or Tag Manager APIs is sent solely to produce the answer you requested. Separately, for Backpack Works employees using the internal assistant, upcoming Google Calendar events are included as context so the assistant can answer questions about the day ahead: the event title, its time, the attendees, and the location. Attendees are identified by the display name Google returns, or by a non-addressable label derived from their email domain where Google returns none, so we do not send attendee email addresses to the model. Google Calendar is the only Google Workspace API whose data is sent to a model. Our Google Drive access is limited to files Backpack OS itself creates, so no Drive content is read or sent anywhere.
This processing is governed by contracts that prohibit the provider from using your data to train or improve their models and that limit retention.
We do not use Google user data, whether raw or aggregated and anonymized, to develop, improve, or train artificial intelligence or machine learning models, whether our own or a third party's, and we do not transfer it to any third-party service that would use it to train theirs.
5.6 Limited Use
Backpack Works' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we do not allow humans to read Google user data unless: we have your affirmative agreement for specific data; it is necessary for security purposes such as investigating abuse; it is necessary to comply with applicable law; or the data has been aggregated and anonymized and is used for internal operations.
5.7 Retention and revoking access
You can disconnect any Google integration at any time from within Backpack OS. Disconnecting deletes the stored tokens, and once the last integration using a given Google account is disconnected we also revoke the authorization with Google. Where the same Google account is still connected for another integration, that authorization is kept so the remaining integrations keep working, and it is revoked when the last one is removed. You can also revoke access directly from your Google account at any time at myaccount.google.com/permissions.
When you disconnect an integration or close your account, Google user data we have stored is deleted within 30 days, except where we are required to retain it by law. You can also request deletion at any time by contacting us at privacy@backpack.works.
6. AI features
Backpack OS includes AI-assisted tools. To generate output, relevant inputs (such as brand details and the content being worked on) are processed by our AI providers under agreements that prohibit using your data to train their models and limit retention. AI-generated changes are drafts and are reviewed by a person before being applied to a live site. Section 5.5 describes how this applies specifically to Google user data.
7. Data retention
We keep personal information for as long as needed to provide the Services and for legitimate business or legal purposes, then delete or anonymize it. Clients may request deletion of their account data, which we action within a reasonable period, subject to legal retention requirements. Retention of Google user data is described in Section 5.7.
8. Cookies and tracking
We use cookies and similar technologies for essential functions, analytics, and (with consent where required) marketing. You can manage preferences through our cookie banner and your browser settings. Refusing some cookies may limit parts of the Services.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and tenant isolation. Details are in our Trust Center at security.backpack.works. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. International transfers
We may process information in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
11. Your rights and choices
Depending on your location, you may have the right to access, correct, delete, port, or restrict the use of your personal information, to object to certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of "sale" or "sharing" (which we do not do). To exercise any right, contact us (Section 14). We will not discriminate against you for exercising your rights, and you may appeal a decision by replying to our response.
12. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
13. Third-party links
The Services may link to third-party sites we do not control. Their privacy practices are governed by their own policies.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date and, where appropriate, provide additional notice.
15. Contact us
Backpack Works LLC
Email: privacy@backpack.works (or hello@backpack.works)
Trust Center: https://security.backpack.works
For EEA/UK inquiries, you also have the right to lodge a complaint with your local data protection authority.

