Lifted Work Privacy Policy

Last updated: August 11, 2026

Thank you for choosing Lifted Work, Inc. (“Lifted Work,” “we,” “us,” or “our”). We respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy explains what information we collect, how we use it, and your rights. It applies to visitors to https://www.liftedwork.com, account holders, and all Authorized Users of our web and mobile applications (collectively, the “Service“).

Note: If your organization uses Lifted Work, we process the personal data in its workspace on its behalf, as a service provider/processor. Where a Data Processing Addendum has been signed, it governs that processing and prevails over anything inconsistent in this Policy.


1. Information We Collect

Category Examples Source
Account Data Name, business e‑mail, job title, billing address, username, hashed password Provided by you / your Agency
Client Data End‑customer names, contact details, project notes, uploaded files Provided by Authorized Users
Usage Data Log files (IP, browser type, timestamps, requests, error traces), feature interactions, clickstream Collected automatically via Fly.io and Neon logs
Device & Cookie Data Cookies, pixel tags, device IDs Cookies / tracking tech (see § 7)
Analytics & Marketing Data Page views, campaign parameters Google Analytics, Meta/Facebook Pixel
AI Input/Output Prompts, completions, embedding vectors Processed by Anthropic and OpenAI through our API integrations

We do not intentionally collect sensitive personal data (e.g., health or biometric data). Agencies are contractually prohibited from uploading such data without a lawful basis and proper safeguards.


2. How We Use Information

We process personal data to:

  1. Provide & secure the Service – authenticate users, host projects, detect fraud, and maintain logs;
  2. Improve & develop features – debug errors, monitor performance, and decide what to build next. We do not train AI models on your data;
  3. Bill & administer accounts – manage subscriptions, process payments via Stripe;
  4. Communicate – send transactional e‑mails, product updates, and (with consent) marketing messages;
  5. Comply with law – respond to lawful requests, enforce Terms, and protect rights.

3. Legal Bases (EU/UK GDPR)

Purpose Legal Basis
Account creation, Service delivery Contract (Art. 6 (1)(b))
Security & fraud prevention Legitimate interest (Art. 6 (1)(f))
Marketing e‑mails Consent (Art. 6 (1)(a))
Compliance with legal obligations Legal obligation (Art. 6 (1)(c))

4. Sharing & Disclosures

We do not sell personal data. We share it only:

  • With Sub‑processors – cloud & analytics vendors listed at /subprocessors;
  • Within a Customer workspace – Agencies control visibility of their own data;
  • For legal reasons – to comply with subpoenas or prevent harm;
  • In corporate transactions – merger, acquisition, or asset sale (with notice).

5. International Data Transfers

We are headquartered in Florida, USA, and the Service is hosted in the United States. Data may also be processed in other regions where our Sub‑processors operate. If you are transferring personal data from the EEA, the UK, or Switzerland and need a specific transfer mechanism in place, see /dpa and we will cover it in the addendum we send you.


6. Data Retention

Data Type Retention Period
Account & billing records Life of account + 7 years (tax/audit)
Client/Project data Until Agency deletes or 30 days after subscription ends
Back‑ups Up to 90 days
Security & audit logs Up to 365 days
Marketing unsubscribes Permanently (to honour opt‑out)

You can delete items at any time via the app. Deletion removes them from the active database immediately and works through to back‑ups within 90 days, unless a legal hold applies.


7. Cookies & Tracking Technologies

We use:

  • Essential cookies – session management, CSRF protection;
  • Analytics cookies – Google Analytics (IP‑anonymized);
  • Advertising pixels – Meta/Facebook (marketing site only).

Non‑essential cookies and pixels run on our marketing site only, not inside the application. You can control them through your browser settings, and directly at Google and Meta. The full list of tools on our marketing site is at /subprocessors.


8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict personal data, and to object to processing or withdraw consent.

  • EEA/UK: Contact privacy@liftedwork.com – we will respond within 30 days.
  • California: We honour CCPA/CPRA rights and do not sell personal data.

If we process your data on behalf of an Agency, please direct requests to that Agency; we will assist them.


9. Children

The Service is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us to delete it.


10. Security

We employ encryption in transit and at rest, access controls on internal systems, and monitoring of our application and hosting platform. Our Gmail integration has passed Google’s CASA (Cloud Application Security Assessment) review, which Google requires of applications that access Gmail data. No system is completely secure, and we do not claim otherwise.


11. Changes to This Policy

We may update this Policy to reflect changes in law or in our practices. When we do, we update the “Last updated” date above, and where a change materially affects how we handle your personal data we will also announce it by e‑mail or in‑app before it takes effect. Continued use after the effective date constitutes acceptance.


12. Contact Us

Lifted Work, Inc. 1343 Main Street, Sarasota, FL 34236, USA E‑mail: privacy@liftedwork.com

If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority, but we hope you will contact us first so we can address your concerns.