01 Who we are
Uprisen Antraajaal CMS is part of Uprisen Antraajaal Private Limited ("we", "us" or "our"). This policy explains how we handle information through our website, CMS dashboard, supported players and connected features.
It covers uprisenantraajaalcms.com and dashboard.uprisenantraajaalcms.com. It also covers our processing of information through reseller-branded deployments of the CMS. A reseller may separately explain how it handles its own customer relationship.
For account administration and enquiries, we determine how information is handled. When a business uses the CMS to manage its own content, that business decides what to upload, who may manage it and where to display it; we process that content to provide the service.
This policy describes data handling. It does not transfer ownership of your content to us, grant permission for otherwise unlawful processing, or replace the service terms and content rules that apply to your account.
02 Information we handle
The information involved depends on the features you use and the details you provide.
- Account & contact details
- Name, email address, username, company details, phone number where provided, account role, and authentication or email-verification information.
- Media & workspace content
- Uploaded or imported files, filenames, file types, folders, playlists, mosaic layouts, screen groups, publishing schedules and related configuration.
- Screen & service activity
- Device identifiers, reported operating system, screen orientation and resolution, IP address and network information, connection status, playback or command logs, and requested screenshots or live-view images where supported.
- Support & enquiries
- Demo requests, support messages, attachments and details you share with our team, including the source page of a website enquiry. For abuse or privacy reports, we may also handle the reporter's contact details, content references, allegation and records of our response.
- Plans & licenses
- Chosen plan, device allocation, license status and expiry, and billing, invoice or transaction-reference information relevant to your subscription.
- Technical & security records
- Browser or user-agent information, IP addresses, session information, request timestamps and audit records of account and CMS actions.
Connected Google information is described separately below. Do not upload personal information that you are not authorized to use or display.
03 How we use information
- Create and authenticate accounts, verify email addresses and support account recovery.
- Store and organize media, generate supported previews or conversions, and deliver content to screens you select.
- Manage playlists, schedules, screen groups, device licenses, remote commands and operational reports.
- Respond to demos, enquiries and support requests, and send relevant service or account communications.
- Detect abuse, investigate failures, enforce access controls and maintain the reliability of the CMS.
- Manage subscriptions and address applicable legal, accounting and dispute-resolution obligations.
Connecting a cloud account is optional. You can use device uploads without connecting Google Drive.
04 Google sign-in & Drive imports
Signing in is separate from importing
When you choose Sign in with Google, Google supplies the identity information needed for your CMS account, such as your Google account identifier, name, email address and email-verification status. You enter your Google password with Google, not with us. Signing in does not automatically authorize the CMS to read your Drive files.
You choose the files
The Drive importer requests permission when you select Google Drive in the uploader. It uses Google's drive.file permission and file picker. This is selected-file access, not permission to read your entire Drive.
Google describes this permission as allowing an app to create, read, edit or delete specific files used with the app. Our importer only reads or exports the files you select. It does not edit or delete your Google originals, create files in your Drive, or automatically synchronize your Drive.
For a selected file, the importer reads its identifier, name, file type, size, download availability and file content. Google Docs, Slides, Sheets or Drawings may be exported into supported document or image formats.
What happens to an imported file
The file is downloaded through your browser. When you start the import, a copy is uploaded to the CMS folder you choose and checked before saving. The CMS stores that copy and its media metadata so you can preview it, organize it and use it in your signage workflow. Importing a file does not itself publish it to a screen.
Your imported copy is separate from the Google original. Subsequent changes in Drive do not automatically update that copy. If you later publish it, the content is sent to the chosen players and can be visible to people near those screens.
Access tokens & disconnecting
The Drive importer holds a short-lived access token in browser memory. It does not save that token in the CMS database or browser local storage, and it does not request a refresh token for unattended Drive access.
