Skip to content
Menu

This describes what we actually do with your data.We hold ourselves to it, and we will give you at least 30 days’ notice before changing it. To ask what we hold about you, to export it, or to have it deleted, email notifications@uberagencyos.com.

Privacy & data

Last updated 17 August 2026

What we store

  • Account data: name, email address, a hashed password, and which workspaces you belong to.
  • Workspace data: the clients, projects, tasks, content items, campaigns, media plans, invoices and expenses your agency enters. This can include your clients’ business contact details and tax registration numbers.
  • Integration credentials: access tokens for services you connect, encrypted at rest.
  • Audit records: who did what, when, for actions that change money or access.

We do not store payment card numbers. Uploaded receipts are streamed to the storage account you connect and are not retained on our servers.

Why we hold it

To run the service you asked for: showing your records back to you, calculating totals, syncing the ad platforms you connected, and keeping an audit trail that makes financial changes accountable. We do not sell data, do not share it with advertisers, and do not use your workspace data to train machine-learning models.

Who else processes it

Subprocessors and what each one handles
ProcessorRoleData involved
VercelApplication hosting and deliveryRequests, logs
NeonManaged Postgres databaseAll workspace records
Google (Drive API)Receipt storage, only when you connect itFiles you upload, stored in your own Drive
Meta (Marketing API)Ad performance sync, only when you connect itCampaign metrics from your ad account
Google (Ads API)Ad performance sync, only when you connect itCampaign metrics from your ad account

The three integrations run only if you connect them, using credentials you supply, against accounts you already control.

Getting your data out, or deleted

Every module exports to CSV from inside the app, on any plan, at any time, including during a trial and after cancellation; media plans also export to Excel. To request a full export or the deletion of a workspace, send the request through the contact form using the owner’s address; we act on it and confirm in writing. Deleting a workspace removes its records from the live database; backups age out on the database provider’s retention schedule.

Retention

Workspace data is kept for as long as the workspace exists. Cancelling makes financial history read-only rather than deleting it, because an agency’s books outlive its subscription. Deletion is always something you ask for, never something that happens because an invoice went unpaid.

Security

Passwords are hashed with bcrypt. Integration tokens are encrypted at rest. Access to a workspace is scoped by membership and role on every request, and money-changing actions are recorded in an audit log. Transport is HTTPS throughout.

Contact

Privacy questions and data requests go through the contact form. Say what you need in the message and we reply to the address you give us.