Privacy & Security

Privacy Policy

Last Updated: January 14th, 2026

1. Introduction

This Privacy Policy describes how 99CODESHOP LLC (DBA "OneUpAI") and ONEUPAI SOLUTIONS INC (collectively, "OneUpAI," "we," "us," or "our") collect, use, disclose, and protect your personal information when you use our website at https://oneupai.com (the "Site"), our AI automation services, software development services, SaaS products, educational content, and related services (collectively, the "Services").

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the Personal Information Protection and Electronic Documents Act (PIPEDA) for users in Canada, and various U.S. state privacy laws including the California Consumer Privacy Act (CCPA) and its amendments.

By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.

2. Data Controllers

For users in the United States:

99CODESHOP LLC (DBA "OneUpAI")

For users in Canada and other jurisdictions:

ONEUPAI SOLUTIONS INC

For privacy-related inquiries, please contact us at privacy@oneupai.com. For legal matters, contact legal@oneupai.com.

3. Information We Collect

3.1 Information You Provide to Us

We collect information that you voluntarily provide when you:

  • Create an account or register for our Services
  • Subscribe to our SaaS products or services
  • Request information, support, or consultations
  • Participate in our educational content, community forums, or webinars
  • Schedule appointments or consultations through our calendar system
  • Communicate with us via email, phone, or chat

This information may include:

  • Personal identifiers (name, email address, phone number)
  • Business information (company name, job title, industry)
  • Account credentials (username, password)
  • Communication preferences and interests
  • Any other information you choose to provide

3.2 Payment Information

We use Stripe, a third-party payment processor, to process subscription payments and transactions. We do not directly collect or store your complete payment card information. Stripe collects and processes payment information in accordance with their privacy policy and PCI-DSS standards. We may receive limited payment information such as the last four digits of your card and billing address for record-keeping purposes.

3.3 Automatically Collected Information

When you access our Site or use our Services, we automatically collect certain information, including:

  • Device information (device type, operating system, browser type)
  • IP address and approximate geographic location
  • Usage data (pages visited, features used, time spent, navigation patterns)
  • Referral source and campaign information
  • Cookies and similar tracking technologies (see Section 8)

3.4 Lead and Calendar Data

We collect and process lead information and calendar scheduling data when you book consultations, demos, or other appointments. This includes your contact information, appointment preferences, time zone, and any information you provide during the scheduling process.

3.5 Third-Party Service Data

If you integrate third-party services with our platform or authorize us to access third-party accounts on your behalf (for AI automation purposes), we may collect information from those services as necessary to provide our Services, subject to the privacy policies and permissions of those third-party platforms.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our Services
  • To process your transactions and manage subscriptions
  • To create and manage your account
  • To communicate with you about your account, services, and updates
  • To provide customer support and respond to inquiries
  • To deliver AI automation services, software development, and SaaS solutions
  • To provide access to educational content and community platforms
  • To schedule and manage appointments and consultations
  • To send marketing communications (with your consent where required)
  • To personalize your experience and recommend relevant content
  • To analyze usage patterns and improve our Services
  • To detect, prevent, and address technical issues, fraud, and security threats
  • To comply with legal obligations and enforce our agreements

5. Legal Bases for Processing (EEA Users)

For users in the European Economic Area, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide Services you've requested or to enter into a contract with you
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as improving Services, preventing fraud, and ensuring security
  • Consent: Processing based on your explicit consent, such as for marketing communications
  • Legal Obligation: Processing necessary to comply with legal requirements

6. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

6.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our business and providing Services:

  • Stripe: Payment processing
  • Supabase: Database and backend services
  • Vercel: Hosting and content delivery
  • Clerk: Authentication and user management

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

6.2 Business Transfers

If we are involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

6.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.

6.4 With Your Consent

We may share information with third parties when you have given us explicit consent to do so.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States and Canada. These countries may have different data protection laws than your jurisdiction. When we transfer personal data from the EEA or UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your information in accordance with GDPR requirements.

8. Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities and to provide and improve our Services. Cookies are small data files stored on your device that help us recognize you, remember your preferences, and analyze site usage.

8.1 Types of Cookies We Use

  • Essential Cookies: Required for the operation of our Services (authentication, security)
  • Functional Cookies: Enable enhanced functionality and personalization
  • Analytics Cookies: Help us understand how visitors use our Site
  • Marketing Cookies: Track your visits across websites to deliver relevant advertising

You can control cookies through your browser settings. However, disabling certain cookies may affect your ability to use some features of our Services.

9. Data Retention

We retain your personal information for as long as necessary to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. When we no longer need your information, we will securely delete or anonymize it. Specific retention periods depend on the type of data and the purpose for which it was collected:

  • Account information: Retained for the duration of your account plus applicable legal requirements
  • Transaction records: Retained for 7 years for tax and accounting purposes
  • Marketing communications: Retained until you unsubscribe
  • Analytics data: Retained for 26 months

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

10.1 Rights for All Users

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Opt-out: Unsubscribe from marketing communications

10.2 Additional Rights for EEA Users (GDPR)

  • Data Portability: Receive your data in a structured, machine-readable format
  • Restriction of Processing: Request limitation on how we process your data
  • Object to Processing: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for processing based on consent
  • Lodge a Complaint: File a complaint with your local data protection authority

10.3 Additional Rights for Canadian Users (PIPEDA)

  • Access to information about our privacy practices
  • Challenge the accuracy and completeness of your information
  • File a complaint with the Privacy Commissioner of Canada

10.4 Additional Rights for California Users (CCPA/CPRA)

  • Right to know what personal information is collected, used, shared, or sold
  • Right to opt-out of the sale or sharing of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights
  • Right to limit use of sensitive personal information

10.5 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@oneupai.com. We will respond to your request within the timeframes required by applicable law (typically 30 days for GDPR requests, 45 days for CCPA requests). We may need to verify your identity before processing your request.

11. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and monitoring
  • Access controls and authentication measures
  • Employee training on data protection
  • Secure third-party service provider agreements

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

12. Children's Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@oneupai.com, and we will delete such information from our systems.

13. Third-Party Links and Services

Our Site and Services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to such third-party services. We encourage you to review the privacy policies of any third-party services you access through our Site or Services.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated Privacy Policy on our Site and updating the "Last Updated" date. For significant changes, we may provide additional notice, such as via email or a prominent notice on our Site. Your continued use of our Services after such changes constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For Privacy Inquiries:

Email: privacy@oneupai.com

For Legal Matters:

Email: legal@oneupai.com

Mailing Address:

99CODESHOP LLC (DBA "OneUpAI")

4030 Wake Forest Road, STE 349

Raleigh, NC 27609

USA

ONEUPAI SOLUTIONS INC

67 D30 Suite 1003

Vaughan, ON L4L 9J8

Canada

15.1 EEA Representative

For users in the European Economic Area, you may also contact our designated representative for GDPR matters at privacy@oneupai.com

By using OneUpAI's Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Chat with OneUpAI