Data Safety
Last Updated : 03 June 2026
UpBlick implements reasonable technical, administrative, and organizational safeguards designed to protect personal data, business information, review data, and authorized integration data processed through the Services.
1. Security Program
Our security practices are intended to support confidentiality, integrity, availability, and resilience of the Services. Those practices may evolve over time in response to changes in technology, operational requirements, and risk.
2. Infrastructure and Environment Controls
- Use of managed hosting and infrastructure services with layered network and administrative controls.
- Segregation of environments and controlled access to production systems.
- Monitoring and alerting intended to identify availability issues, abuse patterns, and anomalous activity.
3. Encryption and Credential Handling
- Use of encrypted transport protocols such as HTTPS/TLS for data in transit.
- Use of security controls intended to protect sensitive credentials, tokens, secrets, and authentication artifacts.
- Access restrictions intended to limit exposure of operational secrets and privileged credentials.
4. Access Management
- Role-based or function-based access restrictions for administrative and support personnel.
- Least-privilege access principles applied to internal operations to the extent reasonably practicable.
- Logging and review of certain administrative events and privileged system activity.
5. Application Security
- Development and maintenance practices intended to reduce common application security risks.
- Controls such as validation, access checks, monitoring, and security-related updates.
- Investigation of identified vulnerabilities and operational issues based on severity and business impact.
6. Backup, Recovery, and Business Continuity
- Backups and recovery procedures intended to support service restoration and continuity.
- Retention of backup copies for operational, disaster recovery, audit, legal, and security purposes where appropriate.
7. Vendor and Subprocessor Oversight
Where we engage hosting providers, infrastructure vendors, payment processors, monitoring tools, or other subprocessors, we seek to use providers that are commercially appropriate for the relevant function and to impose contractual obligations relating to confidentiality, security, and lawful data handling, as appropriate.
8. Google and Third-Party Integration Data
For data obtained through Google APIs or other third-party integrations, UpBlick is intended to use and retain such data only as reasonably necessary to provide the authorized user-facing features and in accordance with applicable third-party terms and policies. We do not sell such data or use it for unrelated advertising purposes.
Our technical and organizational measures are intended to support compliance obligations that may apply under laws such as GDPR and DPDP, but customers remain responsible for configuring the Services and their own internal processes in a manner consistent with their legal obligations.
9. Incident Response
We maintain processes intended to detect, evaluate, contain, investigate, and remediate suspected security incidents. Where required by applicable law or contractual obligation, we will provide notice of qualifying incidents within a commercially reasonable period after confirmation.
10. Shared Responsibility
Security is a shared responsibility. Customers are responsible for maintaining strong authentication practices, limiting account access appropriately, ensuring lawful collection and use of data uploaded to the Services, and reviewing team permissions and connected integrations.
11. No Absolute Security Guarantee
Although we apply reasonable safeguards, no method of transmission, storage, or electronic processing can be guaranteed to be completely secure. Accordingly, UpBlick cannot warrant absolute security.
12. Customer
Security or data protection questions may be sent to support@upblick.com.