Privacy Policy & Data Processing Addendum
Last updated: June 26, 2026
This Privacy Policy explains how Upruve, the service operated by Luis Parker (an individual sole proprietor) ("Upruve", "we", "us", or "our"), collects, uses, shares, and protects personal data in connection with the Upruve service (the "Service"). It is incorporated into our Terms of Service. A postal address for legal and privacy notices is available on request at privacy@upruve.com.
1. Our two roles: controller and processor
Upruve processes personal data in two distinct roles:
- As a controller — for personal data about our account holders and Professionals (for example, registration, authentication, billing, and support data), and for operating, securing, and improving the Service. This Privacy Policy describes that processing.
- As a processor — for personal data that our customers (Professionals and their Teams) upload, generate, or transmit through the Service about their own clients and contacts ("Customer Personal Data"). For that data, the customer is the controller and Upruve acts on the customer's documented instructions. The Data Processing Addendum (DPA) in Part B below governs this relationship.
If you are a Client Contact or another individual whose data was uploaded by a customer, the customer (not Upruve) is responsible as controller; please direct privacy requests to them. We will assist our customers in responding to such requests.
2. Personal data we process
a) Account and Professional data (we are controller):
- Identity and contact data: name, email address, and (if provided via OAuth) profile information from Google or Microsoft.
- Authentication data: hashed credentials, session tokens, OAuth identifiers.
- Workspace data: Team name, role (admin/member), language preference, notification preferences.
- Communications: messages you send us for support and related correspondence.
b) Customer Personal Data (we are processor):
- Client company and contact details that you create: contact names, email addresses, language preferences, and roles you assign.
- Deliverable content and collaboration data: files, images, documents, URLs, website captures, comments, feedback, approvals, selections, and activity records — which may contain personal data you choose to include.
- Client Contact interaction data when a Client Contact uses a Share Link: the actions they take (comments, approvals, selections, read status, timestamps) and limited technical data needed to deliver and secure that access.
c) Billing data:
- Subscription, seat count, plan status, and billing-related metadata. Payments are processed by Paddle as Merchant of Record; we do not collect or store full payment card numbers. Paddle processes your payment data under its own privacy policy.
d) Technical and usage data:
- Device and connection data such as IP address, browser type, and operating system; log data; and aggregated, privacy-friendly usage analytics. We use Vercel Web Analytics, which is designed to be cookieless and does not use cross-site tracking cookies.
e) Email delivery data:
- Delivery status of transactional emails (e.g., delivered, bounced) via our email provider, used to maintain deliverability and contact preferences.
3. Cookies and similar technologies
We use only essential cookies and local storage required to operate the Service, including:
- Authentication/session cookies that keep you logged in (Supabase Auth).
- Local storage of your interface language preference.
For analytics we use Vercel Web Analytics, which is cookieless. We do not use advertising or cross-site tracking cookies, and we do not sell personal data. Because we rely on essential cookies and cookieless analytics, you can control non-essential storage through your browser settings; disabling essential cookies may prevent the Service from working.
4. How we use personal data and legal bases
We process personal data for the following purposes. Where the GDPR or similar laws apply, the corresponding legal bases are indicated:
- To provide the Service (create and manage accounts, Teams, deliverables, Share Links, comments, decisions, and notifications) — performance of a contract.
- To process payments and manage subscriptions (via Paddle) — performance of a contract; legal obligation (tax/accounting).
- To send transactional communications (magic links, notifications, invitations, security and account messages) — performance of a contract; legitimate interests.
- To secure the Service (prevent fraud, abuse, and unauthorized access; maintain logs) — legitimate interests; legal obligation.
- To maintain and improve the Service (using technical, usage, and aggregated/anonymized data) — legitimate interests.
- To comply with law and respond to lawful requests — legal obligation.
- To process Customer Personal Data on our customers' instructions — processed on behalf of the customer as processor (the customer is responsible for the legal basis).
5. Aggregated and anonymized data; no sale; no third-party AI training
We may create and use aggregated, de-identified, or anonymized data (which does not identify any individual) to operate, analyze, and improve the Service. We do not sell personal data, and we do not use Customer Content to train third-party artificial-intelligence or machine-learning models.
6. How we share personal data
We share personal data only as follows:
- With sub-processors and service providers that help us run the Service, under contractual confidentiality and data-protection obligations (see Section 7).
- With Client Contacts you designate, to the extent you choose to share deliverables and collaborate with them.
- With Paddle, our Merchant of Record, to process payments and meet tax obligations.
- For legal reasons: to comply with law, enforce our Terms, protect our rights, safety, or property, or respond to lawful requests by public authorities.
- In a business transfer: in connection with a merger, acquisition, reorganization, financing, or sale of assets, or a transfer of the Service to a future legal entity, subject to this Privacy Policy.
We do not otherwise disclose your personal data to third parties for their own purposes.
7. Sub-processors
We use the following sub-processors to provide the Service. Each processes personal data on our behalf under appropriate data-protection terms:
| Sub-processor | Purpose | Primary data location |
|---|---|---|
| Supabase | Database, authentication, and file storage | United States (AWS, us-west-2) |
| Vercel | Application hosting, content delivery, and cookieless web analytics | United States / global edge |
| Resend | Transactional email delivery | United States |
| ScreenshotOne | Capturing screenshots of URLs you submit | International |
| Paddle | Payment processing and Merchant of Record (billing/tax) | International (incl. EU/UK/US) |
Payouts to the Service operator are handled by Payoneer; that process does not involve your personal data as a user of the Service. We may update this list as our providers change and will reflect changes here. Customers may request advance notice of new sub-processors as described in the DPA.
