Legal / Privacy Policy

Privacy Policy

What personal data Uplift Funnel collects, why, how long it is kept, and the rights you have over it under the GDPR and KVKK.

Effective 2026-07-25

1. Two different roles, and why it matters

Uplift Funnel handles personal data in two distinct capacities, and your rights differ depending on which one applies.

  • We are the controller for data about our own customers: the people who sign up for a dashboard account. That is what most of this policy covers.
  • We are a processor for data about the end users of our customers apps. Our customer decides what is collected and why; we act on their instructions. If you used an app that runs an Uplift Funnel onboarding flow and you want your data removed, please contact that app developer — they are the controller, and we will assist them. The terms governing this are in our Data Processing Agreement.

The controller for customer data is Doğukan Özgür Yılmaz, TODO_STREET_ADDRESS, TODO_CITY, TODO_POSTAL_CODE, Türkiye. Contact: privacy@upliftfunnel.com.

2. What we collect about you, as our customer

  • Account details — name, email address, a hashed password, and email verification status. We never store your password in a readable form.
  • Workspace content — the apps you register, your flows and drafts, templates, uploaded images and video, team members you invite, and audit records of who changed what.
  • Billing data — a customer and subscription identifier from Paddle, the plan you are on, and your invoice history. Paddle is the merchant of record and handles your card details; we never see or store card numbers.
  • Technical logs — IP address, user agent, and timestamps, used to authenticate you, apply rate limits, and investigate abuse or errors.
  • Support correspondence — what you write to us and our replies.

3. What the SDK collects in your app, and what it deliberately does not

When you integrate an Uplift Funnel SDK, it reports funnel analytics so that your dashboard can show where users drop off. The events carry: an anonymous device identifier that the SDK generates itself, a session identifier, the flow and screen involved, the event type, a timestamp, and any answers your flow was designed to collect.

If you call our identify method, an identifier you choose is also stored and linked to the anonymous one. If you connect a subscription provider such as RevenueCat or Adapty, we receive transaction records from that provider — product, price, currency, transaction identifiers, and trial or renewal status — so that revenue can be attributed to a funnel.

The SDK does not read the advertising identifier (IDFA), the vendor identifier (IDFV), the Android advertising ID, or any other device or cross-app tracking identifier. The anonymous identifier is generated by the SDK, is scoped to your app, is not shared with anyone, and cannot be used to track a person across apps or websites. Because of that, integrating Uplift Funnel does not by itself require an App Tracking Transparency prompt. Our documentation sets out exactly what to declare in App Privacy.

One exception, and it is entirely under your control: if you enable a mobile measurement partner integration such as AppsFlyer or Adjust, that partner sends us postbacks which may contain an advertising identifier that they collected. We store it only to match their attribution data to a funnel. If you do not enable such an integration, we never receive one.

4. Why we process it, and on what legal basis

  • To provide the service — performance of our contract with you.
  • To bill you — performance of contract, and compliance with tax and accounting law.
  • To keep the platform secure and available — our legitimate interest in preventing abuse, fraud, and outages.
  • To send transactional email such as email verification, invitations, and billing notices — performance of contract.
  • To send product or marketing email — your consent, withdrawable at any time from the message itself.
  • To improve the product using aggregated, non-identifying usage statistics — our legitimate interest.

We do not sell personal data, and we do not use your workspace content or your end user data to train machine-learning models.

5. AI features

The optional AI features — flow generation, Copilot, and Insights — send content to OpenAI in order to produce a result. What is sent is the flow content you are working on and aggregated funnel metrics such as drop-off rates. End-user identifiers are not sent. OpenAI acts as our sub-processor and does not use the content to train its models. If you would rather nothing left the platform, do not use these features.

6. Who we share it with

Only the sub-processors listed on our Sub-processors page, each for the narrow purpose stated there, plus: professional advisers where necessary, authorities where we are legally required, and an acquirer if the business is sold — in which case this policy continues to apply until you are notified of a replacement.

7. International transfers

We are based in Türkiye and some sub-processors are in the United States or the European Union, so your data will be transferred internationally. Where personal data leaves the EEA or the UK, transfers rely on the European Commission Standard Contractual Clauses or another lawful transfer mechanism. Where KVKK applies, transfers are made on the basis of your explicit consent or another lawful ground under Article 9.

8. How long we keep it

  • Account and workspace data — for as long as your account is open, then 30 days after closure so that you can reactivate or export, then deleted.
  • Funnel analytics events — retained according to the retention period of your plan, then deleted.
  • Revenue and invoice records — kept for as long as tax and accounting law requires, which is longer than the rest.
  • Technical logs — a short rolling window, typically 30 days.

9. Your rights

Subject to the conditions in the GDPR and, where it applies, KVKK, you may request access to your data, correction of it, deletion, restriction of processing, a portable copy, and you may object to processing based on legitimate interests. You may withdraw consent at any time where consent is the basis.

Write to privacy@upliftfunnel.com and we will respond within 30 days. You may also complain to your local data protection authority; in Türkiye that is the Kişisel Verileri Koruma Kurumu.

If your request concerns data collected inside a third-party app that uses Uplift Funnel, we will forward it to that app developer, who is the controller.

10. Security

Data is encrypted in transit and at rest, credentials for connected services are stored under envelope encryption, access to production systems is restricted and logged, and API keys are stored only as hashes. More detail is on our Security page, including how to report a vulnerability.

11. Cookies

See our Cookie Policy. In short: the website itself needs only a session cookie once you sign in, and we do not run advertising trackers on it.

12. Children

The platform is for developers and businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a customer. Whether the apps built with Uplift Funnel are directed at children is a matter for their developers, who must configure their flows accordingly.

13. Changes

We will post any change on this page and update the date at the top. For material changes we will email account holders at least 30 days before the change takes effect.