Lifted Work Privacy Policy
Last updated: August 11, 2026
Thank you for choosing Lifted Work, Inc. (“Lifted Work,” “we,” “us,” or “our”). We respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy explains what information we collect, how we use it, and your rights. It applies to visitors to https://www.liftedwork.com, account holders, and all Authorized Users of our web and mobile applications (collectively, the “Service“).
Note: If your organization uses Lifted Work, we process the personal data in its workspace on its behalf, as a service provider/processor. Where a Data Processing Addendum has been signed, it governs that processing and prevails over anything inconsistent in this Policy.
1. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, business e‑mail, job title, billing address, username, hashed password | Provided by you / your Agency |
| Client Data | End‑customer names, contact details, project notes, uploaded files | Provided by Authorized Users |
| Usage Data | Log files (IP, browser type, timestamps, requests, error traces), feature interactions, clickstream | Collected automatically via Fly.io and Neon logs |
| Device & Cookie Data | Cookies, pixel tags, device IDs | Cookies / tracking tech (see § 7) |
| Analytics & Marketing Data | Page views, campaign parameters | Google Analytics, Meta/Facebook Pixel |
| AI Input/Output | Prompts, completions, embedding vectors | Processed by Anthropic and OpenAI through our API integrations |
We do not intentionally collect sensitive personal data (e.g., health or biometric data). Agencies are contractually prohibited from uploading such data without a lawful basis and proper safeguards.
2. How We Use Information
We process personal data to:
- Provide & secure the Service – authenticate users, host projects, detect fraud, and maintain logs;
- Improve & develop features – debug errors, monitor performance, and decide what to build next. We do not train AI models on your data;
- Bill & administer accounts – manage subscriptions, process payments via Stripe;
- Communicate – send transactional e‑mails, product updates, and (with consent) marketing messages;
- Comply with law – respond to lawful requests, enforce Terms, and protect rights.
3. Legal Bases (EU/UK GDPR)
| Purpose | Legal Basis |
|---|---|
| Account creation, Service delivery | Contract (Art. 6 (1)(b)) |
| Security & fraud prevention | Legitimate interest (Art. 6 (1)(f)) |
| Marketing e‑mails | Consent (Art. 6 (1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6 (1)(c)) |
4. Sharing & Disclosures
We do not sell personal data. We share it only:
- With Sub‑processors – cloud & analytics vendors listed at /subprocessors;
- Within a Customer workspace – Agencies control visibility of their own data;
- For legal reasons – to comply with subpoenas or prevent harm;
- In corporate transactions – merger, acquisition, or asset sale (with notice).
5. International Data Transfers
We are headquartered in Florida, USA, and the Service is hosted in the United States. Data may also be processed in other regions where our Sub‑processors operate. If you are transferring personal data from the EEA, the UK, or Switzerland and need a specific transfer mechanism in place, see /dpa and we will cover it in the addendum we send you.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account & billing records | Life of account + 7 years (tax/audit) |
| Client/Project data | Until Agency deletes or 30 days after subscription ends |
| Back‑ups | Up to 90 days |
| Security & audit logs | Up to 365 days |
| Marketing unsubscribes | Permanently (to honour opt‑out) |
You can delete items at any time via the app. Deletion removes them from the active database immediately and works through to back‑ups within 90 days, unless a legal hold applies.
7. Cookies & Tracking Technologies
We use:
- Essential cookies – session management, CSRF protection;
- Analytics cookies – Google Analytics (IP‑anonymized);
- Advertising pixels – Meta/Facebook (marketing site only).
Non‑essential cookies and pixels run on our marketing site only, not inside the application. You can control them through your browser settings, and directly at Google and Meta. The full list of tools on our marketing site is at /subprocessors.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict personal data, and to object to processing or withdraw consent.
- EEA/UK: Contact privacy@liftedwork.com – we will respond within 30 days.
- California: We honour CCPA/CPRA rights and do not sell personal data.
If we process your data on behalf of an Agency, please direct requests to that Agency; we will assist them.
9. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us to delete it.
10. Security
We employ encryption in transit and at rest, access controls on internal systems, and monitoring of our application and hosting platform. Our Gmail integration has passed Google’s CASA (Cloud Application Security Assessment) review, which Google requires of applications that access Gmail data. No system is completely secure, and we do not claim otherwise.
11. Changes to This Policy
We may update this Policy to reflect changes in law or in our practices. When we do, we update the “Last updated” date above, and where a change materially affects how we handle your personal data we will also announce it by e‑mail or in‑app before it takes effect. Continued use after the effective date constitutes acceptance.
12. Contact Us
Lifted Work, Inc. 1343 Main Street, Sarasota, FL 34236, USA E‑mail: privacy@liftedwork.com
If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority, but we hope you will contact us first so we can address your concerns.