Legal
Privacy Policy
This policy explains what information moves through Uptoad, why it is needed, and the choices available to account holders and people who submit files.
Effective 9 August 2026
Scope and roles
This Privacy Policy applies to the Uptoad website, hosted upload portals, account areas, and related services (together, the Service).
A business or organization that creates an Uptoad workspace (the Workspace Owner) decides why files and submitter details are collected. For that information, the Workspace Owner is the data controller or business and Uptoad acts as its service provider or processor. Uptoad is independently responsible for information used to operate accounts, secure the Service, meet legal duties, and manage its customer relationships.
A branded upload portal may identify its Workspace Owner and show its contact details. Questions about a particular submission should usually be directed to that Workspace Owner first.
Information we collect
- Account and workspace information: name, email address, password hash, organization, role, subscription status, and account timestamps.
- Submission information: uploader name and email, project reference, notes, filenames, file sizes and types, upload status, delivery time, and receipt data. The fields shown depend on the portal configured by the Workspace Owner.
- Files: the content selected for upload. The primary copy is sent to the Workspace Owner's connected Google Drive rather than stored by Uptoad as file storage. File bytes may pass through Uptoad when an authorized user downloads a file.
- Technical and security information: IP address, session identifier, authentication attempts, audit events, error details, browser-generated upload state, and basic request information needed to prevent abuse and troubleshoot the Service.
- Communications: messages sent to Uptoad or a Workspace Owner and delivery records for upload notifications and receipts.
Uptoad does not use third-party advertising cookies and does not sell personal information. The Service does not currently use behavioral advertising or cross-site tracking.
Google user data
When a Workspace Owner connects Google Drive, Uptoad requests the drive.file permission. This lets the Service create, upload, verify, and retrieve files it created or that were opened with the Service; it does not provide general access to existing Drive contents. Uptoad may also receive the connected Google account email address, connection time, folder identifiers, file identifiers, and an OAuth refresh token. Refresh tokens are encrypted before database storage and are removed when the Drive is disconnected.
Google user data is used only to provide the visible Drive connection and file-delivery features, protect those features, comply with law, or act on the user's instructions. It is not used for advertising, sold, or used to train general-purpose AI models. Human access is limited to cases where the user gives permission, access is necessary for security or support, or the law requires it.
Uptoad's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
- create and administer accounts, workspaces, portals, requests, and invitations;
- transfer files to the selected Google Drive and confirm delivery;
- resume interrupted uploads and provide private upload receipts;
- send operational notifications requested by the Workspace Owner;
- authenticate users, maintain audit trails, prevent abuse, and investigate incidents;
- provide support, maintain, and improve the reliability of the Service; and
- comply with legal obligations and enforce agreements.
Where EU or UK data protection law applies, Uptoad relies as appropriate on performance of a contract, legitimate interests in providing and securing the Service, compliance with legal obligations, and consent where it is specifically requested. The Workspace Owner determines the lawful basis for submission information it instructs Uptoad to process.
Data retention
- Account sessions expire after seven days and can be revoked sooner.
- Browser upload-resume records expire after seven days and are normally removed when an upload completes or is cancelled.
- Google authorization is kept until the Drive is disconnected or the related account or workspace is closed.
- Files remain in the connected Google Drive until the Workspace Owner or Drive owner deletes them under its own retention policy.
- Submission metadata, account records, audit logs, and communications are retained for as long as needed to provide the Service, follow Workspace Owner instructions, resolve disputes, enforce agreements, and meet legal obligations. Limited copies may remain in protected backups until those backups cycle out.
Security
Uptoad uses safeguards designed for the sensitivity of the Service, including encrypted transport, password hashing, encrypted Google refresh tokens, restricted Drive permissions, expiring and revocable sessions, rate limiting, tenant isolation, and audit logging. No system can guarantee absolute security. Users should protect receipt links and account credentials and promptly report suspected unauthorized access.
International transfers
Uptoad, Workspace Owners, Google, and other service providers may process information in countries other than the one where it was collected. Where required, appropriate transfer mechanisms and contractual safeguards are used. The Workspace Owner can provide details about the Google Drive region and providers selected for its workspace.
Your privacy rights
Depending on location, a person may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to certain processing; withdraw consent; and complain to a data protection authority. These rights can be limited by law.
For information submitted to a particular portal, contact the Workspace Owner shown on that portal or the organization that requested the upload. Uptoad will assist the Workspace Owner with verified requests. For Uptoad account, security, or commercial records, use the support contact supplied with the account or service order. Additional information may be requested to verify identity before fulfilling a request.
Contact and changes
The Service is intended for business use and is not directed to children. Do not submit information about a child unless the Workspace Owner has a lawful reason and has specifically requested it.
Uptoad may update this policy as the Service, providers, or law changes. The effective date will be revised, and material changes will be communicated through the Service or the account contact where required.
Privacy questions can be sent through the Uptoad support contact identified in the Workspace Owner's account or service order. Questions about an uploaded file should be sent to the organization that requested it.