Privacy, Terms, Refunds & Security
Last updated: May 31, 2026. These policies explain how UpRender handles data, Google Search Console and Analytics integrations, AI audits, sitemap and llms.txt generation, proxy-based bot rendering, refunds, service limits, and liability.
Plain-English Summary
UpRender helps JavaScript sites become readable by search and AI crawlers by serving crawler-ready HTML, metadata, schema, sitemaps, and llms.txt files according to customer configuration.
We process account data, billing data, domain settings, public site content, render/cache data, bot logs, analytics, Search Console data, AI audit outputs, support records, and security logs.
We do not guarantee search ranking, indexing, AI citation, revenue, crawler behavior, third-party API availability, or that AI-generated metadata is always accurate.
UpRender is infrastructure. You remain responsible for your website content, SEO strategy, robots directives, privacy notices, consent banners, proxy rules, backup strategy, and ensuring that routed pages are lawful and appropriate for bot rendering.
Privacy Policy
This Privacy Policy describes how UpRender collects, uses, stores, discloses, and protects personal data and customer content when you use our website, dashboard, APIs, middleware, proxy configuration, rendering service, Search Console integrations, Google Analytics integrations, sitemap tools, llms.txt generation, AI visibility audits, support channels, and related services.
1. Data categories we collect and process
| Category | Examples | Primary Purpose |
|---|---|---|
| Account and identity data | Name, business email, company name, role, account ID, password hash, OAuth identity, team memberships, plan information. | Create accounts, authenticate users, manage teams, provide support, enforce security, send service notices. |
| Billing and commercial data | Plan, subscription status, invoice history, billing contact, tax identifiers, payment method token, charge status, overage usage. | Process payments, issue invoices, calculate plan usage and overages, prevent fraud, handle refunds and credits. |
| Domain and configuration data | Customer domains, verified ownership status, integration type, proxy/CDN rules, route include/exclude rules, cache TTLs, headers, bot rules, sitemap settings. | Operate crawler routing, generate rendered HTML, enforce customer configuration, verify domains, troubleshoot integration issues. |
| Rendered content and cache data | HTML snapshots, metadata, structured data, Open Graph tags, canonical tags, page text, page status codes, sitemap files, llms.txt files, generated metadata suggestions. | Serve crawler-ready HTML to bots, cache responses, improve render reliability, power AI visibility scoring, generate SEO/AEO assets. |
| Bot request and activity logs | Requested URL, timestamp, crawler user-agent string, bot classification, the requesting server's IP address, status code, cache hit/miss, response time, page size, render error, quota usage. | Detect crawlers, provide bot analytics, debug failed renders, prevent abuse, monitor performance, calculate usage. |
| Google Search Console data | Verified properties, site ownership status, sitemap status, URL inspection details, index coverage signals, search analytics metrics, queries, clicks, impressions, position, country, device. | Show indexing and search performance in the dashboard, detect issues, submit or monitor sitemaps, support AI and SEO audits. |
| Google Analytics data | GA4 property identifiers, acquisition and engagement metrics, event and traffic reports, device/country/source dimensions, aggregated trends and dashboard views. | Display analytics alongside Search Console and rendering data, help customers understand performance, troubleshoot traffic and bot visibility changes. |
| AI audit and optimization data | Page content, headings, metadata, schema, entities, author/context signals, internal link context, issue reports, AEO scores, AI-generated recommendations. | Run AI visibility audits, recommend missing metadata, generate schema and llms.txt content, provide optimization reports. |
| Support and communications data | Tickets, chat messages, emails, call notes, diagnostic screenshots, logs submitted by users, feedback, survey responses. | Respond to support requests, investigate incidents, improve services, train support teams, maintain audit trails. |
| Website and cookie data (uprender.io only) | Device identifiers, browser type, IP address, cookie IDs, session data, pages visited, campaign parameters, approximate location. | Operate the website, remember preferences, secure sessions, measure marketing performance, detect abuse. |
2. What the rendering proxy does and does not receive
UpRender is designed to operate on publicly accessible content only. When a search or AI crawler requests one of your pages and your integration routes that request to UpRender, we receive the URL to render, the crawler's user-agent string, and the IP address of the requesting server.
Through the rendering proxy, UpRender does not intentionally receive or store your end visitors' personal data, authenticated session cookies, login tokens, or visitor IP addresses, and does not bypass authentication or connect to your internal systems.
