Privacy Policy
Last updated: 08/24/2026
1. Overview
UpFront Solutions LLC, a New York limited liability company doing business as "UpFront" ("UpFront", "we", "us", "our"), respects your privacy. This Privacy Policy explains what information we collect when you use the UpFront service, why we collect it, how we use it, who we share it with, and the choices and rights you have. By using UpFront, you agree to the practices described here.
2. Who This Policy Applies To
UpFront serves three kinds of people, and this policy applies to each in different ways:
- Account holders — owners and admins of home-service businesses who sign up for UpFront. We collect and process your personal information as the data controller.
- Crew members — people added to an account holder's UpFront workspace. The account holder is the data controller for crew profile and time-tracking information; UpFront is the processor.
- End-clients — the homeowners and customers whose contact information, addresses, photos, and job details account holders store in UpFront. The account holder is the data controller for this information; UpFront is the processor. See Section 8 — Your Clients' Data.
3. Information We Collect
Information you provide
When you sign up and use UpFront, you provide information such as your name, email address, phone number, business name and address, business logo, payment information (handled by Stripe — we never see or store full card numbers), photos and notes you upload, voice recordings you create, and the client and job data you enter into the system.
Information we collect automatically
We automatically collect basic technical and usage information when you use the service, including device type, browser, IP address, pages viewed, and time of access. The UpFront crew time-tracking feature requires GPS location at clock-in and clock-out so you can verify that your crew is on the job site — this is collected only when crew members clock in or out through the app.
Information from third parties
We receive limited information from our integration partners as needed to run features you have enabled — for example, payment and subscription status from Stripe, SMS delivery status from Twilio, and, if you choose to connect them, accounting data from QuickBooks or Xero. See Section 6 — Subprocessors and Section 7 — Optional Integrations.
4. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the service.
- Bill you for your subscription and process payments through Stripe.
- Send transactional emails and SMS messages related to your account and your jobs.
- Power AI features such as smart job suggestions, photo analysis, voice transcription, and the auto-responder (see Section 5 — Use of AI and Machine Learning).
- Show weather forecasts, maps, directions, and address suggestions for scheduled jobs.
- Improve the product, including diagnosing bugs and prioritizing features.
- Respond to support requests and other communications you send us.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
5. Use of AI and Machine Learning
We use OpenAI to power AI features in the UpFront app — including smart job suggestions, photo analysis, and voice transcription. When you use these features, your job photos, client details, job descriptions, and voice recordings are sent to OpenAI's API for processing. Per OpenAI's API terms, your data is not used to train OpenAI's models. You can review OpenAI's API data-handling commitments at openai.com/policies/api-data-usage-policies .
AI-generated suggestions, transcripts, and analyses are provided as drafts to help you work faster. They may contain errors and should be reviewed before being acted upon or sent to your clients. If you do not want a particular piece of data sent to OpenAI, do not enter it into AI-powered features (for example, do not use the photo-analysis or voice-transcription tools for that item).
6. How We Share Information / Subprocessors
We share information with the subprocessors and infrastructure providers listed below, only as needed to deliver the service. Each receives only the information necessary for the function it performs.
- Stripe — payment processing. Receives your billing email, name, and subscription and invoice metadata. Stripe handles card numbers directly under PCI-DSS; UpFront never sees or stores full card numbers.
- Twilio — SMS delivery to your end-clients. Receives the recipient's phone number and name, your crew or business name, appointment date and time, and the SMS message body. See Section 8 for the controller/processor relationship for end-client data.
-
Resend — transactional email delivery (our sole email provider). Receives recipient email and
name, your business name and logo, verification and password-reset tokens, and invoice and client-portal
details. Mail is sent from
UpFront <info@startuf.com>. - Railway — application hosting and infrastructure. All server traffic and environment variables flow through Railway.
- Neon — managed Postgres database hosting (US region). Stores all application data.
- Sentry — crash and error reporting. Receives error events with stack traces and a scrubbed request payload. We have configured Sentry to strip passwords, PINs, and signature data before events are sent, to truncate request payloads larger than 2 KB, and to strip inline image data from client-side reports. Session replays are disabled.
- OpenAI — AI processing. See Section 5 — Use of AI and Machine Learning for the full disclosure.
- Google Maps Platform — geocoding, directions, and place details. Receives client and business addresses; latitude/longitude coordinates may be stored in your account.