8. International data transfers
We and our sub-processors are located in, and process data in, various countries, including the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, Argentina, or another jurisdiction with data-transfer restrictions, your personal data may be transferred to and processed in countries that may not provide the same level of protection as your own. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms offered by our providers. You can request more information at privacy@upruve.com.
9. Data retention
We retain personal data for as long as needed to provide the Service and for the purposes described in this Policy. In general:
- Account and Team data is retained while the account/Team is active.
- After a Team is deleted or archived, we delete or anonymize associated personal data within up to 90 days, except for: (a) data we must retain to comply with legal, tax, or accounting obligations; (b) data needed to resolve disputes or enforce agreements; and (c) residual copies in routine, time-limited backups, which are overwritten on their normal cycle.
- Billing records are retained for the period required by applicable tax and accounting law.
For Customer Personal Data, retention and deletion also follow the customer's instructions and the DPA.
10. Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls and tenant isolation (row-level security in our database), authentication safeguards, restricted administrative access, and per-recipient, revocable Share Links. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials secure and for controlling the distribution of Share Links.
11. Your rights
Depending on your location, you may have rights regarding your personal data, including the rights to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority — in Argentina, the Agencia de Acceso a la Información Pública (AAIP); in the EEA/UK, your local data-protection authority.
To exercise rights regarding data for which we are the controller, contact privacy@upruve.com. We may need to verify your identity. We will respond within the timeframes required by applicable law.
If your request concerns Customer Personal Data (data uploaded by a customer about you), please contact the relevant customer, who is the controller; we will assist them as their processor.
You can unsubscribe from non-essential communications using the link in those emails or your settings. Some transactional messages (e.g., security or account-critical notices) are necessary to provide the Service.
12. Children
The Service is for business and professional use and is not directed to, or intended for, individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@upruve.com.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance.
14. Contact
Privacy questions and requests: privacy@upruve.com. General inquiries: info@upruve.com. Intellectual-property or abuse reports: abuse@upruve.com.
Part B — Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and Upruve ("Processor") and applies to the Processor's processing of Customer Personal Data on the Controller's behalf. If there is a conflict between this DPA and the rest of the Terms regarding the processing of Customer Personal Data, this DPA prevails.
1. Roles and scope. The Controller is the controller and Upruve is the processor of Customer Personal Data. Upruve processes Customer Personal Data only to provide the Service and on the Controller's documented instructions (including as set out in the Terms and through the Controller's use of the Service), unless required by law (in which case Upruve will, where permitted, inform the Controller).
2. Subject matter, duration, nature, and purpose. Subject matter: provision of the Upruve Service. Duration: for the term of the Terms plus the retention/deletion period in the Privacy Policy. Nature and purpose: hosting, storage, transmission, display, and processing of Customer Personal Data to enable collaboration, feedback, and approvals on deliverables, and related communications.
3. Categories of data subjects. The Controller's client-company contacts and their representatives (Client Contacts), and any individuals whose personal data the Controller includes in Customer Content.
4. Types of personal data. Names, email addresses, language preferences, roles; collaboration data (comments, feedback, approvals, selections, activity, timestamps); and any personal data contained in files, documents, URLs, or captures the Controller chooses to upload. The Controller must not upload special-category (sensitive) personal data unless it has ensured an appropriate legal basis and safeguards; the Service is not designed for that purpose.
5. Controller obligations. The Controller warrants that it has a valid legal basis and all required notices and consents to provide Customer Personal Data to Upruve and to have it processed as described, and that its instructions comply with applicable law.
6. Confidentiality. Upruve ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
7. Security. Upruve implements appropriate technical and organizational measures as described in Section 10 of the Privacy Policy, taking into account the state of the art, costs, and the nature and risks of the processing.
8. Sub-processors. The Controller provides general authorization for Upruve to engage the sub-processors listed in Section 7 of the Privacy Policy and others of similar nature. Upruve imposes data-protection obligations on its sub-processors substantially as protective as those in this DPA and remains responsible for their performance. Upruve will make available the current list of sub-processors and, on request to privacy@upruve.com, will provide a mechanism to be notified of changes; the Controller may object on reasonable data-protection grounds.
9. Assistance. Taking into account the nature of the processing, Upruve will provide reasonable assistance to the Controller, by appropriate measures, to: (a) respond to data-subject requests; (b) ensure security; (c) notify and handle personal-data breaches; and (d) carry out data-protection impact assessments and prior consultations, in each case insofar as applicable to the Service.
10. Personal-data breach. Upruve will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to help the Controller meet its obligations.
11. International transfers. To the extent Upruve transfers Customer Personal Data across borders, it relies on appropriate safeguards (such as the Standard Contractual Clauses and the UK Addendum) as described in Section 8 of the Privacy Policy.
12. Deletion and return. Upon termination of the Service, and at the Controller's choice, Upruve will delete or return Customer Personal Data and delete existing copies, subject to the retention period and legal obligations described in the Privacy Policy.
13. Audits. Upruve will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, scope, frequency, and notice limitations, and at the Controller's expense.
14. Liability. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.