Privacy Policy
Version: 2026-07-15
Effective date: 2026-07-15
This Privacy Policy explains how UpShyft, LLC ("UpShyft," "we," "us," or "our") collects, uses, shares, and protects information when you use the UpShyft platform — the websites and applications at upshyft.io and app.upshyft.io, the client portal, the embeddable funding-readiness assessment widget, and related services (collectively, the "Service").
Capitalized terms not defined here have the meanings given in our Terms of Service. Words like "Brokerage" (the independent funding brokerage that serves you), "Client," and "Credit Data" are defined there.
THE SHORT VERSION
- We collect the information you give us — including, if you are a Client who authorizes it, the contents of your credit report — plus limited technical data.
- We use it to run the Service: evaluating funding readiness, generating funding roadmaps, and enabling your Brokerage to serve you.
- We share it with your Brokerage and with service providers that host and operate our infrastructure. We do not sell your personal information, disclose it to data brokers, or share it for cross-context behavioral advertising.
- Credit report contents receive additional controls, including field-level encryption at rest and per-Brokerage access isolation; under the current product design, the original credit-report file is not retained after processing.
- You can request access, correction, or deletion of your information, subject to identity verification and applicable legal exceptions.
1. WHO THIS POLICY COVERS — AND AN IMPORTANT NOTE ABOUT YOUR BROKERAGE
This Policy covers information handled by UpShyft through the Service. It applies to Visitors (for example, people who complete a funding-readiness assessment), Clients (people invited to a client portal account by their Brokerage), and Brokerage Users (brokerage staff).
Your Brokerage is an independent business. When your Brokerage collects or uses information about you outside the Service — for example, in its own CRM, email, phone calls, or files — that handling is governed by the Brokerage's own privacy practices, not this Policy. This Policy governs what UpShyft does.
Depending on the context, UpShyft may handle information for its own purposes—such as account administration, security, legal compliance, and operation of the platform—and may process Client information on behalf of a Brokerage so that Brokerage can provide its services.
2. INFORMATION WE COLLECT
2.1 Information you provide.
(a) Contact and account information: name, email address, phone number, password (stored only in cryptographically hashed form), and multi-factor-authentication enrollment details.
(b) Business and assessment information: business or LLC name, industry, state, time in business, estimated monthly revenue, desired funding amount, intended use of funds, self-estimated credit score range, credit card limits, reported negative credit items, and banking relationships (bank, account types, dates opened, and related contacts).
(c) Credit Data and other sensitive personal information (Clients who authorize it): if you accept the Credit Data Authorization and upload a credit report (or, where offered, authorize us to obtain one), we collect the contents of your consumer credit file. This can include your Social Security number, date of birth, current and prior addresses, credit scores, tradelines and account histories, inquiries, and public-record items. We also generate inferences and derived Credit Data, including parsed summaries, readiness evaluations, and educational improvement plans.
(d) Documents: files you or your Brokerage upload in connection with your engagement (for example, bank statements, tax documents, or identification).
(e) Consent records: when you accept our legal documents, we record which document versions you accepted, when, and technical details of the acceptance (IP address and browser user-agent) as evidence of consent.
(f) Communications: messages you send us (for example, support requests).
2.2 Information collected automatically.
When you use the Service we collect standard technical data: IP address, browser and device information, pages and actions within the Service, and timestamps, via server logs and strictly necessary cookies (see Section 8). If you arrive at the assessment widget from a marketing page, we also record attribution data (the source URL and campaign/UTM parameters) so your Brokerage knows where its leads come from.
2.3 Information from others.
(a) Your Brokerage: your Brokerage may add or update information about you in the Service (for example, creating your client record, entering business details, or uploading documents you provided to them).
(b) Consumer reporting agencies and credit-data providers: only if and when you expressly authorize it under the Credit Data Authorization, we (or our authorized data providers) may obtain your consumer report on your behalf.
We do not purchase or sell personal information about you to data brokers.
