Welcome to Upside! Upside Services, Inc. (“Upside,” “we,” “us,” or “our”) wants you to be familiar with how we collect, use, and disclose Personal Data.
At Upside, we care about your privacy and are committed to protecting your Personal Data. We collect and process your Personal Data so we can personalize the Services we provide—such as the offers in our App. We do not sell the Personal Data collected in our App or the transactional information we receive from our merchant partners.
This Privacy Policy describes our practices in connection with Personal Data that we collect through:
Collectively, we refer to the Website, App, Social Media, Emails, and Offline Interactions as the “Services.” Our Services are intended for individuals in the United States only.
In addition, your access to and use of the Services is subject to the Terms of Service available here, which may be updated by Upside from time to time. As a courtesy, Upside may provide versions of the Terms of Service, the Privacy Policy, and other policies or documents translated into a foreign language. In case of any discrepancy in wording, the English language version of these documents and policies shall prevail.
Click here for additional information for residents of U.S. states.
“Personal Data” is information that identifies an individual or relates to an identifiable individual. We collect the following categories of Personal Data:
Identifiers
Such as first and last name, email address, and telephone number. We may also collect a list of your contacts, including names and telephone numbers, if you choose to upload your contacts to make referrals and generate referral bonuses.
For a small subset of Upside users, we may collect additional categories of Personal Data that those users voluntarily provide to us while using the Services. For example, a user may provide additional contact information while interacting with customer support or entering an Upside promotion or sweepstakes, or a user may provide a tax identification number for tax reporting purposes.
User Content
Such as reviews about our Services and other content that you may create or share with us during our relationship, including posts on our Social Media and comment sections.
Preferences
Such as language, interests, and other feedback/preferences that you might express during your use of our Services.
Marketing Data
Such as your choices regarding our newsletters, surveys, and other marketing/advertising displayed or provided to you, and preferred methods of such promotional communication.
Commercial Information
Such as your history of Upside use, including transaction timestamps, site identifiers, transaction totals, purchase history, cash back rewards earned, and the first six and last four digits of any credit cards used, if you use our Services and redeem cash back rewards offers. We also collect payment card data through a third-party payment processor if you choose to input a credit or debit card into your Upside wallet.
We collect the name of your financial institution(s) and the last four digits of your bank account number(s), if you choose to redeem your cash back rewards by receiving a direct transfer to your bank account, and we collect the email address associated with your PayPal account, if you choose to redeem your cash back rewards by receiving a direct transfer to your PayPal account.
We may also collect images of your credit card receipts from transactions at Upside merchant partners, if you upload these images to the Services to claim cash back rewards offers. Depending on the merchant, such receipts may include additional Personal Data. We use the transaction information contained on these receipts to verify your claims for cash back rewards offers and to update your history of Upside use.
Employment or Professional Information
For our current and potential business partners, we collect professional or employment-related information, such as current company, position and title, work history, and prior employer.
Online Activity Data
Pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access, and whether you have opened our marketing emails or clicked links within them.
Device Information
Your mobile device’s operating system type and version, manufacturer and model, screen resolution, RAM, CPU usage, device type (e.g., phone, tablet), IP address, language settings, mobile device carrier, radio/network information (e.g., WiFi, LTE, 5G), advertising ID, and general location information.
This includes data obtained through cookies and similar technologies, as described below in the COOKIES AND SIMILAR TECHNOLOGIES section.
Audio/Visual Data
Audio, electronic, visual, and similar information, such as call and video recordings and photos.
Geolocation Data
Such as device location (if you choose to enable location services on your mobile device) and approximate location derived from IP address. We use device location to verify your claims for cash back rewards offers and to notify you when you are near one of our merchant partners.
Third-Party Logins
When you link, connect, or login to our Services with a third-party service (e.g., Google, Apple, or Facebook), you direct the service to send us information as controlled by that service or as authorized by you via your privacy settings on that service.
