Stackd

Privacy Policy

Last updated: 12 March 2026

Overview

Stackd is a task management application that helps you visualise and balance your workload. We are committed to protecting your privacy and being transparent about how we handle your data.

Data We Collect

Account Information

When you create an account, we collect your email address for authentication purposes. Passwords are securely hashed and never stored in plain text.

Task Data

We store the tasks you create, including titles, time estimates, deadlines, and completion status. This data is essential to provide the core functionality of Stackd.

Payment Information

Payment processing is handled entirely by Stripe. We do not store your card details. We only receive confirmation of your subscription status from Stripe.

How We Use Your Data

  • To provide and maintain the Stackd service
  • To authenticate your account and keep it secure
  • To process your subscription payments
  • To send essential service communications (e.g., password resets)

We do not sell your data. We do not use your task data for advertising or share it with third parties except as necessary to provide the service.

Infrastructure & Data Storage

Database

Your data is stored in a PostgreSQL database hosted by Supabase, a trusted infrastructure provider. Supabase provides enterprise-grade security, encryption at rest, and regular backups. Data is hosted in secure data centres with SOC 2 Type II compliance.

Authentication

User authentication is managed by Supabase Auth, which provides secure session management, password hashing using bcrypt, and protection against common attacks.

Payments

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. Your card details never touch our servers.

Hosting

The Stackd application is hosted on Vercel, which provides secure, globally distributed infrastructure with automatic HTTPS encryption.

Data Retention

We retain your account and task data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.

Your Rights

Under GDPR and UK data protection laws, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to processing of your data

To exercise any of these rights, please contact us at privacy@stackd.today.

Cookies

We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party analytics that track you across websites.

Contact

If you have questions about this privacy policy or how we handle your data, please contact us at privacy@stackd.today.