đź”’ Privacy & Security

Privacy Policy

Your privacy is important to us. This Privacy Policy explains how OneStep AI System collects, uses, stores, and protects your personal information while using our platform and services.

Last Updated: July 2026

01

Introduction


At OneStep AI System, trust is a core part of the product experience. This Privacy Policy describes how we responsibly handle information when you visit our website, create an account, integrate services, or use automation and AI-powered workflows.

By accessing or using our platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please discontinue use of the services.

We process personal and business data only for legitimate, transparent, and clearly defined purposes. We continuously review our practices to align with applicable laws, evolving security standards, and customer expectations.

02

Information We Collect


To operate our services effectively, we collect data you provide directly, data generated through your usage, and technical signals required for stability and performance.

  • Personal Information: Name, user profile data, account role, and authentication details used to create and manage your account.
  • Contact Information: Business email address, support communication records, and optional phone details for account notifications.
  • Business Information: Company name, organization size, workflow preferences, and operational settings relevant to your implementation.
  • Payment Information: Billing profile and transaction metadata processed by secure third-party payment processors. We do not store full payment card numbers on our own servers.
  • Device Information: Device type, operating system, device identifiers, language settings, and application-level technical diagnostics.
  • Browser Information: Browser type, browser version, time zone, IP-derived region, and session configuration details.
  • Cookies: Essential and preference cookies used to maintain sessions, improve usability, and preserve security controls.
  • Usage Analytics: Feature interactions, navigation patterns, performance timings, and non-sensitive telemetry used to improve reliability and product design.
03

How We Use Your Information


We use collected information for specific business and service-related purposes, always guided by proportionality, data minimization, and security-by-default practices.

  • Providing Services: To deliver workflows, AI automation, onboarding experiences, billing administration, and account lifecycle functions.
  • Customer Support: To respond to requests, troubleshoot technical issues, resolve disputes, and provide implementation guidance.
  • Marketing Communication: To send relevant announcements, product updates, events, and educational resources where allowed by law or your preferences.
  • Platform Improvements: To analyze user behavior and improve product performance, interface clarity, onboarding flow, and reliability.
  • Security: To detect abuse, unauthorized access, suspicious activity, fraud attempts, and potential policy violations.
  • Legal Compliance: To satisfy lawful obligations, tax requirements, contractual commitments, and regulatory reporting standards.
  • AI Feature Enhancement: To refine model behavior and recommendation quality, primarily through aggregated or de-identified usage patterns where possible.
04

Cookies Policy


Cookies and similar technologies help us provide secure sessions, remember preferences, and improve platform quality. You can manage cookie controls in your browser settings at any time.

  • Essential Cookies: Required for account login, authentication persistence, navigation security, and core service functionality.
  • Analytics Cookies: Help us understand usage trends, identify friction, and improve the usability of key workflows and dashboards.
  • Marketing Cookies: Enable relevant campaign attribution and communication personalization where lawful consent has been provided.
  • Performance Cookies: Track load times, session errors, and feature-level response metrics to maintain service reliability at scale.

Disabling certain cookies may reduce functionality, including session persistence and preference retention.

05

Data Security


We maintain layered security controls to protect information from unauthorized access, misuse, alteration, and disclosure. While no system can guarantee absolute security, we apply practical and industry-aligned safeguards.

  • Encryption: Data is encrypted in transit using modern TLS protocols and protected at rest through encryption standards supported by our infrastructure providers.
  • Secure Servers: Production environments use hardened configurations, segmentation controls, and continuous patching practices.
  • Access Controls: Internal data access is role-based and restricted to authorized personnel with legitimate business needs.
  • Monitoring: Logging, anomaly detection, and threat monitoring help us investigate suspicious behavior and respond to incidents quickly.
  • Security Best Practices: We routinely review policies, access rights, and operational procedures, and we train teams on secure handling expectations.
06

Data Sharing


We do not sell your personal data. Data sharing is limited to categories required for service delivery, compliance, and secure operations.

  • Trusted Service Providers: We share relevant data with vetted vendors that provide hosting, support tools, infrastructure, communication, or operational services under contractual safeguards.
  • Legal Authorities: We may disclose information when required by applicable law, court order, legal process, or to protect rights and safety.
  • Payment Processors: Billing and transaction data may be processed by secure payment partners to complete subscriptions and maintain financial records.

Where possible, we limit shared data to the minimum necessary and require third parties to preserve confidentiality and security.

07

Data Retention


We retain personal and account data only for as long as needed to provide services, fulfill legal obligations, resolve disputes, and enforce agreements.

Retention periods depend on data category, contractual needs, legal requirements, and legitimate operational interests. When data is no longer required, we delete or anonymize it using reasonable technical and procedural controls.

Backup systems may retain encrypted snapshots temporarily according to disaster recovery schedules, after which data is automatically rotated out.

08

User Rights


Depending on your location and applicable law, you may have rights regarding your personal data. We honor valid requests in accordance with legal requirements.

  • Access: Request confirmation about whether we process your data and obtain information about categories and purposes.
  • Update: Correct inaccurate profile, account, or business details linked to your workspace.
  • Delete: Request deletion of personal information when retention is no longer legally or operationally required.
  • Download: Request a copy of certain data in a portable format, where technically feasible and legally applicable.
  • Withdraw Consent: Revoke consent for data processing activities that rely on consent as the legal basis.
  • Marketing Preferences: Opt out of promotional communications while still receiving essential service-related notices.

To submit a request, please use the contact details in Section 13. We may verify identity before fulfilling sensitive requests.

09

Third-Party Services


Our platform may integrate with third-party tools to enable messaging, analytics, payments, and campaign workflows. These providers process data according to their own policies.

  • Google: Integrations may support authentication, analytics, productivity workflows, or advertising measurement.
  • Meta: Used for ad and communication integrations, including campaign-related data and audience connections.
  • WhatsApp Cloud API: Enables business messaging workflows, notifications, and conversational automation features.
  • Payment Gateways: Securely process subscription and billing transactions through PCI-aligned partners.
  • Analytics Services: Help evaluate feature adoption, stability, and user experience trends.

We encourage users to review each third-party provider’s privacy terms before enabling integrations.

10

Children’s Privacy


OneStep AI System is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13.

If we become aware that such information has been provided without verified parental consent, we will take reasonable steps to delete it promptly. Parents or guardians who believe a child has submitted data may contact us immediately.

11

International Data Transfers


Depending on your region and chosen integrations, data may be transferred to and processed in countries where privacy laws differ from those in your jurisdiction.

When cross-border transfers occur, we apply lawful transfer mechanisms and suitable safeguards, including contractual protections and access controls.

By using our services, you acknowledge that such transfers may be necessary for global infrastructure, support, and service continuity.

12

Policy Updates


We may update this Privacy Policy to reflect changes in legal obligations, service features, security controls, or business operations.

Material updates will be communicated through appropriate channels, such as in-product notices, account email notifications, or updates posted on this page with a revised “Last Updated” date.

Continued use of the platform after updates become effective indicates acceptance of the revised policy terms.

13

Contact Information


For privacy requests, questions, or concerns regarding this policy, please contact us using the following details:

Company Name: OneStep AI System
Email: [Insert official privacy email]
Phone: [Insert official support phone]
Website: [Insert official website URL]
Business Address: [Insert registered business address]