1. Who this policy covers
Uptify operates uptify.ai. This policy covers information about visitors, Buyer and Builder representatives and other people who contact us. It describes the Platform, not a Builder's independently operated Product or your AI agent provider. Contact our privacy team at legal@uptify.ai.
2. Information and sources
You provide identifiers and business contact details such as name, email, dealer name, city, state, job title and systems; profile and employer declarations; listing files and media; pilot goals and outcomes; orders, licenses, support requests, messages, reviews, reports and appeals. Builders supply payout and tax information through the relevant payment onboarding process. We receive transaction status and connected-account references from payment providers.
We also collect sign-in attempt information including IP address and timestamps; session and device request information; first-party listing view counts; download and license events; and agent client, scope, grant, token-prefix and activity records. Information comes from you, your authorized users or agents, other transaction participants, our service providers and use of the Platform. Public listings and reviews are visible to visitors.
Do not submit dealership customer records, credit applications, government identifiers or sensitive personal data in listings or messages. A Product may separately process customer data only within its disclosed, authorized scope. Contact us if prohibited data was submitted so we can assess removal.
3. How we use information
We use information to authenticate accounts, operate purchases and pilots, deliver licenses and files, coordinate onboarding and support, process payments and refunds, verify Builder identity privately, moderate content and messages, investigate rights and safety complaints, prevent fraud, maintain security and comply with tax and legal requirements. We use aggregate first-party view counts to understand listing interest. Transactional notices concern your account or orders. Marketing email requires opt-in and can be stopped using its unsubscribe control.
Account credentials and message contents may be sensitive personal information under state law. We use them for the requested service, security and other legally permitted operational purposes, not to infer sensitive characteristics. We do not use the current Platform for targeted advertising or automated decisions that produce legal or similarly significant effects; automated moderation may flag or restrict activity, with a human appeal route.
4. Codes, links and agent credentials
Email sign-in uses a six-digit code and a confirmation link. They expire after 15 minutes, are single-use and share the same verification record: using either invalidates both. A new request replaces older unused codes, and attempts are limited. The verification table stores keyed hashes of codes and link tokens, with request metadata. The email provider necessarily processes the code and link for delivery. The legacy email-link route keeps a queued message containing its link; development diagnostics can also contain test credentials.
OAuth authorization codes, access tokens, refresh tokens and personal agent tokens are stored as hashes for verification, with associated scopes, expiry and grant information. The full credential is supplied when issued and must be protected by you and your agent. Ordinary web sessions use server-side session records and a browser session cookie. Revoking an agent grant stops future authorized access but does not undo completed actions or erase information already sent to the agent.
7. Retention and security
We retain account and profile information while needed to operate the account; orders, acceptance records, payment and tax records as needed for accounting, legal obligations and disputes; and messages, moderation, security and download records as needed for support, safety, rights enforcement and claims. Expiration stops a credential from working but does not itself delete its verification or audit record. We assess deletion requests against these purposes and legal requirements and remove or deidentify information no longer needed. Backups may retain deleted information until their normal replacement and are restricted from ordinary use.
We use access controls, scoped agent permissions, hashed agent credentials and sign-in verification values, and protected download links. No service can promise perfect security. Protect your email and connected agents, limit permissions and report suspected compromise promptly. Information is processed in the United States and may be processed where our service providers operate, subject to applicable safeguards.
8. California and other US privacy rights
Depending on applicable law, you may request access to or a copy of your personal information, correction, deletion and information about its collection and disclosure. You may also have rights to opt out of sale, targeted-advertising sharing or certain profiling, and to limit specified uses of sensitive information. We do not conduct those sale or advertising activities or use sensitive information beyond the operational purposes described above. We do not knowingly sell or share minors' information. We will not discriminate against you for exercising a protected right.
Send requests to legal@uptify.ai with your account email and the right you wish to exercise. An authorized agent may act with proof of authority. We verify identity using proportionate account information, not a demand for unnecessary sensitive documents. We respond within applicable statutory periods, explain any permitted denial or extension and preserve required exceptions. To appeal a denial where an appeal right applies, reply with "Privacy appeal"; we will review it and explain how to contact your state regulator if the appeal is denied. California residents may also request information about any disclosure for another business's direct marketing; we do not make such disclosures.
During the preceding 12 months, the categories collected and disclosed for business purposes are the identifiers, commercial records, internet activity, professional information and submitted content described above, to the recipient categories described above. We do not buy data broker lists or use information to infer sensitive personal characteristics.
9. Children and changes
The Platform is for business representatives age 18 or older. We do not knowingly collect information from children under 13. If you believe a child provided personal information, contact us for investigation and deletion as required. We post policy changes with a new effective date and give notice of material changes before they apply. A new use requiring consent will not begin without that consent.
Contact
Send legal notices and questions about this document to Uptify at legal@uptify.ai. Identify your account and the relevant listing or order. Do not include dealership customer records or account credentials.