Uptillo

Privacy Policy

Last updated:

Introduction

This Privacy Policy describes how Uptillo, operated by Olevis LLC ("we", "our", "us", or "Company"), collects, uses, discloses, and safeguards your personal information when you use our invoice payment reminder service (the "Service").

Legal Entity Information

Business Name: Olevis LLC

Business Address: 30 N Gould St Ste N, Sheridan, WY 82801

Contact Email: [email protected]

Support Email: [email protected]

Effective Date:

1. Information We Collect

1.1 Categories of Personal Information Collected

We collect the following categories of personal information:

Account Data

Name, email address, business name, password (hashed), account preferences

Source: Directly from you during registration

Billing Data

Payment card details, billing address, transaction history, subscription plan

Source: Directly from you; payment details processed by Stripe (not stored by us)

Client and Invoice Data

Client names, email addresses, invoice numbers, amounts, due dates, payment status, custom notes

Source: Directly from you when you add clients and invoices

Email Configuration Data

Sender email, reply-to address, business information for email templates

Source: Directly from you in settings

Usage and Device Data

IP address, browser type, operating system, pages visited, time spent, features used, login times

Source: Automatically collected via cookies and log files

Email Engagement Data

Email opens, clicks, delivery status, bounce information

Source: Automatically collected via email service provider

Communications Data

Support messages, feedback, correspondence with us

Source: Directly from you when you contact support

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain our invoice reminder service
  • Email Sending: To send payment reminder emails on your behalf to your clients
  • Account Management: To manage your account, process payments, and provide customer support
  • Analytics: To understand how users interact with our Service and improve functionality
  • Communication: To send you service updates, security alerts, and administrative messages
  • Compliance: To comply with legal obligations and enforce our Terms of Service
  • Fraud Prevention: To detect, prevent, and address technical issues and security threats

3. Data Sharing and Disclosure

We may share your information in the following circumstances:

3.1 Service Providers

We share data with trusted third-party service providers who help us operate our Service:

  • Stripe: Payment processing (subject to Stripe's Privacy Policy)
  • Email Providers: Resend or Postmark for email delivery
  • Cloud Hosting: Database and application hosting providers

3.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental request, or if we believe such action is necessary to comply with legal obligations, protect our rights, or prevent fraud.

3.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

3.4 Subprocessors and Third-Party Services

We engage the following third-party subprocessors to help us provide and improve our Service:

SubprocessorPurposeLocationData Shared
StripePayment processingUSABilling data, payment information
Resend / PostmarkEmail deliveryUSARecipient emails, message content
Hetzner Online GmbHApplication & database hostingUSA (Ashburn, Virginia)All service data

Note: We regularly review our subprocessors and may update this list. For B2B customers, we will provide 30 days' notice of new subprocessors via email.

All subprocessors are contractually required to maintain appropriate security measures and use data only for the purposes we specify. Where required, we have Data Processing Agreements in place.

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption: All data transmitted over the internet is encrypted using SSL/TLS
  • Password Security: Passwords are hashed using bcrypt with strong salt
  • Access Control: Strict access controls limit who can access your data
  • Regular Audits: We conduct regular security assessments and updates
  • Secure Infrastructure: Our servers are hosted in secure, SOC 2 compliant data centers

However, no method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

5. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

  • Active Accounts: Data is retained while your account is active
  • Deleted Accounts: Most data is deleted within 30 days of account deletion
  • Email Logs: Retained for 90 days for deliverability tracking
  • Billing Records: Retained for 7 years for tax and accounting purposes
  • Backups: Data in backups may persist for up to 90 days

6. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Data Portability: Request a copy of your data in a machine-readable format
  • Objection: Object to processing of your personal information
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw Consent: Withdraw consent where processing is based on consent

To exercise these rights, please contact us at [email protected]

7. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on the following legal grounds:

  • Contract: Processing necessary to perform our contract with you (account provisioning, service delivery)
  • Consent: You have given consent for specific processing activities (e.g., marketing emails)
  • Legitimate Interests: Processing necessary for our legitimate business interests (fraud prevention, analytics, security)
  • Legal Obligation: Processing necessary to comply with legal requirements (tax, accounting)

International Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs with our subprocessors
  • Adequacy Decisions: We rely on adequacy decisions where applicable
  • Data Processing Agreements: Available for B2B customers upon request

Your GDPR Rights

Under GDPR, you have additional rights:

  • Right to Lodge a Complaint: You may file a complaint with your local supervisory authority
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Restriction: Request restriction of processing in certain circumstances

EU Representative: [If applicable, list EU representative details here. If not required, state: "We do not currently have an EU representative as we are not established in the EU."]

7A. US Privacy Rights (California and Other States)

⚖️ Your Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or other US states with comprehensive privacy laws, you may have specific rights regarding your personal information.

California Privacy Rights (CCPA/CPRA)

Categories of Personal Information We Collect

CategoryExamplesCollected
IdentifiersName, email, IP address✅ Yes
Commercial InformationSubscription plan, transaction history✅ Yes
Internet ActivityPages visited, features used, email opens✅ Yes
Professional InformationBusiness name, role✅ Yes
Sensitive Personal InformationAccount credentials (password hashed)✅ Yes (limited)

Your California Rights

  • Right to Know: Request disclosure of personal information we have collected about you in the past 12 months
  • Right to Delete: Request deletion of your personal information (subject to certain exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information in the traditional sense. However, some analytics/advertising activities may constitute "sharing" under CCPA
  • Right to Limit Use of Sensitive Personal Information: We only use sensitive PI for permitted business purposes
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Do We "Sell" or "Share" Your Personal Information?

Sale: We do not sell your personal information for monetary consideration.

Sharing for Targeted Advertising: We may share certain usage data with analytics providers (e.g., Google Analytics) which could constitute "sharing" under CCPA's broad definition. You can opt-out of this sharing through cookie preferences or by contacting us.

How to Exercise Your Rights

Submit a Request:

Email: [email protected]

Subject Line: "California Privacy Rights Request"

Include: Your name, email, account details, and specific request type

Verification Process: To protect your privacy, we will verify your identity before processing your request. We may ask you to verify the email address associated with your account or provide additional identifying information.

Authorized Agent: You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization, and we may also require you to verify your identity directly.

Response Time: We will respond to verifiable requests within 45 days. If we need more time (up to 90 days total), we will notify you.

Other State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights. Please use the contact method above to exercise these rights.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service:

  • Essential Cookies: Required for authentication and security
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand how users interact with our Service

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

9. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

10. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

11. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your country. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

13. Contact Us & Legal Notices

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Uptillo - Data Protection & Privacy

Legal Entity: Olevis LLC

Business Address: 30 N Gould St Ste N, Sheridan, WY 82801

Privacy Inquiries: [email protected]

General Support: [email protected]

Data Subject Requests: [email protected] (Subject: "Privacy Rights Request")

Website: https://uptillo.com

Response Time: We aim to respond to all privacy inquiries within 5 business days and to formal data subject requests within the timeframes required by applicable law (typically 30-45 days).

For B2B Customers:

If you need a Data Processing Agreement (DPA) or have questions about our data processing practices as they relate to your business, please contact us at [email protected] with "DPA Request" in the subject line.