UPICK POWER
Privacy Policy
Last updated September 25, 2026
This policy describes how UPICK Network LLC (“UPICK,” “we”) handles information in the UPICK Power mobile application — the Power web app at https://joinupick.com/power, including when that same surface is opened from the Android app published as com.upick.customer. It covers only features that exist in the Power product today. It does not describe rideshare, towing, or other UPICK services except where you use the same UPICK account.
The general UPICK platform privacy page still applies to your UPICK account. If something conflicts for Power-only features, this page controls those features.
What this app actually does
UPICK Power lets you find listed power-bank stations, scan a station QR code, start a rental, pay through a third-party checkout, return a bank, view rental history, and contact support. Rewards, invites, and business hosting forms appear when those features are turned on.
On Android, UPICK Power opens this same web application. The permissions you may see are the ones these screens actually request: precise location while Find a Station is open, and the camera while Scan is open. We do not request Android background location, microphone access, or contacts.
Account information
If you sign in with UPICK, we receive the account identifiers Supabase Auth already has for that login — typically an email address and an account id. The Power account screen can show the signed-in email. We do not ask Power users for a separate legal name, photo, or date of birth on the Power screens.
Email and phone authentication
Signed-in rentals use the UPICK login at /auth/login. Guest checkout can store a phone number and an optional email on the rental so we can attach the session and send a receipt. A one-time phone code exists only in demo hardware mode; that demo path does not send a live SMS. Production guest checkout does not send a live SMS verification code.
Location
Find a Station can ask the device for your current position so we can sort nearby stations and show a “you are here” marker. The implementation is a one-time navigator.geolocation.getCurrentPosition call with enableHighAccuracy: true. On Android that corresponds to precise location (the OS may also grant approximate location). It is requested while the station finder is in the foreground. This app does not call watchPosition, does not register a background location service, and does not request Android background location.
If you allow it, coordinates are sent to /api/power/stations as lat and lng so the server can return distances. The same coordinates may be reverse-geocoded by Mapbox to a place label on your device. Location is optional: if you deny it, the station list and map still work without distances.
We do not operate a Power “location history” table. Coordinates used to sort stations are request parameters, not a saved trail of where you have been.
Camera and QR codes
The Scan screen asks for camera access (getUserMedia video, rear camera preferred, audio: false) so it can read a station QR locally with the browser Barcode Detector. Camera frames are not uploaded and are not stored. You can skip the camera and type the station QR or URL instead.
Rental and transaction history
When you start a rental we store records such as station, plan, status, amounts, timestamps, and — if you are a guest — the phone or email you entered. History is shown for the signed-in account or for guest sessions kept with an access token on this device. Active and past rentals appear under Rental History.
Payments
Card and wallet payments run through Stripe’s Payment Element, including Apple Pay or Google Pay when the device offers them. UPICK does not collect or store raw card numbers. Stripe may create a customer record with the email or phone from checkout. We store payment intent ids, authorization and capture amounts, and related payment-log events (intent ids and amounts — not full card data). A temporary authorization may appear; the rental charge is captured when the bank is returned, as described in the Rental Terms.
Device and app information
Normal HTTPS requests include an IP address (used to rate-limit station and guest-OTP endpoints) and a browser user-agent. Guest rentals may keep an access-token cookie on the device so you can reopen that rental. We do not collect contacts, advertising IDs, IMEI, or a Power-specific product-analytics SDK.
Customer support
Report a Problem sends a category, optional description, and any rental or station id you include. If you are signed in, we attach your account id. The support API can accept photo URLs, but the Power Report form does not upload photos today. You can also email support@joinupick.com.
Rewards and referrals
When Power Rewards are enabled, a signed-in account can have points, credits, and activity rows after a qualifying completed rental. When invites are enabled, we can create a referral code and count eligible referred rentals. Sharing uses the device share sheet, SMS, email, or social links you choose — we do not read your address book.
Notifications
Rental reminder events can be stored (for example, a “find a return station” message). Email or SMS delivery runs only if reminder providers are enabled on the server. This Power app code does not call Notification.requestPermission, does not register a push token, and does not declare Android POST_NOTIFICATIONS. We do not claim mobile push is active.
Analytics, security, and fraud prevention
There is no third-party product-analytics SDK on the Power screens. We do use IP-based rate limits, payment logs without raw card data, and standard web request metadata to reduce abuse. The main UPICK customer app has a separate analytics-opt-in preference; Power does not surface that toggle.
Business hosting applications
If you use “Bring UPICK POWER to my business,” we collect the business and contact fields you submit (name, email, phone, address, hours, and related notes). That is a hosting application, not required to rent a power bank.
How we use information
- Show stations and optional distances
- Open the correct station from a QR code
- Create, authorize, capture, or cancel a rental payment
- Show active and past rentals on this device or account
- Operate rewards or referrals when those flags are on
- Investigate support reports and prevent abuse
When we share information
We share information with service providers that run these flows:
- Stripe — payment authorization, capture, and wallets
- Supabase — authentication and Power database records
- Mapbox — map tiles and optional reverse geocoding
We may also share information if required by law, to protect users or the service, or with a successor if the business is transferred. We do not sell Power rental data.
Data retention
We keep rental, payment, support, rewards, and referral records as needed to complete the rental, handle disputes, and prevent fraud. UPICK does not publish a single deletion period because legal, tax, and payment needs differ by record type. Uninstalling the app does not delete your UPICK account or rental history.
Security
Power is served over HTTPS. Card numbers are entered in Stripe’s form, not in an UPICK card field. We do not claim a specific encryption standard, certification, or audit in this policy because those have not been verified in this product documentation.
Your choices and rights
- Deny location and still browse stations without distances
- Deny the camera and enter the station QR or URL
- Rent as a guest or sign in with UPICK
- Email support@joinupick.com to ask what we hold or to request a correction
- Use the UPICK account deletion or data deletion pages
Depending on where you live, you may have additional rights under applicable law. Contact us to exercise them. We do not publish a verified list of every jurisdiction.
Account deletion
Request deletion at joinupick.com/delete-account. That flow covers the UPICK account. The current deletion processor does not list Power rental tables by name. Payment, rental, and fraud-prevention records may be retained as described on that page. Closing or uninstalling the Android app is not the same as deleting the account.
Children’s privacy
UPICK Power is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information, email support@joinupick.com.
Changes to this policy
We will update this page when Power data practices change and will revise the Last Updated date above. Material changes may also be noted in the app or on joinupick.com.
Contact
UPICK Network LLC
support@joinupick.com
https://joinupick.com/power
Related: Rental Terms · Get Help · UPICK platform privacy