Privacy policy
Last updated: August 5, 2026
Who we are
Noupad (noupad.com) is a client-facing project tracker with built-in scope protection, built for digital agencies and freelancers. Noupad is the controller of the personal data described in this policy, and this page explains in plain language what we handle and why.
The data we collect
Three kinds. Account details you give us when you sign up: your name, email address, and organization. Project data you enter as you work: projects, milestones, scope changes, prices, notes, and client records. And technical data generated by using the service: server logs, which include IP addresses, and anonymous usage statistics from our own self-hosted, cookieless analytics. We do not sell personal data and we do not run advertising trackers.
Your clients’ data
Client records and share pages can contain your clients’ personal data — names, email addresses, phone numbers. For that data you are the controller and we act as your processor: we use it only to run the features you switch on, such as the share page and client notification emails, and never for our own marketing.
Why we process it
We process account and project data to provide the service you signed up for — performance of a contract. We process technical logs to keep the service secure and reliable — a legitimate interest. We send marketing email only if you opted in, and every message includes a way out — consent. And we keep billing records because tax law requires it — a legal obligation.
Client share pages
Every share page sits behind a private, unguessable link that you create and can revoke at any time; rotating the link immediately cuts off anyone holding the old one, and you can additionally lock the page with a passcode. Share pages show only the project information you chose to publish, and they are served with headers that tell search engines not to index them.
Cookies
We set strictly necessary cookies only: one that keeps you signed in and one that remembers your language. Our analytics are cookieless. There are no third-party advertising cookies.
The services we rely on
A small set of providers processes data under contract, and each receives only what it needs to do its job. Supabase hosts our database and authentication. Polar processes payments as merchant of record — your card details go to Polar and never touch our servers. Brevo delivers transactional and notification email. If you choose to sign in with Google, Google confirms your identity to us. Where a provider processes data outside the EEA, the transfer rests on GDPR safeguards such as standard contractual clauses.
Retention and deletion
Your data stays for as long as your account exists. Delete your account, or ask us to delete it, and your data is removed from production systems within 30 days.
Your rights
The GDPR gives you the right to access, correct, export, and delete your personal data, and to object to or restrict its processing. Write to us and we will act on it — no forms, no runaround. You also have the right to complain to your local data protection authority.
Changes to this policy
If this policy changes in a way that matters, we will update the date at the top and flag significant changes by email or in the app. We will never quietly reduce your protections.
Contact
Questions about privacy: [email protected]