Home/Privacy Policy
Privacy & security

Your privacy matters.Here's how we protect it.

We collect only the information needed to operate UPTOWN LOGS, keep your account secure, process your orders, and provide support.

Last updated8/31/2026
Written in plain language
01

What we collect

We collect the information necessary to provide and secure your account and operate our services.

  • Account info: name, email, and a hashed (never plaintext) password
  • Profile picture, if you upload one
  • Order and transaction history — service, amount, status, timestamps
  • Support chat messages, if you use the chat widget
  • Passkey public keys, if you register one (the private key never leaves your device)
  • Basic technical data for security — IP address (for rate limiting/abuse prevention), browser info
02

Cookies

We use a session cookie to keep you signed in, and a separate CSRF cookie to protect against cross-site request forgery — both are essential to how the site works and aren't used for tracking or advertising.

Both clear when you sign out.

03

Third parties we use

Data is shared with the following providers, only as needed to run the service:

  • Flutterwave — processes wallet payments; we never see your card details
  • Google — if you sign in with Google, we receive your name/email from them
  • Supabase — stores uploaded profile pictures
  • An AI provider (Gemini or Groq) — powers the support chat assistant; chat messages are sent to generate replies
  • Our SMM and airtime/data resellers — receive the link/phone number and quantity needed to fulfill your order, nothing more
  • An email provider — sends verification codes, receipts, and account notifications
04

How we use your data

We use your information to create and secure your account, process orders and payments, send transactional emails (OTP codes, receipts, security alerts), respond to support requests, and detect fraud or abuse.

05

Your controls

  • Update your name, avatar, and theme anytime from Settings
  • Enable or disable two-factor authentication and passkeys from Settings
  • Delete your account (OTP-confirmed) from Settings
Order and transaction records are kept after account deletion for accounting and fraud-prevention purposes, with your personal profile removed.
06

Security

Passwords are hashed, sessions use httpOnly cookies with CSRF protection, sensitive actions require OTP or two-factor confirmation, and all authentication endpoints are rate-limited.

Security is built into the account and payment flow.
07

Contact

Questions about this policy or your data? Reach us through the chat widget or WhatsApp — see the Help page.

Visit Help Center

Nexi

Your website co-pilot

Hey! I'm Nexi 👋 I'm here if you need a little help.

Online