3. HOW WE USE INFORMATION
We use information to:
(a) provide the Service: create and administer accounts; parse and analyze Credit Data; generate readiness evaluations, funding roadmaps, action plans, and educational content; and display bank and lender information relevant to your profile;
(b) enable your Brokerage to serve you: make your profile, assessment results, evaluations, documents, and progress available to the Brokerage team that works with you;
(c) communicate with you: send transactional messages such as invitations, email-verification codes, security alerts, and service notices; and, where you have consented, facilitate contact about funding options;
(d) secure the Service: authenticate users, enforce tenant isolation and permissions, prevent fraud and abuse, and investigate violations of our Terms;
(e) comply with law: maintain consent evidence, respond to lawful requests, and meet our legal obligations;
(f) improve the Service: analyze usage and outcomes, including through de-identified and aggregated data as described in Section 6.
We do not use your personal information for third-party advertising, and we do not make automated decisions about you that produce legal effects without human involvement — evaluations produced by the Service are informational tools reviewed and used by you and your Brokerage, not credit decisions.
4. HOW WE SHARE INFORMATION
We share personal information only as follows:
(a) With your Brokerage. This is the core of the Service: the Brokerage that serves you (and its authorized staff, under role-based permissions) can access your profile, assessment answers, Credit Data and evaluations, documents, and progress. Access is isolated per Brokerage — staff of one brokerage cannot access another brokerage's client data.
(b) With service providers (processors) that operate our infrastructure under contractual confidentiality and data-protection obligations, and only as needed to run the Service:
- cloud database, authentication, and file-storage hosting;
- application hosting and content delivery;
- transactional email delivery
We may update this list as our infrastructure evolves; material changes will be reflected in this Policy.
(c) With your Brokerage's connected systems, at the Brokerage's direction. If your Brokerage connects its customer-relationship-management system (for example, GoHighLevel) to the Service, limited information—such as contact details, funding-journey status, and appointment or pipeline events—may be synchronized to that system so the Brokerage can manage its client work. UpShyft's configured CRM integrations are designed not to transmit Social Security numbers or credit-report contents.
(d) With consumer reporting agencies or credit-data providers, only as needed to fulfill a request you have authorized under the Credit Data Authorization (for example, verifying your identity to retrieve your report).
(e) For legal reasons: to comply with law, regulation, legal process, or enforceable governmental request; to enforce our Terms; or to protect the rights, safety, or property of UpShyft, our users, or the public.
(f) In a business transfer: if UpShyft is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy's commitments.
(g) At your direction, with your consent.
WE DO NOT: sell your personal information; share it with data brokers; share it for cross-context behavioral advertising; or share your Credit Data with lenders or other third parties except at your direction.
5. CREDIT DATA — SPECIAL HANDLING
Credit Data is subject to additional protections and controls:
(a) Consent-gated: we only collect Credit Data from Clients who have accepted the Credit Data Authorization.
(b) Field-level encryption: parsed credit-report contents are encrypted at rest with dedicated application-level encryption (AES-256-GCM), using separate encryption keys per Brokerage, in addition to infrastructure disk encryption.
(c) Minimal retention of raw files: under the current product design, after an uploaded credit-report file is processed successfully, the original file is not retained; the encrypted parsed record is the retained copy.
(d) Isolation: access controls are designed so Credit Data is accessible only to you, authorized staff of your Brokerage, and authorized UpShyft personnel with a business need, and not to other brokerages.
(e) No CRM egress: Credit Data and Social Security numbers are excluded from data synchronized to Brokerage CRM systems.
(f) Crypto-shredding on deletion: when a Brokerage's data is deleted, destruction of its encryption keys renders the encrypted Credit Data unreadable.
6. DE-IDENTIFIED AND AGGREGATED DATA
We may create de-identified or aggregated data (data that does not identify you and cannot reasonably be linked to you) and use it to operate, improve, and demonstrate the Service — for example, statistics about funding outcomes across anonymized cohorts. We commit to maintaining such data in de-identified form, not attempting to re-identify it, and applying minimum-cohort thresholds before surfacing any aggregate statistic.
