BundleUp logo
BundleUp Icon

Privacy Policy

Effective Date: August 18, 2026

This Privacy Policy explains how OneClick Lab, LLC, a Delaware limited liability company doing business as BundleUp (“BundleUp,” “we,” “us,” or “our”), collects, uses, shares, stores, and protects information when you visit bundleup.io or use our APIs, dashboards, SDKs, and related services (together, the “Services”). It applies to visitors to our website, to people who create an account, and to the data we handle on behalf of our customers. If you do not agree with this policy, please do not use the Services.

1. Our Role: Controller and Processor

We act as a controller for the information we collect about you directly — your account details, billing information, support conversations, and the technical data generated when you use our website and dashboard. We decide how that information is used, and this policy describes those decisions.

We act as a processor for the data we handle on our customers’ behalf when they use BundleUp to build integrations. That includes the OAuth tokens, API credentials, and request and response payloads belonging to their end users. Our customer is the controller of that data, decides why it is processed, and is responsible for providing notices and obtaining consents. We process it only on their documented instructions, which are given through their configuration and API calls. If you are an end user of a product built on BundleUp and want your data corrected or deleted, please contact that product directly; we will support them in responding to you.

2. Information You Provide

When you create an account we collect your name, email address, and password or, if you sign in with a third-party identity provider, the basic profile information that provider returns to us. We also collect your company or workspace name, the names and email addresses of the team members you invite, and any preferences you configure. If you subscribe to a paid plan we collect billing contact details and a limited record of your payment method, such as the card brand and last four digits; full card numbers are collected and stored by our payment processor and never reach our servers. When you email support, respond to a survey, or fill in a form on our website, we keep the content of that correspondence and any information you choose to include in it.

3. Information We Process on Your Behalf

When you use BundleUp to create and operate integrations, we process the OAuth access and refresh tokens, API keys, and client secrets that authorize those connections, along with connection metadata such as the provider, scopes granted, account identifiers, expiry times, and connection status. We also process the requests you send through our proxy and the responses returned by the third-party provider, because routing, retrying, transforming, and monitoring those calls is the service you are asking us to perform. We retain request and response metadata for observability and troubleshooting, and we keep payload bodies only for the retention window associated with your plan.

4. Information Collected Automatically

Our systems record technical information whenever you use the Services, including your IP address, browser and device type, operating system, referring page, and the pages or dashboard screens you view. Our API and proxy record usage metrics such as request counts, endpoints called, response status codes, latency, error rates, and rate-limit events, which we need in order to operate the platform, detect abuse, and bill usage accurately. Our error monitoring tooling records diagnostic information, including stack traces and the context surrounding an exception, when something goes wrong.

5. How and Why We Use Information

We use the information described above to provide and operate the Services, to authenticate you and keep your account secure, to establish and refresh the connections you create, and to route, retry, and monitor the API requests that flow through our proxy. We use usage data to enforce plan limits and rate limits, to detect and prevent fraud and abuse, and to calculate and invoice your usage. We use technical and error data to debug problems, measure performance, and improve the reliability and design of the platform, and we use your contact information to respond to support requests and to send you service notices about outages, security matters, billing, and material changes to our terms or this policy.

We send marketing email only where you have opted in or where permitted by law, and every marketing message includes a way to unsubscribe; opting out of marketing does not stop transactional and service messages that are necessary to operate your account. We also use information as needed to comply with legal obligations and to establish, exercise, or defend legal claims. We do not sell your data, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train machine learning models.

6. Legal Bases for Processing

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar rules, we rely on the following legal bases. We process your account, connection, and billing data because it is necessary to perform our contract with you. We process usage, security, and diagnostic data on the basis of our legitimate interests in securing the platform, preventing abuse, understanding how the Services are used, and improving them, balanced against your rights. We rely on your consent for analytics cookies and for optional marketing communications, and you may withdraw that consent at any time. We process certain information because we are required to do so by law, for example to keep accurate tax and accounting records.

7. Cookies and Analytics

We use strictly necessary cookies to keep you signed in, to maintain session state, and to protect our forms and sign-up flows from automated abuse; these cannot be switched off because the site and dashboard will not work without them. We also use analytics cookies, loaded through Google Tag Manager, to understand how visitors find and move through our website so that we can improve it. Analytics cookies are set only if you consent through the banner shown on your first visit, your choice is remembered for up to twelve months, and you will be asked again after that or whenever you clear your browser storage. We do not use cookies for advertising and we do not allow third parties to use them to track you across other websites.

