Privacy Policy
Last Updated: August 23, 2026
1. Introduction
OneTool ("we," "our," or "us") provides a business management platform for small field-service businesses. This Privacy Policy describes what information we collect through our web and mobile applications and related services (the "Service"), how we use it, and the choices you have.
Two different kinds of personal information flow through OneTool, and we treat them differently:
- Your account information — information about you and your team members (names, emails, login activity). For this data, OneTool decides how and why it is processed.
- Your business records — information you enter about your own clients and business (client contacts, addresses, quotes, invoices, emails, signatures). For this data, you and your organization control what is collected and why; we process it only to provide the Service to you.
If you do not agree with the practices described here, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Your name, email address, and organization details (business name, address, phone, website). Sign-in and account identity are handled by Clerk, our authentication provider.
- Business Records: Client and contact details (names, email addresses, phone numbers, job titles), property and service addresses, project and task details, quote and invoice line items, pricing, notes, and tags. When you enter an address, we may geocode it (via Mapbox) and store the resulting map coordinates.
- Email and Messages:Emails you send through the Service and inbound emails received at your organization's OneTool receiving address, including subject lines, full message bodies, sender and recipient details, and attachments; internal team chat messages and their attachments.
- Files: Documents, images, and CSV files you upload, generated quote and invoice PDFs, and signed documents.
- E-Signature Records:When a client approves a quote through the client portal, we record the signature (typed or drawn), the approver's name and email, the IP address and browser information of the device used to sign, a snapshot of the approved line items and terms, and timestamps. This creates a tamper-evident approval record.
- Payment Records: We store payment amounts, status, and limited card details (brand and last four digits only) and, for payout accounts, the bank name and last four digits of the account. Full card numbers and bank credentials are collected and held by Stripe, never by OneTool.
2.2 Information Collected Automatically
- Usage Analytics (web app only):We use PostHog to understand how the web application is used. This includes pages visited, clicks and form interactions (autocapture), heatmap data, performance metrics, and application errors. Analytics is tied to your account (name, email, role, organization, and plan type) so we can understand usage per customer. PostHog receives your IP address as part of standard event delivery. In the signed-in web workspace we also use session replay: your interactions with the app may be recorded so we can reproduce bugs you report and improve the product. All form inputs are masked in recordings, and recordings are retained under PostHog's retention settings. We honor your browser's Do Not Track setting: when it is enabled, analytics and session replay are disabled for your visits. Our mobile app contains no analytics.
- Log Data: Our hosting and backend providers (Vercel, Convex) generate standard server logs, including access times, requests, and error messages.
- Cookies and Local Storage: Authentication cookies set by Clerk, a session cookie for the client portal, and PostHog analytics identifiers (see Section 10).
- Location: We do not collect GPS location from your device. Map coordinates in the Service come from geocoding addresses you type in. The IP address recorded at quote signing implies an approximate location.
2.3 Mobile App
- Push Notifications: If you enable notifications, we store your device push token, platform, and device name to deliver notifications.
- Camera and Photos: Used only when you choose to attach an image or document; we access only what you select.
- Face ID: Used on-device to keep you signed in. Biometric data never leaves your device and is never sent to us.
2.4 Information from Third Parties
- Account and organization membership information from Clerk.
- Payment, payout, and dispute status from Stripe (including card brand/last four and bank name/last four).
- Signature status and signed documents from BoldSign.
- Email delivery events from Resend (delivered, bounced, complained), and inbound email content addressed to your organization's receiving address — including mail from senders who are not yet in your client list.
3. How We Use Information
- Service Delivery: To provide, maintain, and operate the Service and its features.
- Account Management: To authenticate users and manage organization access, roles, and permissions.
- Communication: To send transactional emails (billing notifications, signature requests, system alerts) and respond to support requests.
- Payment Processing: To process subscription payments and facilitate invoice payments to your business through Stripe.
- Product Improvement: To analyze how the web app is used, diagnose errors, and improve the Service.
- Security and Fraud Prevention: To detect and address abuse, unauthorized access, and technical issues, including rate limiting and webhook verification.
- Legal Compliance: To comply with legal obligations and enforce our Terms of Service.
We do not use your business records for advertising, and we do not sell personal information.
4. AI Features
Some features of OneTool are powered by OpenAI's API:
- The AI assistant answers questions about your business data. To do this, relevant records from your organization — which can include client names, contact details, addresses, quotes, invoices, and the contents of email threads — are sent to OpenAI as context for generating responses.
- AI-assisted import and report generation send the data you provide for those features (such as CSV contents or your report request) to OpenAI.
Under OpenAI's API terms, data submitted via the API is not used to train OpenAI's models by default, and we have not opted in to training. OpenAI may retain API data for a limited period for abuse monitoring under its policies. AI features run only when you invoke them; if you do not use them, your data is not sent to OpenAI.
5. How We Share Information
We do not sell or rent personal information. We share information only with the service providers that operate the Service ("subprocessors"), within your organization, and where required by law.
5.1 Service Providers
- Clerk — authentication and organization management: your name, email, and sign-in activity.
- Convex — our database and file storage: all data stored in the Service.
- Vercel — web hosting and delivery: standard request data and server logs.
- Stripe— payment processing (including Stripe Connect payouts to your business): payment details, and identity information you provide during Stripe's onboarding.
- Resend — email sending and receiving: message content, recipient addresses, and delivery events.
- BoldSign — e-signatures: documents sent for signature and signer names and email addresses.
- PostHog— web analytics and customer support: usage events, session replay (inputs masked), and your account identity (name, email, role, organization, plan), plus IP address on event delivery. Support messages you send us — in-app or by email to support@onetool.biz — are processed in PostHog's support inbox.
