1 Scope
UpScaleUp.io (“we”, “our”, “us”) provides a WhatsApp marketing and messaging platform (the “Solution”) that enables businesses to manage communications with their customers. We are committed to protecting and respecting your privacy.
This Privacy Policy, together with our Terms of Service, describes how we collect, use, and safeguard information when you use the Solution. By using, registering, or signing up for the Solution, you accept this Privacy Policy. If you do not accept these terms, your use of the Solution may be restricted.
This policy covers two kinds of data:
- Account Data
- Information about you and your team as our customer (name, email, phone, billing, login, usage of the dashboard).
- End User Data / Client Data
- Information about your customers, leads, and other contacts that you import, collect, or message through the Solution (phone numbers, names, WhatsApp messages, consent records, custom fields).
For End User Data, you are the data fiduciary / controller and we act as a processor / service provider on your instructions. You must have a lawful basis (including a valid WhatsApp opt-in where required) before you store or message those people. We do not send Marketing Messages to your contacts for our own purposes.
If you connect Google services (such as Google Calendar), we also process Google user data as described in Section 8.
2 Changes to This Policy
We may update this Privacy Policy from time to time based on business, legal, or regulatory requirements. We will communicate significant changes to you where appropriate. Your continued use of the Solution after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
3 Personal Information We Collect
“Personal information” means information that can identify you, such as your name, email address, phone number, business details, messages sent or received through the platform, and information about products or services you are interested in.
Collection
We collect personal information when necessary to provide the Solution, complete transactions, or when you register or apply for our services.
Usage
We use this information to: (a) validate and process your use of the Solution; (b) handle orders and transactions; (c) improve the quality of the Solution; (d) provide support and resolve disputes; (e) detect and prevent fraud or abuse; (f) send marketing communications where you have consented; (g) comply with legal and regulatory requirements; and (h) as described at the time of collection.
Sharing
We may share personal information with affiliates and service providers who help us operate the Solution (for example hosting, email delivery, payment processing, and customer support). We may disclose information to third parties when required by law, to protect our rights or safety, or to address fraud or security issues. We do not sell your Account Data or your End User lists. Sharing of Google user data is limited as described in Section 8.
4 End User Data You Process Through the Solution
When you import contacts, run campaigns, use inbox, chatbots, or automations, you instruct us to process End User Data. Typical data includes phone numbers, names, message content and media, delivery status, group membership (including unsubscribers), custom fields, and opt-in or opt-out records you store.
You must only upload and message End Users who have opted in in line with WhatsApp’s Business Messaging Policy and applicable law (including India’s Digital Personal Data Protection Act, 2023 when in force, GDPR, or other local rules that apply to your audience). You must not upload purchased, scraped, or harvested lists. You must honor opt-out (including STOP and WhatsApp marketing opt-out) and keep records of consent.
We process End User Data only to provide the Solution to you, to maintain security and prevent abuse, to comply with law or Meta/WhatsApp requirements, and as otherwise described in our Terms. We do not use your End User Data to market our own products to those End Users.
If an End User contacts us about their data, we will typically direct them to you, because you decide why and how that data is collected. You are responsible for responding to access, correction, deletion, and withdrawal-of-consent requests from your End Users. We will assist where reasonably required and technically feasible.
5 Non-Personal Information
We collect diagnostic, technical, and usage data that does not personally identify you. This information is used to improve the Solution, provide updates and support, and verify compliance. We may share anonymized or aggregated non-personal information with partners and service providers.
6 Cookies
We use cookies (permanent and temporary) on our website and platform. Information collected by cookies is treated as non-personal information unless combined with personal information or where local law treats identifiers like IP address as personal data. You can control cookies through your browser settings.
7 WhatsApp Cloud API & Data Residence
Our Solution uses the WhatsApp Business Platform (Cloud API), a product of Meta. When you use WhatsApp messaging through UpScaleUp.io:
- Data shared in relation to WhatsApp messaging may reside on infrastructure operated by Meta (Cloud API), including data centers in regions such as North America and the European Union.
- We do not offer data localization for WhatsApp infrastructure data; such data is processed in accordance with Meta’s infrastructure and policies.
- Your use of WhatsApp features is also subject to WhatsApp’s Privacy Policy and WhatsApp’s Terms of Service.
8 Google APIs & Google User Data
UpScaleUp.io may offer optional integrations that use Google APIs (including Google Calendar via OAuth). This section explains how we access, use, store, share, protect, and delete Google user data. It applies to Google user data we receive when you connect a Google account to the Solution.
Google user data we access
Depending on the integration you enable and the permissions you grant on Google’s consent screen, we may access:
- Basic Google account profile information used to identify the connected account (such as your Google account email address, and related OpenID profile identifiers).