Other Third Parties, including our Merchant Partners
We collect information from sources such as your friends who may refer you to us and from our merchant partners who participate on the Upside platform.
Merchants who partner with Upside share transaction-level data with us, which we use to verify your Upside transactions and to identify your purchase history with those merchants. When you choose to redeem a cash back rewards offer for the first time, you instruct participating merchants to send your purchase history data to Upside.
If you connect your bank account(s) to the App to redeem your cash back rewards, we may collect related commercial data, including purchase history, site identifiers, and transaction timestamps, through our financial services partner to provide more personalized Services to you.
We need to collect Personal Data to provide the requested Services to you. If you do not provide the information requested or you later request to delete your Personal Data, you may not be able to use some or all of the Services. If you disclose any Personal Data relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the data in accordance with this Privacy Policy.
We use Personal Data for our business purposes, including:
DISCLOSURE OF PERSONAL DATA
We disclose Personal Data to third parties and for the purposes described below:
By using the Services, you may elect to disclose Personal Data on message boards, chats, profile pages, blogs, and other services to which you are able to post information and content (including, without limitation, our Social Media), or through which you are able to send messages through the Services. Please note that any data you post or disclose in this context will become public and may be available to other users and the general public.
SECURITY
We seek to use reasonable organizational, technical, and administrative measures to protect Personal Data within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. For example, email sent to or from the Services may not be secure. Therefore, you should take special care in deciding what information you send to us via email. Please keep this in mind when disclosing any Personal Data to Upside through the Internet. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the CONTACTING US section below.
CHOICES AND REQUESTS
If you no longer want to receive marketing-related emails from us on a going-forward basis, you may opt out by following the unsubscribe instructions in any such email message.
We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt out of receiving marketing from us, we may still send you important administrative messages, from which you cannot opt out.
If you wish to use the Services, you can choose to provide certain Personal Data, such as login information to create an account and transaction information to accept cash back rewards offers. If you choose not to provide certain Personal Data, you may not be able to use all features of the Services.
Please refer to the U.S. STATE CONSUMER PRIVACY SUPPLEMENT at the end of this Privacy Policy for more information about your rights and requests you may make under applicable law.
RETENTION PERIOD
We retain Personal Data for as long as needed or permitted for the purpose(s) for which it was obtained, as outlined in this Privacy Policy, unless a longer retention period is provided for under applicable law. The criteria used to determine our retention periods include:
THIRD-PARTY SERVICES
This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties. This includes any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.
In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Data you disclose to other organizations through or in connection with the App or our Social Media.
COOKIES AND SIMILAR TECHNOLOGIES
We and our service providers collect information automatically, including through cookies, pixel tags, and similar online technologies, such as from:
Your browser or device. Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (i.e., Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version and the name and version of the Services (such as the App) you are using. We use this information to ensure that the Services function properly.
Your use of our App. When you download and use our App, we and our service providers may track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.
Cookies and similar technologies. Cookies are pieces of information stored directly on your computer. We use first and third-party cookies and similar technologies to collect such information as browser type, time spent on the Services, pages visited, language preferences, unique identifiers, content you view, click on, or share, screen gestures or actions, and other traffic data. We and our service providers use the information for security purposes, to power the interactive features of our Services, to facilitate navigation, to display information more effectively, to personalize your experience, to develop and improve the performance, functionality, and design of the Services, for advertising and marketing purposes, and to help keep the Services free of bugs or errors.
We also gather statistical information about use of the Services to continually improve their design and functionality, understand how they are used, and assist us with resolving questions regarding them. Cookies and similar technologies further allow us to select which of our advertisements or offers are most likely to appeal to you and display them to you. We do not currently respond to browser do-not-track signals.
If you do not want information collected through the use of cookies, most browsers allow you to automatically decline cookies or be given the choice of declining or accepting particular cookies from a particular website. You may also wish to refer to http://www.allaboutcookies.org/manage-cookies/index.html. If, however, you do not accept cookies, you may experience some inconvenience in your use of the Services. You also may not receive advertising or other offers from us that are relevant to your interests.