- OpenAI — AI features: the data described in Section 4, only when you use those features.
- Mapbox — address search and geocoding: the addresses you type into address fields.
- Expo — mobile app services and push notification delivery: device push tokens.
Each provider processes data under its own terms and privacy policy, and several hold their own security certifications (for example, Stripe is a PCI DSS Level 1 certified payment processor). We share with them only what is needed to provide their function.
5.2 Within Your Organization
Data you create in your organization is visible to other members of your organization according to their role and permissions. Admins control membership and access.
5.3 Legal Requirements
We may disclose information if required by law, court order, or government request, or when we believe in good faith that disclosure is necessary to protect the safety, rights, or property of OneTool, our users, or the public, or to enforce our Terms of Service.
5.4 Business Transfers
If OneTool is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice where required by law.
6. Data Security
We take reasonable technical and organizational measures to protect your information, described in more detail on our Data Security page:
- Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our infrastructure providers.
- Authentication is handled by Clerk; passwords are never stored by OneTool.
- Every query and change is scoped to your organization — the application enforces organization-level isolation on all business data.
- Role-based permissions limit what members of your organization can see and do.
- Client portal access uses short-lived, server-revocable sessions with email verification codes, and sensitive endpoints are rate limited.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please protect your login credentials and notify us immediately of any suspected unauthorized access.
7. Data Retention and Deletion
- While your account is active: We retain your data so the Service can function. Cancelling a paid subscription does not delete your data; your account continues on the free plan.
- When you delete your organization or account: Deletion of your organization (available in your organization settings) or your account permanently deletes your organization's data from our database and file storage — including clients, contacts, quotes, invoices, emails, attachments, documents, and signatures. Deletion begins immediately and completes shortly after, with a daily automated job that sweeps for and removes any remaining records.
- Archived clients: Clients you archive are permanently deleted 7 days after archiving.
- Internal system logs: Automation execution logs are deleted after 30 days and internal change events after 7 days.
- Data held by service providers:Our service providers retain data under their own policies. For example, Stripe retains transaction records to meet its legal obligations, BoldSign retains signed documents, Resend retains email logs, and analytics events already sent to PostHog are retained under PostHog's retention settings and are not automatically erased when you delete your account.
If you want us to request deletion of data held by a service provider on your behalf, contact us and we will make reasonable efforts to do so.
8. Your Rights and Choices
- Access and Correction: You can view and edit nearly all of your data directly in the Service. For anything you cannot change yourself, contact us.
- Deletion: You can delete your organization from your organization settings (web) or delete your account from the mobile app, or contact us to request deletion. See Section 7 for what deletion covers.
- Copy of Your Data: The Service does not currently include a self-serve bulk export. If you need a copy of your data, contact us and we will provide it in a commonly used format within a reasonable time.
- Notifications: You can disable mobile push notifications in your device settings. Transactional emails are required to operate the Service.
- Analytics:You can block analytics using browser tools or content blockers without affecting core functionality. Our web app honors the "Do Not Track" browser signal: when it is enabled, analytics and session replay are disabled (see Section 2.2).
We extend these rights to all users regardless of where you live. To exercise any of them, contact us using the details in Section 14. We may need to verify your identity before acting on a request, and we aim to respond within 30 days.
9. Your Clients' Information
The client contacts, addresses, emails, and signatures in your OneTool organization belong to your business relationship with your clients. You are responsible for having the right to enter that information into the Service, and we process it only on your behalf to provide the Service.
If one of your clients contacts us directly about their personal information, we will refer them to you, since you control that data. We will assist you in fulfilling access or deletion requests from your clients — deleting a client record in the Service removes that client's data, and Section 7 describes full deletion.
10. Cookies and Similar Technologies
- Essential: Authentication cookies set by Clerk to keep you signed in, and a secure, HTTP-only session cookie for the client portal (24-hour lifetime).
- Analytics: PostHog stores an anonymous identifier in cookies and local storage to associate usage events with your session and account.
You can control or delete cookies through your browser settings. Blocking essential cookies will prevent sign-in; blocking analytics cookies does not affect core functionality. We do not use advertising cookies.
11. Children's Privacy
OneTool is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
12. US State Privacy Laws
Several US states (including California, Virginia, Colorado, Connecticut, Texas, and Utah) have comprehensive privacy laws that grant residents rights such as access, correction, deletion, and opting out of the sale of personal information. Given OneTool's current size, many of these laws' applicability thresholds may not yet apply to us — but as a matter of policy we extend the rights in Section 8 to all users, and:
- We do not sell or share personal information for advertising.
- We do not use personal information for targeted advertising.
- We will not discriminate against you for exercising any privacy right.
13. International Users
OneTool is operated from the United States and is designed for and marketed to US-based businesses. Your information is processed and stored in the United States. We do not target or market the Service to individuals in the European Union, United Kingdom, or other regions, and we do not claim compliance with the GDPR or similar non-US regimes. If you access the Service from outside the United States, you do so understanding that your data will be processed in the United States, and the rights in Section 8 are available to you.
14. Contact Us
If you have questions or requests regarding this Privacy Policy or our data practices, contact us:
OneTool
Email: support@onetool.biz
We aim to respond to privacy requests within 30 days.
15. Changes to This Policy
We may update this Privacy Policy as the Service or our practices change. We will post updates on this page with a new effective date, and for material changes we will make reasonable efforts to notify you (for example, by email or an in-app notice). Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
This Privacy Policy is effective as of August 23, 2026.