7. SECURITY
We use administrative, technical, and organizational safeguards designed to protect your information, including: encryption in transit (TLS) and at rest; field-level envelope encryption for Credit Data and integration credentials; database row-level security designed to enforce per-Brokerage tenant isolation; private, access-controlled file storage; role-based permissions; multi-factor authentication; invitation-only account creation; and tamper-resistant consent evidence. Safeguards evolve, and no controls eliminate all risk. If we learn of a breach affecting your personal information, we will notify affected individuals and regulators as required by law.
8. COOKIES
The authenticated Service currently uses only strictly necessary cookies—primarily session cookies that keep you signed in and secure. We do not currently use advertising or cross-site tracking cookies or run third-party analytics trackers within the authenticated Service. Because we do not sell or share personal information for targeted advertising, there is no such activity for a Global Privacy Control signal to opt out of; we treat GPC signals accordingly. Note that pages operated by your Brokerage (for example, a marketing site that embeds our assessment widget) are the Brokerage's responsibility and may use their own cookies and pixels.
9. RETENTION
We retain personal information for as long as your account or Brokerage engagement is active and afterward only as reasonably necessary for the purposes described in this Policy. The applicable period depends on the category of information, the duration of the relationship, security and fraud-prevention needs, dispute and limitation periods, and legal or contractual requirements. Credit Data is retained only while needed to provide the Service to you and your Brokerage. When a verified deletion request applies, we delete or de-identify covered information from active systems and allow protected backups to expire under our standard backup cycle, unless retention is required or permitted by law.
10. YOUR RIGHTS AND CHOICES
Regardless of where you live, we offer you the following, subject to identity verification:
(a) Access and portability: request a copy of the personal information we hold about you.
(b) Correction: correct inaccurate information (much of your profile can be corrected directly in the portal or through your Brokerage).
(c) Deletion: request deletion of your account and personal information. Deletion removes your profile, Credit Data, evaluations, documents, and account credentials from the Service. We may retain limited information where required by law.
(d) Marketing opt-out: opt out of marketing communications at any time; transactional service messages continue while you have an account.
(e) Withdraw consent: withdraw the Credit Data Authorization or Electronic Signature Consent as described in those documents (withdrawal may limit or end your ability to use the Service).
To exercise any right, contact us at support@upshyft.io or make the request through your Brokerage. We will respond within the time required by applicable law (and in any case aim to respond within 30 days). We will not discriminate against you for exercising your rights. If your state's privacy law grants you additional rights (for example, the right to appeal a denied request), we honor them; you may also lodge a complaint with your state attorney general.
Authorized agents: where applicable law allows, an authorized agent may submit a request on your behalf with proof of authorization.
State-specific disclosures. Depending on your residence and whether a state privacy law applies to UpShyft, you may have additional rights concerning confirmation, access, correction, deletion, portability, opt-out, consent for sensitive data, and appeal of a denied request. We will honor applicable rights and provide any required method to appeal.
11. FINANCIAL PRIVACY (GLBA)
To the extent UpShyft's activities make it a "financial institution" under the Gramm-Leach-Bliley Act, we treat nonpublic personal information in accordance with GLBA: we do not share nonpublic personal information with nonaffiliated third parties except as described in this Policy (service providers, your Brokerage at your direction, legal requirements, and other permitted exceptions), and we maintain an information-security program consistent with the FTC Safeguards Rule. Because we do not share nonpublic personal information with nonaffiliated third parties for their own marketing, no opt-out is required.
12. CHILDREN
The Service is for business use by adults. It is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will investigate and delete it as appropriate.
13. UNITED STATES ONLY
The Service is operated from the United States and intended for U.S. users. Your information is stored and processed in the United States.
14. CHANGES TO THIS POLICY
We may update this Policy from time to time. Each version has a version number and effective date. If we make material changes, we will notify you (for example, by email or in-Service notice) and, where required, ask you to re-accept. The current version is always available in the Service.
15. CONTACT US
UpShyft, LLC
8 ZOELLER CT
PALM COAST, FL 32164
Email: support@upshyft.io
Privacy requests: support@upshyft.io
General support: support@upshyft.io