3. How we use data
- Provide the platform: create accounts, verify domains, route crawler traffic, render pages, cache HTML snapshots, generate sitemaps and llms.txt files, and deliver rendered responses to supported bots.
- Operate Search Console and analytics features: check indexing issues, read URL inspection and search performance data, submit and monitor sitemaps when authorized, and display Search Console and Google Analytics metrics in one dashboard.
- Run AI visibility and metadata services: evaluate heading structure, metadata quality, schema coverage, entity context, author signals, content density, and topic relevance; generate or recommend missing metadata, structured data, and llms.txt content.
- Secure and improve the service: detect abuse, investigate suspicious activity, debug failed renders, improve bot detection, monitor uptime, enforce rate limits, and protect systems and customers.
- Communicate: send account notices, invoices, product updates, security alerts, policy updates, support replies, and administrative messages.
- Comply with law: meet tax, accounting, sanctions, consumer protection, privacy, security, and legal process obligations.
4. Legal bases for processing
Where GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases: performance of a contract, legitimate interests in operating and securing a B2B SaaS platform, compliance with legal obligations, consent for optional integrations and marketing, and protection of vital interests where necessary for security or incident response.
5. Controller, processor, and customer roles
For account, billing, marketing, security, and website analytics data, UpRender generally acts as an independent controller or business. For customer website content, rendered pages, bot logs, Google Search Console data, Google Analytics data, and other data processed on behalf of a customer organization to provide the service, UpRender generally acts as a processor, service provider, or contractor.
6. Sensitive data and restricted routes
Do not route sensitive, private, account-specific, checkout, payment, healthcare, government ID, children, confidential, or non-public pages to UpRender unless your enterprise agreement expressly permits it and the route is configured with appropriate controls.
7. Cookies and tracking technologies
We may use cookies, local storage, pixels, and similar technologies on our own marketing site and dashboard for authentication, preferences, security, analytics, fraud prevention, product usage measurement, and marketing attribution. Customers that use UpRender on their own websites remain responsible for configuring their own consent banners and cookie disclosures.
8. Data retention
- Account and billing records: retained while the account is active and for a reasonable period afterward for legal, tax, audit, dispute, and fraud-prevention purposes.
- Render cache: retained according to the applicable plan, route TTL, purge controls, or enterprise retention setting.
- Bot logs and diagnostics: retained for operational, analytics, security, and support purposes, with configurable retention for eligible plans.
- Zero-retention and private-mode options: where enabled and technically available, rendered content is not stored beyond delivery.
- Backups: deleted on a rolling schedule and may persist for a limited period after production deletion.
9. Disclosure and subprocessors
We may disclose data to subprocessors and service providers that help us host, secure, support, analyze, bill, and deliver the service. We do not sell customer website content, Google API user data, or rendered page data. We do not use customer website content to train third-party foundation models unless a customer expressly authorizes such use in writing.
10. International transfers
UpRender may process data in the United States, India, the European Economic Area, the United Kingdom, and other jurisdictions where we or our subprocessors operate. Where legally required, we use appropriate transfer mechanisms such as standard contractual clauses, data processing agreements, regional hosting, or other lawful safeguards.
11. Security measures
We use administrative, technical, and organizational controls designed to protect data, including encryption in transit (TLS), encryption at rest where supported, access control, role-based permissions, least-privilege administration, logging and monitoring, secret management, vulnerability management, backup procedures, incident response processes, and employee confidentiality obligations.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of your personal data. You may also have the right to withdraw consent and to lodge a complaint with a supervisory authority. To make a request, contact [email protected].
13. Children
UpRender is a B2B developer and SEO infrastructure service and is not intended for children. We do not knowingly collect personal data from children under 13 or the applicable age of digital consent.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page and, where appropriate, communicated through the dashboard, email, or other reasonable means.
Google API and Webmaster-Tool Disclosure
UpRender may allow customers to connect Google Search Console and Google Analytics. These integrations are optional and require an authorized user to authenticate through Google OAuth and approve the scopes shown on Google's consent screen.
1. Search Console features
- Listing and verifying sites or properties connected to your account
- Showing search performance, clicks, impressions, average position, country, device, query, and page-level performance
- Checking indexing, URL inspection, crawl, canonical, structured data, and page coverage signals
- Submitting, listing, reading, monitoring, or refreshing sitemap information when authorized
- Displaying Search Console issues alongside UpRender render status, cache status, bot traffic, AI visibility scores, and sitemap health
2. Google Analytics features
When you connect Google Analytics, you authorize UpRender to display permitted GA4 metrics and dimensions in the UpRender dashboard, such as traffic source, landing page, device, location, engagement, conversion/event, and trend data.
