Privacy Policy

Last Updated: January 2026

1. Introduction

UpBiz ("we", "us", "our", or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our workflow automation platform.

Contact: support@upbiz.com

2. Information We Collect

2.1 Information You Provide Directly

Account Registration

  • Full name
  • Email address

Payment Information

  • Last 4 digits of credit/debit cards (stored in our database)
  • Card expiry date
  • Subscription plan information

Note: Full card details are processed and stored securely by Stripe, our payment processor. We do NOT store complete card numbers.

Workflow Data

  • Workflow configurations and designs
  • Workflow versions and history
  • Workflow notes and descriptions
  • Nodes, edges, and workflow logic
  • Any data you input into your workflows

Sharing & Collaboration

When you share workflows, we collect:

  • Sharing preferences and settings
  • Lead capture information (if enabled): Name, email, company, use case

Communication

2.2 Information Collected Automatically

Better Auth

  • Session tokens for authentication
  • Login timestamps
  • Authentication method used (email/password, OAuth, etc.)

AWS Services

  • Server logs for hosting and performance
  • Email sending records (via AWS SES)

3. How We Use Your Information

We use your information for:

  • Service Delivery: Creating and managing your account, storing workflows, handling subscriptions
  • Authentication: Logging you in securely via Better Auth
  • Payments: Processing subscription payments through Stripe
  • Communication: Sending transactional emails (account confirmation, password reset, subscription updates)
  • Service Improvement: Analyzing how features are used (not tied to individual users currently)
  • Legal Compliance: Meeting legal and regulatory obligations
  • Future Marketing: May send feature updates or service announcements (you can opt-out anytime)

4. Third-Party Services

We use the following third-party services that may collect and process your data:

4.1 Payment Processing

Stripe: Processes credit card payments. Stores full card details securely.

Stripe Privacy Policy →

4.2 Authentication

Better Auth: Manages user authentication and sessions.

Better Auth Documentation →

4.3 Cloud Infrastructure

Amazon Web Services (AWS):

  • EC2: Hosts our application servers
  • SES: Sends transactional emails
AWS Privacy Policy →

5. Data Storage & Retention

During Active Account

All your data (workflows, settings, preferences) is stored indefinitely while your account is active

After Account Cancellation

Your workflows and associated data remain in our database (data is NOT automatically deleted). You can contact support@upbiz.com to request data deletion

Why we keep data

  • To maintain workflow versions and history
  • To preserve shared workflow links
  • To comply with tax and billing requirements

6. Cookies & Tracking

Cookies Used

1. Session Cookies (Necessary)

  • Used by Better Auth for authentication
  • Required to keep you logged in
  • Deleted when you log out

Currently NOT Used

  • Google Analytics
  • Marketing/advertising cookies
  • Facebook Pixel
  • Third-party tracking cookies

Disabling Cookies

You can disable cookies in your browser settings. However, this may prevent you from using UpBiz properly, as authentication requires session cookies.

7. Data Security

We implement security measures to protect your information:

HTTPS encryption for all data in transit
Stripe's PCI-DSS Level 1 compliance for payment data
Password encryption by Better Auth
Only last 4 digits of cards stored (not full numbers)

However, no security system is 100% secure. We cannot guarantee absolute security.

8. Data Breach Notification

In the event of a data breach that compromises personal information, we will:

  1. 1.Notify affected users within 30 days of discovery
  2. 2.Provide notification via email to the address on file
  3. 3.Include information about the breach and steps to take
  4. 4.Comply with applicable state/federal regulations

9. Your Rights

You have the right to:

Access

Request all personal data we hold about you

Export

Download your workflows in JSON format

Account Cancellation

Cancel your subscription anytime

Data Deletion

Request account and workflow deletion

To exercise these rights, email: support@upbiz.com

10. California Users (CCPA Rights)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

Right to Know: What personal data is collected
Right to Delete: Request deletion of personal data
Right to Non-Discrimination: No discrimination for exercising your rights

To exercise California rights, email: support@upbiz.com

11. Children's Privacy

UpBiz is not intended for users under 18 years old. We do not knowingly collect information from children. If we become aware a user is under 18, we will delete their account.

12. International Users

If you are outside the United States, your data may be transferred to, processed, and stored in the United States. By using UpBiz, you consent to this transfer.

For EU users: We are working toward GDPR compliance. Data transfers are necessary to provide our service.

13. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of UpBiz constitutes acceptance of changes.

14. Contact Us

For privacy questions or concerns:

Email: support@upbiz.com

By using UpBiz, you acknowledge you have read and agree to this Privacy Policy.