Privacy Policy
Last updated: March 31, 2026
1. Introduction
Staiup Inc. ("Staiup," "we," "us," or "our") operates the staiup.com website and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including our autonomous business management agents and related tools.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Personal Information You Provide
When you register for an account or use our Service, we may collect:
- Name, email address, and phone number
- Business name, address, and Employer Identification Number (EIN)
- Payment and billing information (processed securely through Stripe)
- Bank account and financial data (processed securely through Plaid)
- Social media account credentials and access tokens for connected platforms
- Profile photographs, logos, and other uploaded media
- Business documents, files, and content you upload to the Service
- Communications you send to us, including support requests
2.2 Information Collected Automatically
When you interact with the Service, we automatically collect:
- Device information (browser type, operating system, device identifiers)
- IP address and approximate geographic location
- Pages visited, features used, and actions taken within the Service
- Date, time, and duration of your sessions
- Referring URLs and search terms that led you to our Service
- Performance data and error logs
2.3 Agent Interaction Data
Our Service includes autonomous business management agents that operate on your behalf. When you interact with or authorize these agents, we collect:
- Prompts, instructions, and preferences you provide to agents
- Agent-generated content, recommendations, and outputs
- Records of actions taken by agents on your behalf (e.g., social media posts, marketing campaigns, file management operations)
- Conversation histories between you and the agents
- Agent performance metrics and feedback you provide
2.4 Information from Third-Party Services
When you connect third-party accounts, we may receive information from those services, including:
- Social media profile data, post analytics, and audience metrics (from platforms such as Facebook, Instagram, LinkedIn, X/Twitter, TikTok, and others)
- Financial account information, transaction histories, and balances (through Plaid)
- Advertising account data and campaign performance metrics
- Calendar events and scheduling data from connected calendar services
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery and Operations
- To create and manage your account
- To provide, maintain, and improve the Service
- To enable our autonomous agents to perform tasks on your behalf
- To process transactions and manage billing through Stripe
- To connect to and interact with your linked third-party services
- To store and manage your uploaded files and business documents
3.2 Agent Operations
- To train and improve the performance of our business management agents
- To personalize agent behavior based on your preferences and business context
- To generate marketing content, social media posts, and business recommendations
- To execute authorized actions across your connected platforms
- To provide analytics and insights about your business performance
3.3 Communication and Support
- To respond to your inquiries and support requests
- To send service-related notifications and updates
- To provide onboarding guidance and product tips
- To send promotional communications (with your consent, where required)
3.4 Analytics and Improvement
- To analyze usage patterns and optimize the Service
- To monitor and improve the accuracy and effectiveness of our agents
- To detect, prevent, and address technical issues
- To conduct research and development for new features
4. Third-Party Services and Data Sharing
We integrate with and share data with the following categories of third-party services to operate the Service:
4.1 Infrastructure and Data Storage
We use Supabase for database hosting, authentication, and file storage. Your data is stored on servers operated by Supabase and its cloud infrastructure providers. Supabase processes data in accordance with its own privacy policy.
4.2 Payment Processing
We use Stripe to process payments and manage subscriptions. When you provide payment information, it is transmitted directly to Stripe and stored on their secure servers. We do not store your full credit card numbers on our systems. Stripe's handling of your payment data is governed by Stripe's privacy policy.
4.3 Financial Data Aggregation
We use Plaid to securely connect to your financial institutions. When you link a bank account, Plaid retrieves account information and transaction data on our behalf. Plaid's use of your data is governed by Plaid's privacy policy.
4.4 Social Media and Advertising Platforms
When you connect social media accounts (such as Facebook, Instagram, LinkedIn, X/Twitter, TikTok, Google, and others), we access and use their APIs to post content, retrieve analytics, and manage advertising campaigns on your behalf. Each platform's handling of your data is subject to its own privacy policy and terms.
4.5 Other Disclosures
We may also share your information:
- With your consent or at your direction
- To comply with legal obligations, court orders, or lawful government requests
- To enforce our Terms of Service and protect our rights
- In connection with a merger, acquisition, or sale of assets (you will be notified of any such change)
- With service providers who assist us in operating the Service, subject to confidentiality obligations
5. Data Retention and Deletion
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained for the duration of your account and for up to 30 days after account deletion to allow for recovery.
- Agent interaction data (conversation logs, generated content) is retained for as long as your account is active and deleted within 90 days of account closure.
- Uploaded files are retained until you delete them or until 30 days after account deletion.
- Payment records are retained as required by applicable tax and financial regulations (typically 7 years).
- Usage logs and analytics data are retained in aggregated, de-identified form for up to 24 months.
When you request account deletion, we will remove or de-identify your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention or financial record-keeping).
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Correction: You may request that we correct inaccurate or incomplete personal information.
- Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions.
- Right to Data Portability: You may request a machine-readable copy of your personal information for transfer to another service.
- Right to Object: You may object to certain processing of your personal information, including processing for direct marketing purposes.
- Right to Restrict Processing: You may request that we limit how we use your personal information in certain circumstances.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time.
To exercise any of these rights, please contact us at privacy@staiup.com. We will respond to your request within 30 days or as required by applicable law.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms, including multi-factor authentication
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data on a need-to-know basis
- Secure coding practices and code review processes
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
8. Children’s Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe that a child under 18 has provided personal information to us, please contact us at privacy@staiup.com.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from the laws of your jurisdiction. By using the Service, you consent to the transfer of your information to the United States and other countries where our service providers operate.
Where required by applicable law, we ensure that appropriate safeguards are in place for international data transfers, including standard contractual clauses approved by relevant regulatory authorities.
10. Additional Rights for California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- The right to know what categories of personal information we collect about you and the purposes for which it is used
- The right to request deletion of your personal information
- The right to opt out of the "sale" or "sharing" of your personal information
- The right to non-discrimination for exercising your privacy rights
We do not sell your personal information. To exercise your CCPA/CPRA rights, please contact us at privacy@staiup.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on this page and updating the "Last updated" date. We may also provide additional notice, such as an email notification or an in-app alert, for significant changes.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: