Last updated: 22 July 2026
Privacy policy
OneStep helps organisations plan work, carry out tasks and handle requests and incidents. This policy explains which personal data is processed and which choices users have.
Who is responsible?
The organisation that created your OneStep account is generally responsible for employee and client data. OneStep provides the technical service and helps the organisation process data securely. Privacy questions can be sent to support@onestep.center.
Data we process
We may process your name, username, role, language, organisation, teams, schedules, attendance, worked hours, task status, requests, incidents, notes, work locations, photos, completion times and technical data required for sessions, security, troubleshooting and push notifications.
Why we process data
We process data to authenticate users, plan and record work, show relevant tasks and photos, handle requests and incidents, inform authorised users and keep OneStep secure and reliable. We do not sell personal data or use it for advertising tracking.
Storage and service providers
Data and photos are stored using Supabase. The web application is delivered through Vercel and mobile notifications may be sent through Expo. These providers process only the data needed for their technical function. Access is limited by organisation and user role.
Retention and deletion
Data is retained while an account is active and for as long as needed for planning, accountability, security and legal obligations. The connected organisation may apply additional retention periods. Data that is no longer required is deleted or anonymised.
Your rights and security
You may request access, correction, restriction, transfer or deletion of your personal data. Contact the organisation managing your account or use the account deletion page. OneStep uses encrypted connections, secure session storage and access controls, but no system is completely risk-free.
