Skip to content

Legal

Privacy Policy

This policy explains what information moves through Uptoad, why it is needed, and the choices available to account holders and people who submit files.

Effective 9 August 2026

01

Scope and roles

This Privacy Policy applies to the Uptoad website, hosted upload portals, account areas, and related services (together, the Service).

A business or organization that creates an Uptoad workspace (the Workspace Owner) decides why files and submitter details are collected. For that information, the Workspace Owner is the data controller or business and Uptoad acts as its service provider or processor. Uptoad is independently responsible for information used to operate accounts, secure the Service, meet legal duties, and manage its customer relationships.

A branded upload portal may identify its Workspace Owner and show its contact details. Questions about a particular submission should usually be directed to that Workspace Owner first.

02

Information we collect

  • Account and workspace information: name, email address, password hash, organization, role, subscription status, and account timestamps.
  • Submission information: uploader name and email, project reference, notes, filenames, file sizes and types, upload status, delivery time, and receipt data. The fields shown depend on the portal configured by the Workspace Owner.
  • Files: the content selected for upload. The primary copy is sent to the Workspace Owner's connected Google Drive rather than stored by Uptoad as file storage. File bytes may pass through Uptoad when an authorized user downloads a file.
  • Technical and security information: IP address, session identifier, authentication attempts, audit events, error details, browser-generated upload state, and basic request information needed to prevent abuse and troubleshoot the Service.
  • Communications: messages sent to Uptoad or a Workspace Owner and delivery records for upload notifications and receipts.

Uptoad does not use third-party advertising cookies and does not sell personal information. The Service does not currently use behavioral advertising or cross-site tracking.

03

Google user data

When a Workspace Owner connects Google Drive, Uptoad requests the drive.file permission. This lets the Service create, upload, verify, and retrieve files it created or that were opened with the Service; it does not provide general access to existing Drive contents. Uptoad may also receive the connected Google account email address, connection time, folder identifiers, file identifiers, and an OAuth refresh token. Refresh tokens are encrypted before database storage and are removed when the Drive is disconnected.

Google user data is used only to provide the visible Drive connection and file-delivery features, protect those features, comply with law, or act on the user's instructions. It is not used for advertising, sold, or used to train general-purpose AI models. Human access is limited to cases where the user gives permission, access is necessary for security or support, or the law requires it.

Uptoad's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

04

How we use information

  • create and administer accounts, workspaces, portals, requests, and invitations;
  • transfer files to the selected Google Drive and confirm delivery;
  • resume interrupted uploads and provide private upload receipts;
  • send operational notifications requested by the Workspace Owner;
  • authenticate users, maintain audit trails, prevent abuse, and investigate incidents;
  • provide support, maintain, and improve the reliability of the Service; and
  • comply with legal obligations and enforce agreements.

Where EU or UK data protection law applies, Uptoad relies as appropriate on performance of a contract, legitimate interests in providing and securing the Service, compliance with legal obligations, and consent where it is specifically requested. The Workspace Owner determines the lawful basis for submission information it instructs Uptoad to process.

05

When information is shared

Information is disclosed only as needed to:

  • the Workspace Owner and its authorized members, who can access submissions and account activity within their workspace;
  • Google, to authenticate a Drive connection and store, verify, or retrieve files;
  • infrastructure, database, security, and notification providers that process data under contract to operate the Service;
  • professional advisers, authorities, or other parties where reasonably necessary to comply with law, protect rights and safety, or investigate misuse; and
  • a successor in a merger, financing, reorganization, or sale, subject to applicable notice and consent requirements.

A Workspace Owner may connect its own Google account or notification workflow. Its use of information outside Uptoad is governed by its own policies and instructions.

06

Data retention

  • Account sessions expire after seven days and can be revoked sooner.
  • Browser upload-resume records expire after seven days and are normally removed when an upload completes or is cancelled.
  • Google authorization is kept until the Drive is disconnected or the related account or workspace is closed.
  • Files remain in the connected Google Drive until the Workspace Owner or Drive owner deletes them under its own retention policy.
  • Submission metadata, account records, audit logs, and communications are retained for as long as needed to provide the Service, follow Workspace Owner instructions, resolve disputes, enforce agreements, and meet legal obligations. Limited copies may remain in protected backups until those backups cycle out.
07

Cookies and local storage

Uptoad uses a strictly necessary, HTTP-only session cookie to keep signed-in users authenticated. It is not used for advertising and cannot be read by browser scripts.

For resumable uploads, the browser may keep the selected file or a reference to it, filename, size, last-modified time, upload identifier, temporary Google upload-session address, and confirmed byte offset in IndexedDB. This allows a large upload to continue after a refresh or network interruption. Clearing site data removes this local record and may prevent resumption.

08

Security

Uptoad uses safeguards designed for the sensitivity of the Service, including encrypted transport, password hashing, encrypted Google refresh tokens, restricted Drive permissions, expiring and revocable sessions, rate limiting, tenant isolation, and audit logging. No system can guarantee absolute security. Users should protect receipt links and account credentials and promptly report suspected unauthorized access.

09

International transfers

Uptoad, Workspace Owners, Google, and other service providers may process information in countries other than the one where it was collected. Where required, appropriate transfer mechanisms and contractual safeguards are used. The Workspace Owner can provide details about the Google Drive region and providers selected for its workspace.

10

Your privacy rights

Depending on location, a person may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to certain processing; withdraw consent; and complain to a data protection authority. These rights can be limited by law.

For information submitted to a particular portal, contact the Workspace Owner shown on that portal or the organization that requested the upload. Uptoad will assist the Workspace Owner with verified requests. For Uptoad account, security, or commercial records, use the support contact supplied with the account or service order. Additional information may be requested to verify identity before fulfilling a request.

11

Contact and changes

The Service is intended for business use and is not directed to children. Do not submit information about a child unless the Workspace Owner has a lawful reason and has specifically requested it.

Uptoad may update this policy as the Service, providers, or law changes. The effective date will be revised, and material changes will be communicated through the Service or the account contact where required.

Privacy questions can be sent through the Uptoad support contact identified in the Workspace Owner's account or service order. Questions about an uploaded file should be sent to the organization that requested it.