Privacy policy
Last updated: 31 August 2026
Who we are
Uplift is operated from the United Kingdom by its founder, Dr Richard Strickland. The operating limited company will be confirmed on this page before paid plans launch. Contact for anything on this page: drrts@hotmail.com.
What we access
With your explicit consent on Xero's own authorisation screen, Uplift accesses your organisation's invoice data under the Xero scope accounting.invoices (plusoffline_access to stay connected between visits). In practice the app reads and writes repeating invoice templates only. We do not request access to contacts, bank transactions, payroll, reports or any other Xero data, and we never see your Xero password — sign-in happens entirely on Xero's pages.
What we store, and why
Three things. First, encrypted OAuth tokens (AES-256-GCM at rest) so the app can act on your instruction. Second, snapshots of the repeating invoice templates you choose to update — kept so every change can be previewed, verified and restored. Third, run history: what changed, when, and the outcome. Template snapshots may include your customers' names as they appear on the templates; we store this solely to provide the preview, verification and restore features (UK GDPR Article 6(1)(b) — performance of a contract). We store nothing about your customers beyond what appears on the templates you select.
What we never do
We never change anything in Xero without a previewed run that you explicitly confirm. We do not sell or share your data with anyone. We do not use your data to train machine-learning models (this is also prohibited by Xero's developer terms).
Where your data lives
Our database is hosted in London, United Kingdom (Neon). The application runs on Vercel with functions in the London region. Our processors are: Vercel Inc. (hosting), Neon Inc. (database), and — once paid plans launch — Stripe (payments). Wherever you are in the world, we apply the same UK GDPR standard to your data.
Your role and ours
For the Xero data processed through Uplift, you (or your client, where you act as their bookkeeper or accountant with authority) are the data controller, and Uplift acts as a processor on your documented instruction — each run you confirm is that instruction.
Retention and deletion
Disconnecting (in the app, or from Xero's Connected Apps page) revokes our access immediately. On disconnection we delete stored tokens straight away; snapshots and run history are deleted within 30 days unless you ask us to keep them longer. You can request deletion of everything at any time by emailing the address above.
Security
TLS on every connection; tokens encrypted at rest; sessions signed; access restricted to the operator. Any suspected breach affecting Xero data will be reported to Xero and to affected users without undue delay, and to the Information Commissioner's Office where required.
Your rights
Access, rectification, erasure, restriction, portability and objection — email the address above and we will respond within one month. UK and EU users can complain to their supervisory authority (in the UK, the ICO at ico.org.uk); we'd appreciate the chance to fix things first.
Governing law: England and Wales. See also our pilot terms.