- OpenWeatherMap — weather forecasts for scheduled jobs. Receives only latitude/longitude coordinates.
- OpenStreetMap — map tile rendering in the UpFront web app (Leaflet). Receives the user's IP address and the map viewport implicitly when tiles are requested.
- SerpApi — optional product search for Home Depot, Lowe's, Walmart, and Google Shopping lookups. Receives the product search query you enter.
- Shovels — optional building-permit lookups. Receives the property address you search.
We do not sell personal data. We may disclose information in response to lawful legal process, to protect our rights and the safety of our users and the public, or to enforce our Terms. If UpFront is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the protections in this policy.
7. Optional Integrations You Choose to Enable
Some integrations only run if you explicitly connect them from your UpFront settings. Data is shared with these providers only after you authorize the connection, and you can disconnect at any time.
- QuickBooks (Intuit) — accounting sync. When you connect your QuickBooks account, UpFront exchanges OAuth tokens with Intuit and syncs accounting data (such as invoices, customers, and payments) per the scopes you approve.
- Xero — accounting sync. When you connect your Xero account, UpFront exchanges OAuth tokens with Xero and syncs accounting data per the scopes you approve, which include accounting transactions and contacts.
8. Your Clients' Data
The contact information, addresses, phone numbers, photos, and job notes you store about your end-clients are processed on your behalf. For that data, you are the data controller and UpFront is the data processor. You are responsible for having a lawful basis to collect and store information about your clients and for honoring any rights they exercise.
This applies in particular to the SMS feature: when you send an SMS through UpFront, your end-client's phone number and name are sent to Twilio so the message can be delivered. The end-client is the data subject, you are the controller, and UpFront acts as your processor for that flow. You are responsible for ensuring you have permission to send SMS messages to the people you contact. UpFront will assist you in fulfilling reasonable end-client data requests at no charge.
9. Data Retention
We retain account and Customer Data for the life of your account. After you cancel, your data remains available for export for 30 days and is then deleted from our active systems within 90 days. Encrypted backups may retain data for up to an additional 35 days before being securely overwritten or destroyed. Error and crash reports in Sentry are retained per Sentry's default retention (currently 90 days).
10. Security
We protect data in transit with TLS 1.2 or higher and encrypt data at rest in our managed database (Neon, US region). Payment card data is handled directly by Stripe under PCI-DSS — we never see full card numbers. Passwords are hashed; we will never ask you for your password. Error reports are scrubbed of credentials and sensitive payload data before being transmitted to Sentry. No system is perfectly secure; please notify us immediately at support@startuf.com if you suspect a security issue.
11. Your Rights and Choices
Subject to applicable law, you have the right to access, correct, delete, or export the personal information we hold about you. To exercise these rights, email support@startuf.com. We will not charge you for these requests unless they are repetitive or manifestly unfounded.
California residents. Under the California Consumer Privacy Act (as amended by the CPRA), you have the right to know what personal information we collect about you, the right to request deletion, the right to correct inaccurate information, the right to opt out of any "sale" or "sharing" of personal information (UpFront does not sell or share personal information as those terms are defined under the CCPA), and the right not to be discriminated against for exercising these rights. To submit a request, email support@startuf.com.
12. Children's Privacy
UpFront is a business-to-business platform intended for use by businesses and adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it.
13. International Users
The service is operated from the United States, and your data is processed in the United States. UpFront is currently offered as a US-only beta. If you access UpFront from outside the United States, you consent to the transfer and processing of your information in the United States, which may have different data-protection rules than your home country.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or with an in-app notice before the change takes effect. The "Last updated" date at the top of this page indicates when this policy was last revised.
15. Push Notifications
If you enable push notifications, we store a notification token from your device with our push provider (Expo). We use these tokens only to deliver notifications you've opted into.
Notifications may include:
- Job assignment alerts (job title, client first name, scheduled time)
- Job status changes (job title, client first name, new status)
- Internal messages from your team
- Weather alerts for upcoming jobs
You can disable push notifications at any time:
- In iOS Settings → Notifications → UpFront, or
- In the UpFront app under Settings → Notifications
Disabling notifications does not delete your account or stop other features from working.
16. Contact Us
UpFront Solutions LLC
New York, United States
Email: support@startuf.com