- Google Calendar event data needed to create, update, read, and delete calendar events that you choose to sync (for example bookings, appointments, and contact reminders you manage in UpScaleUp.io).
- OAuth tokens (access and refresh tokens) that allow the Solution to call Google APIs on your behalf until you disconnect.
We request only the Google OAuth scopes required for the features you use (for Google Calendar event sync, this includes event management scopes together with basic sign-in identity scopes). We do not request access to Google data unrelated to those features.
How we use Google user data
We use Google user data solely to provide and improve the user-facing features you enable, including:
- Connecting your Google account and showing which account is linked.
- Syncing selected UpScaleUp.io bookings and reminders to your Google Calendar (create, update, and delete corresponding events).
- Maintaining the connection (token refresh), troubleshooting sync errors, and security monitoring related to the integration.
We do not use Google user data for targeted advertising, personalized or interest-based ads, selling to data brokers or information resellers, credit-worthiness or lending decisions, building unrelated databases for resale, or training generalized / non-personalized AI or machine-learning models. Google user data is used only to provide or improve the Solution’s Google-connected features.
Limited Use compliance
The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
UpScaleUp.io may offer separate AI-assisted features (for example an AI chatbot) that use third-party AI inference providers. Those AI features operate on non-Google product data (such as WhatsApp conversation context configured by the customer). We do not transfer Google Workspace or Google Photos user data—raw, aggregated, anonymized, or derived—to any third-party AI/ML service, and we do not use Google user data to create, train, or improve foundational or generalized AI/ML models.
Sharing, transfer, and disclosure of Google user data
We do not sell Google user data. We do not transfer or disclose Google user data to third parties for advertising, data brokerage, credit scoring, lending, or training generalized AI/ML models.
We may share or disclose Google user data only as follows:
- With Google, when we call Google APIs to perform the sync actions you requested (create/update/delete calendar events).
- With infrastructure and security service providers that host or operate the Solution (for example cloud hosting), solely to store and process data needed to run the integration, under confidentiality and security obligations.
- When required by law, legal process, or to protect the rights, safety, or security of UpScaleUp.io, our users, or the public.
Other than the limited cases above, we do not transfer or disclose Google user data to third parties for purposes unrelated to providing or improving the Google-connected features of the Solution.
Storage and security of Google user data
Security procedures are in place to protect the confidentiality of Google user data. OAuth tokens are stored encrypted at rest. Data in transit is protected using encryption (such as TLS/SSL). Access to production systems is restricted to authorized personnel who need it to operate or support the Solution.
Retention and deletion of Google user data
We retain Google account connection details, encrypted tokens, and event-link identifiers for as long as the integration remains connected and needed to provide the sync feature, or for a longer period if required or permitted by law (for example security logs or legal claims).
You may disconnect Google Calendar at any time in the Solution’s Integrations settings. When you disconnect (or when we delete the integration at your request), we delete stored Google OAuth tokens and local Google Calendar event-link records associated with that connection in the ordinary course. Events already created in your Google Calendar remain in Google Calendar unless you delete them there. You may also revoke UpScaleUp.io’s access from your Google Account permissions page. To request deletion of remaining Account Data related to a Google connection, contact care@upscaleup.io.
Your choices
Google Calendar sync is optional. You control whether to connect, which sync options are enabled, and when to disconnect. Revoking access in Google Account settings will stop further API access; you should also disconnect in UpScaleUp.io so we can clear stored tokens.
9 Third-Party Services
The Solution may include links to or integrations with third-party services (including WhatsApp, Google, and other platforms). Those services have their own privacy policies, which we do not control. Once you leave our systems or use third-party services, their policies apply. We are not responsible for the privacy practices or content of third-party services. Google’s use of information received from Google APIs is also subject to Google’s policies, including the Google API Services User Data Policy (including Limited Use requirements).
10 Access, Correction, and Deletion
You are responsible for ensuring the information you provide is accurate and up to date. You may request access, correction, or deletion of your Account Data. Note that deletion or withdrawal of consent may limit your access to the Solution or certain features. We may retain data where required by law, for legal proceedings, security, billing, or where deletion is technically impractical (for example, backups for a limited period).
End Users should send rights requests to the business that messaged them (you). If you delete contacts or close your account, we will delete or de-identify associated End User Data in the ordinary course, subject to legal retention and Meta’s own retention of messages processed on Cloud API.
For Google user data retention and deletion, see Section 8.
11 Data Security
We use industry-standard measures to protect your personal information, including encryption and secure networks. Sensitive data is encrypted (e.g., via SSL). OAuth credentials for connected services such as Google are encrypted at rest. We do not store full payment card details on our servers; payments are processed through secure payment providers.
12 Queries and Complaints
If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us at care@upscaleup.io or use the contact details on our website.