1Introduction
Oneplace is operated by HubTech Ltd. This policy explains what we collect when you use the console, why we collect it, and the choices you have. It applies to the Oneplace web application and every integration you connect through it.
If you use Oneplace as a member of someone else’s workspace, that workspace’s owner is the controller of the data inside it. We process that data on their instructions.
2Information we collect
We collect three categories of information:
- Account information — name, work email, company, role, and authentication metadata such as your identity provider and second-factor enrolment.
- Connected platform data — metrics, posts, comments, audience demographics, and publishing history retrieved from the services you authorise.
- Usage information — pages viewed, features used, exports requested, IP address, and approximate location, used for security and product improvement.
3How we use information
We use the information we collect to:
- Operate the console and render the analytics you asked for.
- Generate, schedule, and publish content on your behalf where you enable it.
- Detect competitor changes and deliver the alerts you configure.
- Secure the service, investigate abuse, and satisfy legal obligations.
- Understand which features are used, so we can improve them.
We do not sell personal information, and we do not use your connected platform data to train general-purpose models.
4Third-party platform connections
Oneplace connects to third-party services through OAuth: Instagram, Facebook, X (Twitter), LinkedIn, YouTube, Google Analytics, WordPress, Ghost, Slack, PagerDuty, and Stripe. When you authorise a connection, we store an access token and the minimum scopes required for the features you have enabled.
We never receive your password for those services. You can revoke any connection at any time from Integrations, or from the provider’s own settings; revoking stops collection immediately and removes the token within 24 hours.
5Google user data
If you connect a Google account, Oneplace asks Google for read-only access, and only for these permissions:
- Google Analytics (analytics.readonly) — the GA4 properties your account can see, and their reports: users, sessions, views, engagement, traffic channels, top pages, countries and devices.
- YouTube (youtube.readonly and yt-analytics.readonly) — your channel’s details and videos, and its analytics: views, watch time, subscribers gained and lost, likes, comments, shares, traffic sources and countries.
- Your Google email address (openid and email) — so you can tell your connected accounts apart.
We use this data only to show these reports to you inside Oneplace, on the company page you attach the account to. We do not sell it, use it for advertising, use it to train AI or machine-learning models, or share it with anyone else. No one at Oneplace reads it unless you ask us to for support, or it is needed for security or to comply with the law.
Report data is not stored: Oneplace fetches it from Google each time you open a report. The tokens Google issues are encrypted with AES-256-GCM in a secure, httpOnly cookie that only Oneplace’s servers can decrypt, and a short-lived access token is held in server memory for at most an hour.
You can disconnect at any time from Integrations, which deletes the stored token and asks Google to revoke it, or from your Google account at security.google.com/settings/security/permissions.
Oneplace’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6YouTube API Services
Oneplace uses YouTube API Services to show the YouTube channel data described above. By connecting a YouTube channel, you agree to be bound by the YouTube Terms of Service, and Google’s handling of that data is described in the Google Privacy Policy.
To remove Oneplace’s access to your YouTube data, disconnect the Google account from Integrations, or revoke it at security.google.com/settings/security/permissions.
7Cookies and local storage
We use a small number of strictly necessary cookies to keep you signed in and to remember workspace preferences such as theme and date range. We do not use advertising cookies or third-party trackers in the console.
8Data sharing and disclosure
We share information only in these circumstances:
- With sub-processors that host, deliver, or secure the service, under contract and bound to equivalent obligations.
- With other members of your workspace, according to the role you were granted.
- Where required by law, and only after reviewing the request for validity and scope.
- In connection with a merger or acquisition, with notice before your information becomes subject to a different policy.
9Data security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access tokens for connected accounts are encrypted with AES-256-GCM in secure, httpOnly cookies that only Oneplace’s servers can decrypt. Administrative access is gated behind SSO and hardware-backed second factors, and every configuration change is written to the audit log.
10Data retention
Analytics data is retained for the retention window on your plan — 24 months on Scale. Audit logs are retained for 24 months regardless of plan. When a workspace is deleted, we remove its data within 30 days, except where we are required to keep records for legal or accounting purposes.
11Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
You can export your data at any time from Settings, and you can request deletion by writing to privacy@oneplace.io. We respond within 30 days.
To remove a connected account and the data it gave Oneplace, follow the data deletion instructions.
12Children's privacy
Oneplace is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children. Where a connected program involves minors — youth sports rosters, for example — the workspace owner is responsible for obtaining the appropriate consents.
13International transfers
We process data in the United States and the European Union. Where we transfer personal information out of the EEA or the UK, we rely on Standard Contractual Clauses and apply supplementary technical measures.
14Changes to this policy
We will post any changes on this page and update the date above. For material changes we will notify workspace owners by email at least 30 days before the change takes effect.
15Contact us
Questions about this policy can go to privacy@oneplace.io, or by post to HubTech Ltd, 1200 Union Ave, Seattle, WA 98101, United States.