8. How We Share Information

We share information only with service providers who help us run the Services, and each of them is bound by contract to use the data only for the purposes we specify and to protect it appropriately. Cloudflare hosts our edge network, workers, and key-value storage and provides security and bot protection. Vercel hosts our web applications and related file storage. Amazon Web Services provides key management for the encryption of credentials as well as object storage. Our managed PostgreSQL provider hosts the primary database. Stripe processes payments and stores payment card information. Resend delivers our transactional email. Sentry provides error and performance monitoring, and Trigger.dev runs our scheduled and background jobs. Google Tag Manager and Google Analytics provide website analytics where you have consented, and Sanity hosts the content of our marketing site and blog.

We may also disclose information when we are legally required to do so, for example in response to a subpoena, court order, or other valid legal process; where we believe in good faith that disclosure is necessary to protect the rights, safety, or property of BundleUp, our customers, or the public; and to our professional advisers where necessary. Unless we are prohibited from doing so, we will make reasonable efforts to notify you before disclosing your data in response to a legal request. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, and we will notify you before your data becomes subject to a different privacy policy. We do not share data for advertising purposes.

We maintain a current list of sub-processors and will provide it, along with advance notice of material changes, to customers who request it at support@bundleup.io.

9. International Data Transfers

We operate from the United States, and our infrastructure providers operate globally, so your information may be processed in the United States or in any other country where those providers maintain facilities. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses together with the UK Addendum where applicable, and we take supplementary measures such as encryption in transit and at rest. Customers who need these clauses executed as part of a data processing addendum can request one at support@bundleup.io.

10. Data Retention

We keep information only as long as we need it. Account and workspace data is retained while your account is active and for a short period afterwards so that you can reactivate, after which it is deleted or anonymized. Credentials and tokens are deleted when you remove the associated connection or close your account, and the corresponding key material becomes unusable. Request logs are retained according to your plan: one day on the Free plan, fourteen days on Pro, and thirty days on Enterprise, after which they are automatically purged by a daily cleanup job. Aggregated usage counters and invoices are kept longer because we need them for billing accuracy, tax, and accounting obligations, and security and audit logs are kept for a limited period appropriate to their purpose. Residual copies may persist in encrypted backups for a short time until those backups rotate out on their normal cycle.

11. Security

We encrypt all traffic in transit using TLS, and we encrypt OAuth tokens, client secrets, and other sensitive credentials at rest using AES-256-GCM with envelope encryption, where the data encryption keys are themselves wrapped by a customer master key held in AWS Key Management Service. Access to production systems is restricted to authorized personnel on a need-to-know basis, protected by strong authentication, and logged. We separate environments, scope credentials narrowly, apply rate limiting and bot protection at the edge, and keep our dependencies patched.

If we become aware of a security incident affecting your personal data, we will investigate promptly, take steps to contain and remediate it, and notify you without undue delay where required by law or by our agreement with you, along with the information you need to meet your own notification obligations. Even so, no system is completely secure, and we cannot guarantee absolute security. You play an important part by protecting your API keys, enabling available account security features, rotating credentials you suspect are exposed, and limiting the scopes you request from third-party providers.

12. Your Privacy Rights

Depending on where you live, you may have the right to access the personal data we hold about you, to receive a copy of it in a portable format, to correct inaccuracies, to request deletion, to object to or restrict certain processing, and to withdraw consent you previously gave. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

If you are a California resident, you have the right to know what personal information we collect, use, and disclose, the right to request deletion or correction, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we do not use or disclose sensitive personal information beyond the purposes permitted by law. We will not discriminate against you for exercising any of these rights.

To exercise any right, email us at support@bundleup.io from the address associated with your account or use the controls in the dashboard. We will verify your identity before acting and will respond within the time required by applicable law, normally within thirty days. You may authorize an agent to make a request on your behalf, and we may ask for proof of that authorization. If your request concerns data we process on behalf of one of our customers, we will refer you to that customer and assist them in responding.

13. Children’s Privacy

The Services are intended for businesses and developers and are not directed at children. We do not knowingly collect personal information from anyone under sixteen years of age. If we learn that we have collected such information without the consent required by law, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at support@bundleup.io.

14. Do Not Track and Global Privacy Control

Because there is no common industry standard for responding to “Do Not Track” browser signals, our website does not respond to them. We do honor the Global Privacy Control signal where required by law by treating it as an opt-out of analytics cookies for that browser.

15. Changes to This Policy

We may update this policy as the Services and the law evolve. When we make material changes, we will revise the effective date above and notify you through the dashboard or by email before the changes take effect. We encourage you to review this page periodically, and your continued use of the Services after an update means you accept the revised policy.

16. Contact

If you have questions about this policy, want to exercise a privacy right, or need a data processing addendum, please contact us.
OneClick Lab, LLC
Email: support@bundleup.io

We use cookies to understand how you use our site and to improve your experience. Analytics cookies are only set once you accept. See our Privacy Policy for details.