Trust Center
Last updated: 2026-07-12
OneCount Pty Ltd · ACN 695 536 415 · ABN 29 695 536 415
These are direct answers about the current product. Where OneCount has no certification, automated status feed, or published service level, we say so.
Who owns the data?
Your organisation owns its operating data. OneCount processes that data to provide the service and configured features. You can request access, export available records, or stop using the service subject to the remaining organisation's records and applicable obligations.
Who can access it?
The current public role model is owner, manager, and staff. Staff use day-to-day count workflows; manager-level mobile users receive management and insights surfaces; owner-only website controls cover organisation and member governance. The detailed boundaries are on the Security page.
Authenticated user paths use Supabase row-level security. Privileged server paths can bypass row-level security, so they require separate authorization and tenant checks. We publish no live scanner finding count.
Is data shared?
OneCount uses named subprocessors only for configured product functions: Supabase, OpenAI, RevenueCat, Vercel, conditional mobile Sentry, and Resend. See the Subprocessors page for what each provider does and the data boundary. OneCount does not sell customer operating data.
How do I request deletion?
You can request account deletion in the OneCount app or contact support if you cannot access the app. The verified steps, limits, shared-organisation boundary, and store-subscription caveat are on the Delete account page. No fixed retention period is published.
How are the product and website monitored?
Sentry is conditional mobile monitoring only. The website has no Sentry Next.js runtime and currently relies on Vercel and runtime logging. Monitoring signals help investigation but do not prove the health of Supabase, sync, integrations, or other third-party services.
How are incidents communicated?
OneCount assesses the scope of an identified service issue and notifies affected account contacts when the facts, contract, or law require customer notice. There is no promise of an automatic direct notification for every incident. The current process is described on the Service status page.
Current providers
| Provider | Current role |
|---|---|
| Supabase | Authentication, database, storage, realtime, and backend functions. |
| OpenAI | AI-assisted analysis for selected workflows. |
| RevenueCat | Mobile subscription and entitlement management. |
| Vercel | Website hosting, runtime logging, and cookie-less web analytics. |
| Sentry | Conditional mobile crash and diagnostic monitoring. |
| Resend | Organisation invitation and configured owner-digest email delivery. |
What we do not claim
We are not SOC 2 audited and are not ISO/IEC 27001 certified. We do not publish an uptime SLA, an uptime percentage, or a customer-selectable data region. These are limits, not hidden certifications or commitments.
Questions
Contact hello@onecount.ai with a security, privacy, or procurement question.