Privacy Policy

Last updated: August 19, 2026

Effective: September 18, 2026

These revisions take effect September 18, 2026 for existing users.

Until then, the previous version of these Policy — dated April 27, 2026 — remains the version in effect. If you would like a copy of that prior version, email [email protected].

Overview

This Privacy Policy describes how UppaGo ("we," "us," "our") collects, uses, shares, and protects information when you use our platform and services (the "Service"). We are committed to handling your data responsibly, transparently, and only in ways that serve your use of the Service.

This policy is incorporated by reference into our Terms of Service. By using the Service, you agree to the data practices described here.

We may update this policy from time to time. Material changes will be communicated via email or in-product notification at least thirty (30) days before they take effect.

Information We Collect

We collect information you provide directly when you use the Service:

  • Account information — name, email address, profile picture
  • Organization information — company name, industry, size, address, contact details
  • Customer Content — invoices, receipts, CSV imports, vendor records, transactions, bank-feed data, notes, corrections, and any other documents or data you upload to or generate within the Service
  • Communications — support requests, feedback, survey responses, and any other messages you send to us
  • Payment information — handled entirely by Stripe; we do not store card numbers, bank account details, or billing addresses on our systems (we receive only a Stripe customer identifier and metadata about your subscription state)

We also collect certain information automatically:

  • Usage data — pages visited, features used, actions taken, processing timestamps
  • Device and browser information — browser type and version, operating system, screen resolution, language preferences
  • Log data — IP address, request timestamps, request paths, response codes, error traces (used for debugging, security, and service improvement)
  • Cookies and similar technologies — authentication tokens (required), preference storage (e.g., persisted view modes, dark-mode preference), and minimal analytics for product improvement. We do not use third-party advertising trackers.

How We Use Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process Customer Content through OCR, AI extraction, and intelligence pipelines you have requested
  • Manage your account, subscription, and billing
  • Send service-related communications (transactional emails, security alerts, billing notices, support replies)
  • Send product communications you have opted into (digests, notifications, weekly summaries)
  • Detect, prevent, and respond to fraud, abuse, security incidents, and policy violations
  • Aggregate anonymized usage data to debug, optimize, and improve the Service
  • Comply with legal obligations and enforce our agreements

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.

Artificial Intelligence and Your Data

UppaGo uses AI models — including third-party large-language models and embedding models — to extract, classify, and analyze your Customer Content. Our policies on AI and your data:

  • We do not train AI models on your Customer Content. Your documents, transactions, vendor records, and any data you submit to UppaGo are not used to train, fine-tune, retrain, or otherwise improve any AI model of ours. We operate no training pipeline over Customer Content.
  • Third-party AI processing. Document extraction, embedding generation and similar processing tasks are performed by a third-party AI provider, which receives the Customer Content it needs in order to perform them. That provider's own data-processing terms govern what it may do with that data. Contact [email protected] for the current position on a provider's training and retention commitments.
  • Tally's intelligence is per-tenant by design. The vendor profiles, baselines, autonomy levels, and reviewer memory that personalize Tally's suggestions are computed exclusively from your own Customer Content and are scoped to your account.
  • Cross-tenant aggregation requires explicit business reasons. Where firm-level intelligence is offered, it is available only to a bookkeeping firm for the client workspaces it has been granted access to, aggregation is performed only at the firm level, and only in aggregate form (e.g., counts, percentages, distributions) — never row-level data sharing across distinct Customers. Who pays for a workspace is a billing arrangement and is not what grants this access.
  • Embeddings stay in our infrastructure. Vector embeddings used for semantic search (Ask Tally) are stored in your tenant-scoped database row and never shared with other Customers or external services.

How We Share Information

We share information only as necessary to operate the Service or as required by law:

  • Service providers (sub-processors) — trusted vendors who process data on our behalf to operate the Service across cloud hosting and infrastructure, database and storage, authentication, AI processing, payment processing, transactional email delivery, bank-account connectivity, and accounting-system integrations. We select sub-processors on their published security and confidentiality terms. If you need to know which sub-processors are involved in handling your data, write to us at [email protected].
  • Bookkeepers and team members — as configured by your access settings. You control who has what level of access (view, review, or full) to your account's Customer Content.
  • Legal compliance and safety — to law enforcement or regulators when compelled by valid legal process, to comply with applicable law, or to protect the rights, safety, and property of UppaGo, our users, or third parties.
  • Business transactions — in connection with a merger, acquisition, financing, or sale of assets, your data may be transferred to the successor entity, subject to terms at least as protective as this policy.

Bank Feed Data and Plaid

When you use the bank-feed feature, we connect to your bank through Plaid's secure infrastructure. Plaid retrieves transaction data on your behalf using credentials you provide directly to Plaid (we do not see your bank login credentials).

Bank-feed transactions imported into UppaGo are stored in your tenant-scoped database and used for reconciliation matching, vendor recognition, cash-flow visibility, and reporting. Per our Terms of Service, bank-feed transactions are not used to train Tally's autonomy engine.