Pixel tags (also known as web beacons and clear GIFs) may also be used to, among other things, track the actions of users of the Services (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of the Services and response rates.
Analytics. We use third-party analytics services, including Google Analytics, which use cookies and similar technologies to collect and analyze information about use of the Services and report on activities and trends. These services collect and analyze user interactions with the Services, such as screens visited, pages and content viewed, screen actions and gestures such as taps, clicks, and scrolls, as well as browser and device details including the type, version, model, and operating system. These services may also collect information regarding the use of other websites, apps, and online services.
You can learn about Google’s practices by going to http://www.google.com/policies/privacy/partners/ and you can exercise the opt-out provided by Google by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.
Location data. Depending on how you choose to set your mobile device settings, we may collect the physical location of your device by, for example, using satellite, cell phone tower or WiFi signals. We may use your device’s physical location to provide you with personalized location-based services and content. We may also share your device’s physical location, combined with information about what advertisements you viewed and other information we collect, with our marketing partners to enable them to provide you with more personalized content and to study the effectiveness of advertising campaigns. In some instances, you may be permitted to allow or deny such uses and/or sharing of your device’s location, but if you do, we may not be able to provide you with the applicable personalized services and content.
THIRD-PARTY ADVERTISING
We use third-party advertising companies to serve advertisements regarding goods and services that may be of interest to you when you access and use the Services and other websites or online services.
You may receive advertisements based on information relating to your access to and use of the Services and other websites or online services on any of your devices, as well as on information received from third parties. These companies place or recognize a unique cookie on your browser (including using pixel tags). They also use these technologies, along with information they collect about your online use, to recognize you across the devices you use, such as a mobile phone and a laptop.
Portions of our Website directed at our current and potential business partners (“For Business”) utilize technologies of third-party advertising partners such as NextRoll. These technologies help us recognize devices and understand how visitors use those portions of our Website so that we can improve our business-to-business marketing to reflect interests and serve advertisements about the Services that are likely to be of more interest to visitors to those pages. Specifically, NextRoll collects information about visitor activity on the “For Business” portion of the Website to enable us to measure and analyze traffic and browsing activity on our Website, and to show business to business marketing advertisements for our services on third-party sites. For our current and potential business partners, we may share your Personal Data, such as email addresses or other online identifiers that we collect from you, with NextRoll. This allows our advertising partners to recognize and deliver your ads across devices and browsers. To read more about the technologies used by NextRoll and their cross-device capabilities please refer to NextRoll’s Privacy Notice here.
If you would like more information about these third-party advertising practices, and to learn how to opt out in desktop and mobile browsers on the device on which you are accessing this Privacy Policy, please visit http://optout.aboutads.info/#/ and http://optout.networkadvertising.org/#/. You may download the AppChoices app at www.aboutads.info/appchoices to opt out in mobile apps.
THIRD-PARTY PAYMENT SERVICES
The Services may provide functionality allowing you to make payments to Upside using third-party payment services with which you have created your own account. When you use such a service to make a payment to us, your Personal Data will be collected by such third party and not by us, and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, this third party’s collection, use, and disclosure of your Personal Data.
Upside users who redeem their cash back rewards by receiving a direct transfer to their bank accounts are prompted to log in to an online banking portal. This online portal is provided by Plaid, Inc., which provides your full name, email address, the name of your financial institution, and your full bank account number to Dwolla, Inc. Upside collects (through Dwolla) the name of your financial institution and the last four digits of your bank account number. Dwolla uses the Personal Data collected to originate credit transfers to your bank account(s) that you select in the mobile application. Plaid’s Privacy Policy is accessible here. Dwolla’s Privacy Policy is accessible here. If you wish to exercise your rights or privacy choices regarding Personal Data collected by Plaid or Dwolla, you should contact Plaid or Dwolla.
