Privacy Policy
Effective July 15, 2026 · Last updated July 10, 2026
This Privacy Policy explains how YupUp, Inc. (“YupUp,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when people visit our websites, create or use an account, communicate with us, receive YupUp messages, or interact with services we operate for business customers (“Merchants”).
1. Scope and roles
This Policy applies when YupUp determines the purposes and means of processing, including our website, merchant account administration, billing, product analytics, security, support, and YupUp’s own marketing. When a Merchant uses YupUp to process information about its customers, employees, prospects, loyalty members, or message recipients, the Merchant generally determines the purposes of processing and YupUp processes the information on the Merchant’s instructions. In that situation, the Merchant’s privacy notice also applies and privacy requests concerning Merchant-controlled information should ordinarily be directed to that Merchant.
2. Information we collect
- Identifiers and contact information — Examples: Name, business name, postal address, email, telephone number, account ID, device or online identifiers. Typical sources: You, Merchants, integrations, service providers.
- Account and authentication information — Examples: Login credentials in protected form, role, permissions, verification records, account preferences. Typical sources: You, administrators, identity providers.
- Commercial and transaction information — Examples: Plan, orders, invoices, payment status, partial card details or payment token, rewards activity, merchant products and services. Typical sources: You, Merchants, payment processors.
- Communications and content — Examples: Support requests, survey responses, campaign content, reviews, uploads, call or meeting notes where disclosed. Typical sources: You, Merchants, authorized users.
- Messaging information — Examples: Phone number, sender and campaign, consent evidence, message content or template, delivery status, opt-outs, HELP requests and complaints. Typical sources: You, Merchants, carriers and messaging providers.
- Internet and device activity — Examples: IP address, browser, device, pages viewed, clicks, referring URL, session and cookie identifiers, approximate location derived from IP. Typical sources: Your device, cookies, analytics and security tools.
- Integration information — Examples: Authorization tokens, account identifiers, permissions, synchronized records and metadata from services you connect. Typical sources: You and connected services.
- Inferences and analytics — Examples: Engagement, likely interests, merchant performance trends, risk or abuse indicators, product recommendations. Typical sources: Generated from the above information.
- Sensitive information, limited — Examples: Authentication secrets, precise location only if a feature requires and you enable it, and other sensitive data included by users. Typical sources: You or Merchants; do not submit unless required and authorized.
3. How we use information
- Provide, configure, personalize, maintain, and support the services; authenticate users and manage permissions.
- Process subscriptions, payments, invoices, rewards, communications, integrations, and requested transactions.
- Operate merchant-directed campaigns and messaging subject to the Merchant’s instructions and applicable consent.
- Measure performance, troubleshoot, improve usability, develop features, and create aggregated or deidentified insights.
- Protect accounts, detect fraud, spam, abuse and security incidents, enforce agreements, and maintain audit records.
- Communicate service updates, respond to requests, and send marketing where permitted and consented.
- Comply with law, legal process, tax and accounting duties, and protect rights, safety, and property.
- Use AI-assisted tools to generate or analyze content as described in the service and applicable AI terms. We do not use Customer Content to train a general-purpose model unless separately authorized.
4. How we disclose information
We may disclose information to service providers and subprocessors that support hosting, communications, payments, analytics, security, customer support, AI features, and professional services; to a Merchant or its authorized users; to connected services at your direction; in a corporate transaction; to comply with law or protect rights and safety; and with your consent. We require service providers to process information under appropriate contractual restrictions. We do not disclose mobile information, text-message opt-in data, or consent records to third parties for their own marketing or promotional purposes. This does not restrict disclosures to providers that help us deliver messages, prevent fraud, or comply with law.
4a. Current service providers and subprocessors
The core third-party providers that process personal information on YupUp’s behalf as of the effective date are listed below. YupUp maintains a current subprocessor register and updates it as providers change. YupUp does not currently use a third-party payment processor or an SMS/messaging provider; any such providers will be added here before those features go live.
- Amazon Web Services (AWS) — Cloud hosting and compute, managed database, file and image storage, receipt/expense data extraction (OCR), and content delivery. Processing location: United States (us-east-1).
- Sanity — Content management and delivery for website content and these legal policies.
- Mapbox — Interactive maps shown in the business directory.
- Google (Google Maps Platform / Places API) — Business directory data, place details, and photos used to build and enrich directory listings.
5. Cookies, analytics, targeted advertising and Global Privacy Control
We use necessary technologies for security and core functions and may use analytics, preference, and advertising technologies as described in the Cookie Policy. Where required, non-essential technologies are used only after consent. If our practices constitute “sale,” “sharing,” or targeted advertising under applicable law, eligible users may opt out through Your Privacy Choices. We intend to process recognized opt-out preference signals, such as Global Privacy Control, where legally required and technically applicable. Our response to browser Do Not Track signals is described in the Cookie Policy.
6. SMS and telephone communications
Marketing text consent is optional and is not a condition of purchase. Message frequency varies and message and data rates may apply. You may revoke consent through any reasonable method, including replying STOP or another recognized opt-out request, or contacting the sender. Merchant messages are governed by the named Merchant’s terms and privacy notice in addition to YupUp’s processing commitments. See the applicable SMS Terms for program details.
7. Retention
We retain personal information for the period reasonably necessary for the purposes described here, including providing services, maintaining consent and suppression evidence, resolving disputes, meeting contractual, legal, tax, accounting and security obligations, and enforcing agreements. Retention varies by record type. We delete or deidentify information when it is no longer required, subject to backups, legal holds, fraud prevention, and minimal suppression records. See the Data Retention & Deletion Notice for current target periods.
8. Security
We use administrative, technical, and physical safeguards designed for the nature of the information and our business. No system is completely secure. Users must protect credentials, use appropriate access controls, and promptly report suspected compromise to security@yupup.ai.
9. Your choices and privacy rights
- Update account information and communication preferences in the service where available.
- Opt out of marketing email using the unsubscribe link and marketing texts through STOP or another reasonable method.
- Manage non-essential cookies through our preference center.
- Depending on residence and applicable law, request access, correction, deletion, portability, or information about processing; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain sensitive-information uses; and appeal a denied request.
- Use an authorized agent where permitted. We may verify identity, authority, account control, and the scope of a request.
Submit requests through /privacy-choices or privacy@yupup.ai. If information is controlled by a Merchant, we may direct the request to that Merchant or assist the Merchant under our contract. We will not unlawfully discriminate for exercising applicable rights.
10. Children
The services are intended for businesses and adults and are not directed to children under 13. We do not knowingly collect personal information from a child under 13 without legally required parental consent. Contact us if you believe a child provided information improperly. Merchants must not configure YupUp to collect children’s information without written authorization and appropriate compliance measures.
11. International users
YupUp is initially designed for use in the United States. Information may be processed in the United States and other locations where our service providers operate. Merchants must not deploy the service in another country unless YupUp has approved the deployment and the parties have completed required terms and safeguards.
12. Changes
We may update this Policy. We will post the updated version and effective date and provide additional notice or obtain consent where required for a material change. Prior versions will be retained in our policy archive.
Contact
Privacy: privacy@yupup.ai | Legal: legal@yupup.ai | Support: support@yupup.ai | Security: security@yupup.ai. Mailing address: YupUp, Inc., 41111 Mission Blvd, Suite #121, Fremont, CA 94539.
