Privacy Policy
Last updated · September 26, 2026
This Privacy Policy explains how UpgradIQ, Inc. (a Delaware corporation, “we,” “us,” and “our”), which owns and operates UpgradIQ at upgradiq.com, collects, uses, and protects personal information when you visit the site, use our products, purchase a course or digital product, or otherwise interact with our services.
1. Information we collect
1a. Site visitors
When you visit the site we collect limited technical information automatically, including IP address (anonymized before storage), user-agent string, referring URL, and interaction events via PostHog (analytics) and Sentry (error monitoring). Neither service receives your full IP address.
1b. Contact form submissions
If you submit the contact form, we store your name, email address, message content, and the timestamp of submission.
1c. Orders and billing
When you purchase a course, program, or digital product, we collect your name, email address, and order details necessary to grant access and deliver the service. Payment is processed by Stripe. If you instead pay by bank transfer, we store the receipt you upload and the amount and reference of that transfer, so the payment can be matched and confirmed. The receipt is held in private storage that only an administrator can read. Card payments: we do not store card numbers or payment instrument details on our servers. Stripe holds and processes all payment card data and is subject to PCI-DSS compliance obligations. We receive and store a Stripe customer ID, payment confirmation, and order metadata (item type, amount, date) for accounting and service delivery purposes. Where you hold a membership we also store its plan, its status and the date the current period ends, because that date is what grants access to everything on the site.
1c(ii). People added to a team membership
A team membership lets the account holder give places to other people by entering their email address. That address reaches us from the account holder rather than from the person it belongs to, so we use it for one thing only: creating that person’s own account and sending them the link to set their password. We do not add them to any mailing list, and the account holder can remove a place at any time, which ends that person’s access. Anyone added this way can ask us to delete their account by writing to adam@upgradiq.com, whether or not the account holder asks first.
1c(iii). Your business and its numbers
Members can describe their business (its name, website, type, stage, currency and a goal) and enter figures for it month by month, such as visitors, customers, revenue, marketing spend and margin. Members can also save their inputs in the site’s tools. We use this only to show those figures and the metrics worked out from them back to the member, and to tailor the tools and recommendations they see. We do not sell it, share it, show it to other members, or use it for advertising. If we ever publish benchmarks built from members’ figures, they will only ever be aggregates of many businesses that cannot identify any one of them, and only with the member’s consent. It is included when you export your data and deleted when you delete your account.
Once a month, and whenever you ask, we read the public pages, files and email records of the website you give for your business, to run the site checks and show you the results. Adam AI, our assistant, answers from our own knowledge files. To write the answer, the question, the passages it is answered from and, for a member, the figures of the business it is about are sent to Groq, our AI provider. We keep a count of the questions a member asks. When a question cannot be answered from our files, we keep the text of the question, without your name, email, account or IP address, so we can add the answer; please do not put personal details in a question.
1d. Connected Google accounts (Analytics & Search Console)
If you choose to connect your Google account, we request read-only access to your Google Analytics (GA4) and Google Search Console data (OAuth scopes analytics.readonly and webmasters.readonly). We use this data only to display your own metrics back to you inside your dashboard: we store monthly totals only (users, sessions, your top traffic sources, and search clicks, impressions and average position) for each workspace, and your monthly visitors open pre-filled from them. No page or search query is stored. We read only the property or site you select for each workspace. We never modify anything in your Google account, never use this data for advertising, never use it to train any AI model, and never sell it.
Who we share Google user data with. We do not share, transfer or disclose data received from Google APIs to anyone, except the following service providers, only to run the features you use, and only under contract:
- Supabase stores the monthly totals and the OAuth tokens (database, EU region).
- Vercel hosts the application that reads and shows them.
- Groq receives your saved monthly figures, which may include a visitor count you accepted from Google Analytics, only when you ask Adam AI a question, and only to write the answer to that question.
We also disclose it if the law requires us to. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We store the OAuth tokens needed to read this data on your behalf; you can disconnect at any time from your dashboard, which revokes our access and deletes the stored tokens and every monthly total read with them.
2. How we use information
- To process and fulfil membership purchases, and any courses or digital products bundled with them.
- To show members the metrics and recommendations worked out from their own business figures, and to send a monthly reminder to update them (which can be turned off in settings).
- To respond to inquiries submitted through the contact form.
- To send transactional emails related to your order (access links, receipts, course updates).
- To operate and improve the site and our products, using anonymized analytics via PostHog and error monitoring via Sentry.
- To operate site security and abuse prevention: rate limiting on form submissions and sign-in attempts.
- To comply with applicable legal and accounting obligations, including tax record-keeping.
2a. Shared workspaces
Inside a workspace, its owner and the editors and collaborators they invite can see the workspace’s numbers, tasks, Sprints, decisions, comments and votes, and who wrote each one. We record who invited whom, seat assignments and handovers in our audit log. When a workspace is handed to a new owner, its records move with it; your own account data does not.
A share link shows only the sections its owner picked, to anyone holding the link, until it is withdrawn or expires. A public record page, if you turn it on, shows your name, handle and results as percentages, and nothing else. We process this information to provide the service you and your workspace owner asked for.
3. Legal bases
Where the EU General Data Protection Regulation, UK GDPR, the Brazilian LGPD, or comparable laws apply, we rely on the following legal bases: the performance of a contract or pre-contractual steps at your request (for processing orders and delivering services), our legitimate interests (for site security and fraud prevention), your consent (for optional analytics where required), and compliance with legal obligations (for accounting and tax records).
4. Cookies and tracking
We use a small set of first-party cookies and similar technologies for essential site functionality and, with consent where required, analytics. See our Cookies Policy for the full list of technologies in use.
5. Service providers
We share personal information with service providers acting on our behalf, including:
- Stripe: payment processing. Stripe holds card data and is PCI-DSS compliant.
- Supabase: application database (EU region, Frankfurt), including order and customer records.
- WhatsApp (Meta): only if you choose to message us. The contact button is a link: nothing is sent to Meta until you tap it, and whatever you then write is handled under Meta’s own terms.
- Vercel: application hosting and edge functions.
- Cloudflare: DNS and network security.
- Amazon Web Services (SES): transactional email delivery.
- Upstash: rate limiting and short-lived caching.
- Groq: writes Adam AI’s answers from our own knowledge files, from what is sent to it for that answer only.
- Sentry: error and performance monitoring (anonymized IP).
- PostHog: product analytics (anonymized IP; consent-gated where required).
Each provider is contractually required to handle personal data consistently with this Policy and applicable law.
6. International transfers
UpgradIQ is operated by UpgradIQ, Inc., incorporated in Delaware. Some of our service providers are based in the United States or operate globally. Where personal information is transferred from outside the United States, we rely on standard contractual clauses or other lawful transfer mechanisms permitted by your jurisdiction’s data protection law.
7. Retention
- Order and customer records: retained as long as necessary to fulfil the service and for accounting and tax purposes (typically seven years from the transaction date in accordance with US tax record-keeping standards).
- Business profile, monthly figures and saved tool inputs · kept while the account exists, and deleted when the account is deleted.
- Contact-form submissions: retained for up to twenty-four months for follow-up and audit purposes.
- Aggregated and anonymized data: may be retained indefinitely.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise these rights by emailing adam@upgradiq.com. We will respond within the timeframe required by applicable law. Note that some data (such as transaction records) may be subject to legal retention requirements that limit deletion.
9. Security
We implement technical and organizational measures designed to protect personal information, including encryption in transit, row-level security on application databases, anonymized IP storage in analytics and monitoring tools, rate limiting, hidden-field abuse detection on forms, and access logging. Card data is handled exclusively by Stripe and never stored on our servers. No method of transmission is perfectly secure, and we do not guarantee absolute security.
10. Children
Our services are intended for adults. We do not knowingly collect personal information from children under sixteen.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the most recent substantive change. Material changes will be communicated to affected users by email or a prominent notice on the site.
12. Contact
Questions about this Policy may be directed to: adam@upgradiq.com. UpgradIQ, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.