USE OF SERVICES BY MINORS
Upside prohibits the use of the Services by anyone under the age of sixteen (16), and we do not knowingly collect Personal Data from individuals under 16. If you are under the age of 16, you may not create an Upside account or submit any Personal Data through the Services. We encourage parents and legal guardians to monitor their children’s Internet and mobile device usage and to help enforce our Privacy Policy by instructing their children under the age of 16 never to provide Personal Data on our Services.
CROSS-BORDER TRANSFER
Your Personal Data may be stored and processed in any country or region where we have facilities or engage service providers. By using the Services, you understand that your Personal Data will be transferred to countries outside of your country or region of residence, including to the United States, which may have data protection rules that are different from those of your country or region.
UPDATES TO THIS PRIVACY POLICY
The “Last Updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.
CONTACTING US
If you have any questions about this Privacy Policy, or the data practices of the Services, including if you need access to our Privacy Policy in a different format please contact us:
U.S. STATE CONSUMER PRIVACY SUPPLEMENT
The following chart details which categories of Personal Data we collect and process, as well as which categories of Personal Data we disclose to third parties for our operational business or commercial purposes, including within the preceding 12 months. The chart also details the categories of Personal Data that we “sell” to third parties or “share” for purposes of cross-context behavioral or targeted advertising, including within the preceding 12 months.
We retain each category of Personal Data, including Sensitive Personal Data, as described above under RETENTION PERIOD.
We do not knowingly sell or “share” Personal Data, including Sensitive Personal Data, of minors under 16 years of age.
We collect, use, and disclose Personal Data for the purposes described above under PERSONAL DATA PROCESSING PURPOSES.
We collect, use, and disclose Sensitive Personal Data for purposes of performing services for our business, providing goods or performing services as requested or reasonably expected by you, ensuring safety, security, and integrity, countering wrong or unlawful actions, short-term transient use, servicing accounts, providing customer service, verifying customer information, processing payments, activities relating to quality and safety control or product improvement, and other collection and processing that is not for the purpose of inferring characteristics about an individual. We do not use Sensitive Personal Data for additional purposes.
We collect Personal Data from several sources as described above under CATEGORIES AND SOURCES OF PERSONAL DATA COLLECTED.
Your Privacy Choices
You may request that we:
To make a request, please use one of the following methods:
You have the right to be free from unlawful discrimination for exercising your rights under applicable law.
We will verify and respond to your request consistent with applicable law, considering the type and sensitivity of the Personal Data subject to the request. For your protection, we may need to request information such as your name and email address to verify your identity and protect against fraudulent requests. In accordance with applicable law, Upside may require you to re-enter your login credentials in the App prior to our handling of your request regarding your Personal Data. Note that a request to delete your Personal Data will include the deletion of your login credentials, and thus your Upside account, which may prevent you from using some or all of the Services.
Opt-out Preference Signals
We also process opt-out preference signals, such as the Global Privacy Control. These signals set your opt-out preferences only for the particular browser or device you are using. For information about how to use the Global Privacy Control, please visit https://globalprivacycontrol.org/.
Appeals
If we refuse to take action on your request, you may request to appeal this refusal within a reasonable period after you have received notice of the refusal. You may file a request to appeal by using one of the methods listed above under “Your Privacy Choices.” We will respond to your request consistent with applicable law.
Authorized Agents
If an agent would like to make a request on your behalf as permitted by applicable law, the agent may use the submission methods noted above under “Your Privacy Choices.” As part of our verification process, we may request that the agent provide, as applicable, proof concerning their status as an authorized agent. In addition, we may require that you verify your identity as described above or confirm that you provided the agent permission to submit the request.
De-Identified Information
Where we maintain or use de-identified information, we will continue to maintain and use that information only in a de-identified form and will not attempt to re-identify the information.