3. Limited Use commitment
UpRender's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell Google API data.
- We do not use Google API data for advertising or cross-context behavioral advertising.
- We do not use Google API data to train generalized AI models.
- We restrict human access to Google API data to support, security, legal, compliance, or customer-authorized purposes.
- You may disconnect Google integrations from the dashboard or by revoking access in your Google account.
AI Audit, Metadata, Schema, Sitemap, and llms.txt Processing
UpRender may analyze customer pages using automated systems and AI-assisted tools to identify missing titles, descriptions, Open Graph tags, canonical tags, headings, schema, entity context, author signals, content density, duplicate metadata, sitemap gaps, llms.txt opportunities, crawler-readability issues, and other AI visibility or SEO/AEO signals.
1. AI-generated outputs
AI-generated metadata, structured data, issue summaries, llms.txt entries, page scores, recommendations, and audit reports are machine-generated outputs. They may be inaccurate, incomplete, duplicated, outdated, or unsuitable for a particular business, jurisdiction, search engine, or AI system. Customers are responsible for reviewing, approving, editing, testing, and monitoring outputs before relying on them.
2. Automatic injection and rendered-only modifications
Depending on configuration, UpRender may inject or append metadata, schema, canonical tags, Open Graph tags, or other crawler-facing enhancements into rendered HTML delivered to supported bots. These rendered-only modifications do not necessarily change the customer origin site shown to human visitors.
3. Sitemaps and llms.txt
UpRender may generate, host, refresh, validate, or submit sitemaps and llms.txt files according to your configuration. Customers remain responsible for confirming that generated files accurately reflect canonical, public, indexable, and legally publishable URLs.
4. No SEO, AI citation, or ranking guarantee
UpRender can improve crawler readability and observability, but search engines, AI answer engines, crawlers, social platforms, and LLM systems are independent third parties. We do not guarantee rankings, indexing, crawl frequency, AI citations, traffic, revenue, conversions, search appearance, or that a crawler will use, index, cite, or display any page.
Security, Availability, Data Damage, and Responsibility Limits
1. UpRender is not a backup or disaster recovery service
UpRender may cache rendered HTML, store logs, retain AI audit outputs, or keep generated files for service delivery, but it is not a backup, archive, disaster-recovery, source-control, or data-restoration service. Customers must maintain independent backups of websites, source code, databases, DNS records, CDN rules, SEO configurations, metadata, schema, sitemaps, llms.txt files, and business-critical data.
2. Data damage and configuration errors
UpRender is not responsible for data loss, data corruption, site downtime, search visibility loss, de-indexing, crawler blockage, broken metadata, incorrect schema, broken sitemap or llms.txt files, bot misclassification, or traffic loss caused by customer configuration, origin errors, third-party API outages, DNS/CDN/firewall rules, or changes made outside UpRender.
3. Security incidents
If we determine that a security incident has compromised personal data under our control, we will notify affected customers as required by applicable law and contract.
4. Vulnerability reporting
Please report suspected vulnerabilities to [email protected]. Do not publicly disclose vulnerabilities or access, modify, delete, exfiltrate, or degrade data without written authorization.
Data Processing Addendum Summary
Where UpRender processes personal data on behalf of a customer as a processor, service provider, or contractor, the following DPA summary applies unless a signed DPA supersedes it.
- Instructions: UpRender processes customer personal data only to provide, secure, support, and improve the service, and according to the customer's documented instructions.
- Confidentiality: personnel with access to customer personal data are bound by confidentiality obligations.
- Security: UpRender maintains reasonable technical and organizational measures appropriate to the nature of the service.
- Subprocessors: UpRender may use subprocessors for hosting, security, analytics, support, billing, AI assistance, and infrastructure.
- Assistance: UpRender will provide reasonable assistance for data subject requests, security obligations, impact assessments, and regulatory inquiries.
- Deletion and return: upon termination, UpRender will delete or return customer personal data according to the service configuration, legal requirements, and applicable agreement.
- International transfers: where required, UpRender will use lawful transfer mechanisms such as standard contractual clauses or other approved safeguards.
- Audits: enterprise customers may request available security documentation or audit reports under NDA.
Enterprise customers may request a full DPA and subprocessor list from [email protected].
Contact Information
For questions, notices, requests, or security reports, contact:
Notices sent by email are deemed received when successfully transmitted unless a bounce-back or delivery failure is received.