Clear connection clears the importer's connection on that page. To withdraw Google's account-level permission, remove the app in your Google Account connections. Revoking access does not delete copies already imported into the CMS; use the deletion options in Your choices & deletion.
Google data commitments
Our handling of information obtained through Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data policy.
We use this information for the connected features you request. We do not sell Google user data, use it to build advertising profiles or target advertisements, use it for credit decisions, or use it to train general-purpose AI models.
Human access to connected Google data is limited to your explicit agreement, necessary security investigations, or legal requirements. Transfers are limited to providing the requested features with your consent, security needs, legal obligations, or a business transfer with your prior explicit consent where Google's policies require it.
07 Storage & retention
Account records and media are stored in the systems used to provide the CMS. Selected players may hold local copies for playback, including offline playback. Service providers may process information in locations different from yours; this policy does not promise storage in a particular country.
We retain information for the purposes described here, taking account of your service relationship, deletion requests, security needs and applicable legal obligations. Different categories can have different retention requirements. Contact us for information about a particular record or to request deletion.
Removing content from the library or revoking a cloud connection does not guarantee immediate erasure from backups, logs or offline players. Some records may need to be retained for security, legal or accounting reasons. Offline players may require a connection, a content update or a supported cache-clearing action to remove stored content.
08 Security
We use measures appropriate to the service, including HTTPS connections, authenticated sessions, password hashing and access checks. The Drive import workflow uses short-lived authorization and passes imported files through server-side type validation and malware scanning before saving.
Enable two-step verification
The CMS supports two-step verification. We strongly recommend enabling it for every account, especially administrator and reseller accounts. It adds an additional verification step to sign-in and helps reduce the risk of unauthorized access. Do not assume it is enabled: check your account's security settings and complete the setup offered there, or ask support for help.
- Use a strong, unique password and keep your email account and verification device secure.
- Never share passwords, one-time verification codes, authenticator setup keys or recovery information.
- Use individual accounts with only the access each person needs; remove access when staff or agency relationships end.
- Sign out on shared devices, keep players and browsers updated, and review screen assignments before publishing.
File checks are not content approval
File-type validation and malware scanning do not determine whether an image or video contains nudity, is lawful, has copyright permission, or is suitable for a public screen. An accepted upload is not an endorsement or permission to publish it. Customers must review content before use.
No internet service, file check or security control can guarantee absolute protection. Two-step verification reduces risk but does not prevent every attack. Contact support promptly if you suspect unauthorized access or unexpected content on your screens. Our security and legal responsibilities still apply whether or not you enable two-step verification.
09 Your choices & deletion
- Account details: use available account settings or contact support to request a correction.
- Imported or uploaded media: remove content through the media library. Active-playlist safeguards may require you to remove or replace scheduled content first.
- Google access: remove the CMS connection from your Google Account. This stops future authorized access but does not remove existing CMS copies.
- Account or data requests: email support@uprisenantraajaalcms.com to request access, correction, deletion or withdrawal of consent, where applicable.
Tell us your registered email, the account or workspace concerned, and what you want us to address. We may verify your identity and authority before acting. Do not send passwords, access tokens or unnecessary sensitive documents.
If your business or reseller manages the account, we may need its involvement. We will explain any restriction on fulfilling a request, including applicable legal retention or the effect on the service. Withdrawing optional Google Drive access does not require you to close your CMS account.
10 Children's information
The CMS is intended for businesses and authorized workplace users, not for children to register independently. If you believe a child has provided personal information without appropriate authorization, contact us so we can investigate. Customers displaying content involving children are responsible for having the necessary authority to do so.
11 Policy changes
We may update this policy as the service or applicable requirements change. The published policy will show its effective or updated date. Material changes will be communicated where required, and new Google-data uses or permissions will require appropriate notice and consent before they are used.
12 Contact us
For privacy questions, concerns or data requests, contact:
Uprisen Antraajaal Private Limited Uprisen Antraajaal CMS support@uprisenantraajaalcms.com