Plaid's collection and handling of your bank credentials and transaction data is governed by Plaid's end-user privacy policy, which you accept when you first connect a bank account through Plaid Link.

Data Retention

We retain your account information and Customer Content for as long as your account is active. If you cancel your Subscription or close your account:

  • Customer Content is retained while your account is active. You can request deletion of your account and Customer Content by emailing [email protected]. Each request is reviewed and approved by UppaGo’s founders and processed manually.
  • When we delete an account at your request the following is removed or anonymized: documents and their extracted data, vendor records, bank-feed transactions, learned approval patterns specific to your workspace, and your profile fields.
  • Our deletion workflow includes QuickBooks and Plaid provider-revocation steps. Provider revocation, hosted-record removal, and account anonymization run as an audited deletion workflow once a request is approved. Approval requires a second admin’s co-approval and explicit founder authorization; live customer deletions are not initiated automatically. We have verified the audited deletion workflow with automated tests, including adversarial cases against a real database. It has deliberately not been executed against production customer data.
  • Before a deletion can be executed, any active paid subscription must be canceled. If you have a paid plan, please cancel via your Stripe Customer Portal before submitting a deletion request — otherwise the request is paused at approval until billing is in a canceled or free state. Subscription cancellation alone does not delete your data; deletion is a separate request.
  • Some records are retained by design, even after deletion. Audit records of actions taken on an account are retained, so that a faithful record of what happened survives for security and integrity purposes. 1099 forms generated through UppaGo are retained, with the recipient’s name, tax identification number and address redacted at the time of deletion. Stripe retains its own billing records independently of UppaGo; we sever UppaGo’s local link to the Stripe customer record during approved deletion, and we do not delete records inside Stripe. We do not publish a retention period for these records.
  • A few things sit outside what we can delete on our end: files you have already downloaded — CSVs, PDFs, reports — live on your own devices and cloud-storage accounts. Deleting your UppaGo account does not reach those copies; please remove them from your devices yourself. See our Data Security page for the latest on what we delete and what is retained.
  • Aggregate usage statistics derived from anonymized data may be retained indefinitely.

Security

We use industry-standard administrative, technical, and operational safeguards to protect your data:

  • Encryption in transit — all communication between your browser and the Service uses TLS (HTTPS)
  • Encryption at rest — Customer Content stored in our database and object-storage layer is encrypted at rest by our infrastructure providers
  • Credential handling — authentication is operated by our identity provider, which owns sign-in credentials; UppaGo never receives or stores your password. Third-party OAuth tokens (for example, Plaid and QuickBooks Online) are encrypted at the application layer using AES-256-GCM before being persisted
  • Tenant isolation — every database query that touches Customer Content is scoped to your tenant identifier at the application layer, through scoped data services, explicit tenant filters, and CI tenant-scope contracts, with audit and human-review controls on sensitive actions. UppaGo runs on DigitalOcean Managed Postgres; there is no anonymous database access path
  • Limited internal access — access to production systems is restricted to authorized personnel who are subject to confidentiality obligations
  • Ongoing review — we review our codebase, third-party dependencies, and infrastructure configuration on an ongoing basis as part of our development process

No system is perfectly secure, and we make no guarantee that the safeguards above will prevent every conceivable incident. If you become aware of any actual or suspected security incident affecting your account, contact us immediately at [email protected].

Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information. We honor these rights regardless of jurisdiction where reasonably possible:

  • Access — request a copy of the personal information we hold about you
  • Correction — update or correct inaccurate or incomplete information through your account settings or by contacting us
  • Deletion — request deletion of your Customer Content and account, subject to retention obligations described above
  • Portability — export your data in a machine-readable format (CSV download is available in-product; bulk export by request)
  • Objection — object to specific processing activities, where applicable
  • Withdrawal of consent — withdraw consent for processing that requires consent (e.g., opt out of non-essential email communications via your notification preferences)
  • Complaint — lodge a complaint with your local data protection authority

To exercise these rights, contact us at [email protected]. We will respond to verified requests within thirty (30) days.

Cookies and Tracking

We use a minimal set of cookies and local-storage entries that are essential to the Service:

  • Authentication tokens (required for sign-in)
  • User-preference storage (e.g., persisted view modes, dark-mode preference, default landing tab)
  • CSRF protection tokens
  • Anonymous analytics for product improvement

We do not use third-party advertising trackers, retargeting pixels, or behavioral advertising identifiers. We do not sell or share data for advertising purposes.

International Data Transfers

Your information may be processed and stored in any country where UppaGo or our service providers operate, including (without limitation) Canada, the United States, and the European Union. By using the Service, you acknowledge that your information may be transferred to and processed in countries with data-protection laws different from those of your country of residence.

Where required by law (for example, for transfers of personal data subject to European data-protection regulations), we rely on appropriate safeguards such as Standard Contractual Clauses with our sub-processors.

Children's Privacy

The Service is intended for use by businesses and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact us at [email protected] and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service offerings, or applicable law. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will provide at least thirty (30) days' advance notice via email or in-product notification.

Contact

If you have questions about this Privacy Policy or our data practices, contact us: