Privacy Policy
Effective August 2, 2026 · Last updated August 2, 2026
1. Introduction
At Ubiqo we believe a privacy policy should be readable from start to finish without a lawyer next to you. This document explains what information we collect, what we use it for, and what control you have over it.
Ubiqo is an operations platform that lets companies centralize the history, location, inventory, and movement of their physical assets: inventory, locations, movements, shipments and containers, operational orders, documents and photos, QR labels, and a per-asset timeline. It is built for importers and distributors in Latin America.
When this document says "Ubiqo", "we", or "our", it refers to the team that operates the Ubiqo service. We are an early-stage product, currently in pilot, and there is no incorporated legal entity behind the project yet. We would rather say that plainly than imply a structure we do not have. For any privacy matter you can write to us at victorjmanrique@gmail.com.
This policy covers the following services, which we refer to together as "the Service":
- The web application at app.ubiqo.app.
- The API at api.ubiqo.app.
- The Ubiqo mobile application for iOS and Android.
- The informational site published at ubiqo.app.
Ubiqo is a business tool (B2B) and it works by organization. If you use Ubiqo because your company gave you access, that organization decides what information is uploaded to the platform, who can see it, and how long it is kept. Your organization's internal policies apply to that content alongside this policy. Where there is a question about operational content, the organization decides and we act on its instructions.
By using the Service, you agree to the practices described in this document. If you do not agree with them, please do not use Ubiqo.
2. Information we collect
We collect only the information needed to make the Service work, keep it secure, and meet legal obligations. We group it into five blocks.
Account data
This is the data that identifies the person signing in:
- The name you enter in your profile.
- Your email address, which is also your sign-in identifier and the channel for transactional email.
- Your password, always stored as a hash. We do not store and cannot read your password in plain text.
- Session cookies, scoped to ubiqo.app subdomains, which keep you signed in across the web application and the API. They are necessary for the Service to function and are never used for advertising.
Organization data
Ubiqo is multi-tenant: each organization is a separate space. To maintain that separation we record:
- The organization or organizations your account belongs to.
- Your role and permissions within each organization.
- Invitations sent and received, including the invited person's email address, who invited them, and the invitation status.
- Actor attribution for every action: each change is recorded on a timeline, together with the user who performed it and the date and time it occurred.
Operational content
This is the information your organization uploads to Ubiqo in order to operate. We do not generate it or ask for it: we receive and store it on the organization's behalf. It includes:
- Assets, categories, serial numbers, batches, custom fields, and operational statuses.
- Inventory quantities, costs, values, and minimum stock levels.
- Locations (warehouses, zones, racks, bins), including in-transit locations.
- Inventory movements: inbound, outbound, transfers, reservations, consumption, adjustments, and status changes.
- Shipments and containers, with supplier details, estimated arrival date, port, and tracking information.
- Operational orders and their lines.
- Business contacts, which may include personal data of third parties, such as the name, email, or phone number of a supplier or customer of the organization.
- Photos and documents attached to assets, shipments, or orders.
If your organization uploads personal data of third parties as part of operational content, the organization is responsible for having a legal basis to do so and for informing those people.
Technical data
Our servers automatically log technical information about each request:
- IP address.
- Browser or device type, operating system, and application version.
- Date and time of requests, paths accessed, and response codes.
- Error logs and technical diagnostics.
We use this data to operate the infrastructure, detect abuse, and diagnose failures. We do not use it to build advertising profiles.
Mobile device permissions
The mobile application is designed for warehouse work and requests limited permissions, always with your explicit approval in the operating system:
- Camera: to scan asset and location QR codes, and to take photos attached to an asset or a receiving operation. We do not access the camera in the background.
- Photo library: only so that you can pick an existing image and attach it. We do not browse or index your library.
- Local offline queue: the application stores captures made without connectivity (for example, movements recorded in a warehouse with no signal) on the device itself and syncs them with our servers once connectivity returns. That queue lives on your device until it syncs or you discard it.
You can revoke any of these permissions from your phone settings. If you do, the features that depend on them will stop working.
3. How we use information
We use the information we collect for the following purposes, and only for these:
- Authenticate your identity and keep your session active securely.
- Provide the Service: display and process assets, inventory, locations, movements, shipments, orders, documents, photos, QR labels, and each asset's timeline.
- Sync captures made offline from the mobile application, avoiding duplicates and preserving the date and time the operation actually occurred.
- Send transactional email required for the Service to work: organization invitations, account verification, password recovery, and operational notifications. These are sent from notificaciones@ubiqo.app.
- Provide support and answer your questions.
- Protect the security of the Service: detect unauthorized access, prevent fraud and abuse, and audit sensitive operations.
- Improve the product using aggregate usage metrics and reported errors.
- Comply with legal obligations and respond to valid requests from competent authorities.
What we do not do
These commitments are part of the product, not an informal promise:
- We do not sell or rent your personal data to anyone.
- We do not show advertising inside the Service and we do not allow third parties to run advertising tracking in it.
- We do not use customer content to train artificial intelligence models, whether ours or a third party's.
We do not charge a subscription for Ubiqo today, because the product is in its pilot stage. We may introduce fees later, with reasonable prior notice. Such a change would not alter the commitments above.
5. Roles: controller and processor
Ubiqo is a B2B tool, so data protection roles depend on the type of information involved.
The organization controls operational content
For operational content (assets, inventory, locations, movements, shipments, orders, business contacts, photos, and documents), the customer organization acts as the data controller ("responsable"). It decides what information is uploaded, for what purpose, who on its team can see it, and when it is deleted.
Ubiqo acts as the processor ("encargado") for that content: we process it following the organization's instructions and do not use it for our own purposes beyond operating and securing the Service.
Ubiqo controls account data
For account data and technical data (name, email, hashed password, sessions, access logs), Ubiqo acts as the controller, because we are the ones defining their purpose: authenticating users, providing the Service, and protecting it.
What this means for your requests
If you ask us to access, correct, or delete operational content belonging to an organization, we will likely ask you to direct the request to that organization's administrator, or forward it to them, because decisions about data the organization controls are not ours to make. If your request concerns your account data, we handle it directly.
If an organization stops using Ubiqo, its administrators remain the point of contact for requests about the content they uploaded.
6. Security
We apply reasonable technical and organizational measures to protect information:
- Encryption in transit: all traffic between your devices and our servers travels over HTTPS/TLS.
- Passwords stored using one-way hashing functions. Nobody at Ubiqo can see your password.
- Multi-tenant isolation: every query is filtered by the active organization derived from your authenticated session, never by data sent from the client. One organization cannot read another organization's data.
- Role-based access control within each organization.
- Append-only audit timeline: every change is recorded as an immutable event, with its author and timestamp, visible to your organization. Events are never edited or deleted.
- Sessions using cookies restricted to ubiqo.app subdomains.
- Regular database backups.
Even so, no internet-connected system is completely secure. We cannot guarantee the security of information in absolute terms, and you have a role too: use a strong, unique password, do not share it, and review periodically who has access to your organization.
If we detect a security incident affecting your personal data, we will notify you without undue delay with the information available, and report it to the authorities where applicable law requires. If you find a vulnerability, we would be grateful if you reported it to victorjmanrique@gmail.com.
7. Data retention
We keep information only for as long as it is needed:
- Account data: while your account is active.
- Operational content: while the organization keeps its Ubiqo account active, or until it requests deletion.
- Technical data and access logs: for limited periods, long enough to diagnose failures and detect abuse.
- Timeline events: while the organization exists, because they are the audit record of its operations.
You can request deletion of your account or of your organization's data by writing to victorjmanrique@gmail.com. We will handle the request within a reasonable time and, where operational content is involved, coordinate it with the organization's administrator.
After a deletion, data may remain in backups for a period. Those backups are purged on a rotation schedule and, in the meantime, are out of operational use and subject to the same security measures.
We may retain certain information for longer where a legal, accounting, or evidentiary obligation requires it, or where it is necessary to resolve disputes or enforce our terms. In that case we keep it to the minimum required.
8. Your rights and choices
You are in control of your information. Subject to the law applicable in your country, you may exercise the following rights:
- Access: find out what personal data of yours we process and for what purpose.
- Correction: fix inaccurate or incomplete data.
- Deletion: request removal of your data, subject to any applicable legal limits.
- Portability: obtain a copy of your information in a commonly used format. The web application lets you export inventory and operational data to Excel at any time.
- Objection and restriction: object to certain processing or ask that it be restricted.
- Withdrawal of consent: withdraw consent you previously gave, without affecting the lawfulness of processing carried out before that.
- Complaint: file a complaint with the data protection authority in your country.
To exercise them, write to us at victorjmanrique@gmail.com stating the right you wish to exercise and the account or organization involved. We may ask for additional information to verify your identity, and we will respond within the timeframes set by the law applicable in your country. Exercising these rights is free of charge.
If your request concerns operational content uploaded by an organization, the roles section applies: we will direct it to that organization's administrator.
Ubiqo operates across Latin America, so your rights are governed by the data protection laws applicable in your country. By way of example, frameworks in the region include Ley 1581 de 2012 in Colombia, the LFPDPPP in Mexico, the LGPD in Brazil, and Ley 25.326 in Argentina. This list is illustrative and does not exclude the legislation of other countries.
9. International transfers
Our infrastructure is hosted in the United States. This means your information, including account data and your organization's operational content, is processed and stored on servers located in that country, even if you are in Latin America or any other region.
Data protection laws in the United States may differ from those in your country and do not necessarily offer the same level of protection. By using the Service and uploading information to it, you accept and consent to this international transfer.
We apply the following safeguards to those transfers:
- Contracts with our providers requiring them to process data only on our instructions and to maintain adequate security measures.
- Encryption in transit and per-organization access control, as described in the security section.
- Limiting transferred data to what is strictly necessary to provide the Service.
If the law applicable in your country requires a specific authorization, a formal transfer mechanism, or additional contractual clauses, write to us at victorjmanrique@gmail.com and we will address it.
10. Minors
Ubiqo is a work tool aimed at companies and their teams. The Service is not directed to anyone under 18, and using it requires being at least that age.
We do not knowingly collect personal data from anyone under 18. If we learn that we have received information from a minor without the appropriate authorization, we will delete that information and the associated account.
If you are a parent or guardian and believe a minor has provided us with personal data, write to victorjmanrique@gmail.com and we will act immediately.
11. Changes to this policy
Ubiqo is an evolving product, so this policy may change: we will add features, change infrastructure providers, or adjust practices. When that happens, we will update this document.
The last updated date always appears at the top of the page. We recommend checking it from time to time.
If a change is material, for example a new purpose for using your data or a new category of recipients, we will notify you with reasonable advance notice by email to the address associated with your account, or through a visible notice inside the Service.
If you continue using Ubiqo after a change takes effect, we will understand that you accept the updated policy. If you do not agree, you may request deletion of your account.
12. Contact
If you have questions about this policy, about how we handle your information, or if you want to exercise your rights, write to us:
- Privacy and legal email: victorjmanrique@gmail.com
- Sender address for our transactional email: notificaciones@ubiqo.app
- Website: https://ubiqo.app
We are a small team, so we answer personally. Please include the organization and account involved in your message so we can help you faster.
You may also file a complaint with the data protection authority in your country if you believe we have not handled your request properly.