Privacy Policy
Last updated: 2026-07-13
OneCount Pty Ltd · ACN 695 536 415 · ABN 29 695 536 415
1. Who we are
OneCount is operated by OneCount Pty Ltd. This policy explains how we handle information across the public website and OneCount product. It was reviewed on 12 July 2026 and updated on 13 July 2026.
2. Information we collect
Public website
- Contact form: email, name, company, and the message you choose to submit. Contact-form submissions are stored as rows in Supabase for support follow-up. When a server secret is configured, a server-keyed hash of the request IP may also be stored for abuse and security review; this is not the raw IP address.
- Waitlist forms: email and the initial product or integration interest from the signup source, stored in Supabase.
- Web analytics: Vercel Web Analytics is active. According to Vercel, it uses anonymised and aggregated data and is cookie-less. OneCount sends redacted public paths and controlled enum or boolean events. Vercel says a data point can include a timestamp, referrer, coarse location, browser, operating system, and device type.
- Analytics exclusions: query strings and hashes from OneCount page URLs, form values, email, name, message, organisation or user IDs, invoice content, and private or authenticated routes are excluded from Web Analytics. These exclusions do not describe ordinary hosting, security, or runtime logs used to operate the service.
- Browser storage: essential Supabase authentication storage and the functional
onecount-themecookie/local-storage presentation preference described in our Cookie Notice. The preference only chooses Operational or Paper mode; it does not change operational data or track users.
OneCount product
Depending on the features you use, product records can include:
- Account identity and organisation, venue, location, and membership records.
- Stocktake sessions, count entries, catalog, supplier, pricing, and invoice records.
- Files or images stored by an enabled workflow, except invoice source media. Invoice source photos and PDFs are processed in memory for extraction and are not stored by OneCount; extracted invoice records can be stored for the workflow.
- Subscription and entitlement state.
- Diagnostic information produced by the website runtime or conditional mobile monitoring.
OneCount Shield
OneCount Shield is a compliance and audit product in development. When you use Shield, records can include food-safety checks, temperature readings, corrective actions, evidence photos, audit events, cleaning schedules, equipment records, training and certificate records, and supplier documents. Shield does not claim live sensors, automated verification, or a released product. Shield records follow the same retention, security, and access rules described in this policy.
3. How we use information
- Provide, secure, and support OneCount.
- Run the workflows and integrations you choose to use.
- Investigate reliability, security, and abuse issues.
- Communicate about an account, invitation, support request, or required incident notice.
- Understand aggregate use of public pages and coarse product-interest events.
4. Providers and disclosure
Current providers include Supabase, OpenAI, RevenueCat, Vercel, conditional mobile Sentry, and Resend. Resend is used for configured email workflows such as organisation invitations, not for public contact or waitlist submissions. Each provider receives only the information needed for the configured service. See our Subprocessors page for the current operational boundary. We do not sell personal information.
5. Security and access
Authenticated user paths use Supabase row-level security. Privileged server paths can bypass row-level security and therefore require their own authorization and tenant checks. See Security at OneCount for the current public access model.
6. Retention and deletion
We keep records while they are needed to provide the service and may retain limited records where law, security, fraud prevention, backup handling, or an organisation's continuing obligations require it. No fixed retention period is published. Account deletion is described on the Delete account page.
7. Your choices and rights
You can request access to or correction of personal information, ask about deletion, or raise a privacy complaint by emailing hello@onecount.ai. Australian privacy rights and any legal retention duties continue to apply.