OneSchedule

Privacy and data protection

Privacy Notice

This notice explains how Ones N Zero, operating OneSchedule, handles personal data when you visit our site, create an account, use a Space, connect a social network, buy a subscription, or contact us.

Effective
9 August 2026

1. Scope, controller, and processor roles

Ones N Zero is the controller for account, billing, security, support, and product-usage data. For post content, media, and other personal data a customer places in a Space, the customer normally determines the purpose and OneSchedule acts as its processor. Contact assist@onesnzero.com. If we process data for your organization, direct requests to that organization first; we will assist it as required.

2. Data we handle and where it comes from

We receive account and profile details; sessions and trusted-edge IP information; Space memberships, roles, invitations, and audit events; posts, schedules, media, and filenames; connected-account identifiers, permissions, and encrypted OAuth credentials; subscription and transaction status; support communications; and operational diagnostics. Data comes from you, authorized teammates, your device, selected social networks, Polar, and service providers involved in your request. Do not upload unnecessary sensitive or special-category data.

3. Purposes and legal bases

We process data to create and secure accounts, provide collaboration, storage, scheduling and publishing, administer subscriptions, deliver service messages, answer support requests, prevent abuse, investigate incidents, establish or defend claims, and comply with tax, accounting, sanctions, and other law. The legal basis is performance of our contract, compliance with legal obligations, our legitimate interests in operating and protecting the service, or consent where the law requires it. You may withdraw consent prospectively.

4. Sharing, subprocessors, and connected networks

We disclose only what is needed to infrastructure, authentication, email, storage, job-processing, billing, support, and professional advisers, including Encore, Amazon Web Services, Trigger.dev, Polar, Google, and the social networks you choose. Authorized Space members receive role-appropriate data. A connected social network generally acts under its own terms as an independent controller. We may disclose data when legally required or during a corporate transaction subject to appropriate safeguards.

5. International transfers

Providers may process data outside your country. Where EEA, UK, or Swiss transfer rules apply, we rely on an adequacy decision, approved standard contractual clauses, or another lawful mechanism and assess supplementary technical and organizational measures. Contact us for information about the safeguard relevant to your data. Our subprocessor and transfer records are reviewed when providers, locations, or access patterns change.

6. Retention and erasure

We keep data only for the service, legal, security, and dispute periods that apply. Browser composer recovery expires after 24 hours and is cleared at sign-out; notifications after 7 days; completed email deliveries after 30 days; billing webhook payloads are minimized after 7 days and records removed after 90 days; and audit history follows the Space plan. A deleted Space has a 30-day recovery window, after which current and historical S3 object versions are permanently erased before database records are purged. Backups expire on a controlled schedule and are isolated from ordinary processing.

7. Your rights and choices

Depending on applicable law, you may request access, correction, erasure, restriction, objection, or portability, withdraw consent, opt out of direct marketing, and complain to a supervisory authority. Use Personal settings or email assist@onesnzero.com. We verify identity proportionately, protect other people's rights, explain lawful refusals, and normally respond within one month under GDPR; a complex request may be extended as the law permits. Erasure is not absolute where retention is required for law, security, claims, or another overriding ground.

8. Security, browser storage, children, and changes

We use access controls, encryption, strict validation, rate limits, signed worker requests, logging controls, monitoring, and tested deletion procedures. No service can promise absolute security. OneSchedule currently uses authentication cookies and local or session storage needed for sessions, locale, theme, active Space, and short-lived draft recovery; it does not currently use advertising cookies. We do not knowingly offer the service to children under 16 or make solely automated decisions with legal or similarly significant effects. We will update this notice and provide additional notice for material changes where required.

Questions about these documents can be sent to assist@onesnzero.com.