Privacy Policy
Privacy Policy
Status: Owner / Legal Review
This is a pre-legal-review master, not a finalized, lawyer-reviewed policy. It is not a substitute for jurisdiction-specific legal drafting. Sections marked "Pending — Owner / Legal Decision Required" are genuine open variables and should not be read as decided.
This Privacy Policy explains what personal data ONETO actually collects, why, how it is used, who can see it, who it may be shared with, how long it is kept, and how you can raise a request about your data — grounded directly in the current product, not a generic template.
Introduction
This Privacy Policy explains what personal data ONETO collects, why, how it is used, who can see it, who it may be shared with, how long it is kept, and how a user can raise a request about their data. It applies to use of ONETO and works together with the Terms of Service, which govern use of the platform more broadly.
"ONETO," "we," or "us" refers to the entity operating the platform.
Pending — Owner / Legal Decision Required
The contracting legal entity and its registered address have not yet been finalized (see docs/EXTERNAL/COMPANY_PROFILE_MASTER.md); this document does not invent a name or address, and that gap should be read together with the same open item in the Terms of Service.
Information We Collect
ONETO collects the personal data described below, organized by the part of the platform it comes from. This list reflects what the product actually stores today — not every field theoretically possible, and not features that are planned but not built.
Account and profile
Email address, a securely hashed password (ONETO does not store passwords in plain text), display name, language preference, country and city if provided, account status, and — separately, in your profile — first and last name, timezone, an optional short bio, and an avatar. Phone number and WhatsApp number are optional profile fields that are private to you by design: they are not displayed on public or marketplace-facing profile views and are available to you through your private profile settings.
Organizations
If you create or join an Organization, ONETO stores the organization's name, type, country, optional registration number and website, a description, and which user accounts are members and in what role. An Organization is a shared business identity represented by its member accounts — it is not an independent login identity of its own.
Task and execution data
When you publish or work on a Task, ONETO stores the Task's title, country/city, brief description, budget and deadline, language, and status, along with the Work Order, any Change Orders, and execution requests tied to it. Separately, a Task may have private execution details — an exact address, a contact name and phone number, access instructions, an availability window, and private notes — which are stored apart from the public Task fields and visible only to the requester and the assigned executor.
Evidence
Photos, video, files, captions, and written notes an executor submits against a Task's steps, together with who uploaded them and when, and which Task, execution, and step they relate to. Evidence supports the Task's review workflow — it is a platform record, not independently verified or certified truth.
Signal and community activity
Signal content you publish (title, body, category, images, links, files), your authorship of it, structured comments and replies, saves, and reports you file or that are filed against your content. Some Signal content may be restricted to subscribers; where that applies, ONETO also stores subscription and entitlement records (who subscribed to whom, billing interval, period dates) needed to enforce that access.
Messages and contact
Direct messages you send within a Task's execution workspace, and separately, Global Network contact requests and messages between users who are not otherwise connected through a Task. ONETO also stores who has read a conversation and when, to support the messaging feature itself.
Contact Center
If you submit a Contact Center case, ONETO stores your name, email, the category and subject you selected, your message, any related Task or Signal identifier you provided, the case status, and — separately — internal notes added by ONETO staff, which are never shown to you or any other user.
Professional qualification materials
If you apply to have a professional qualification reviewed, ONETO stores the jurisdiction, credential type, license or certificate details, issuing organization, relevant dates, your introduction, practice areas, languages, the review status, and the supporting file(s) you upload as evidence. These uploaded files are stored for review purposes and are not published; only the limited information ONETO's review process approves for platform display is shown publicly.
Payment and financial workflow records
Even though ONETO does not currently process real-money payments (see Section 9 of the Terms of Service — no live payment provider, no legal escrow, no real external payouts or refunds), the platform still records the internal financial workflow: pricing, commission, funding status, ledger entries, refund and payout status, and a persistent audit trail of these state changes. These are internal platform records of workflow state, not evidence of an actual bank transaction, and they are still personal data where they relate to an identifiable user.
Translation data
The text of public content (Signals, Tasks, profile fields) that is translated for display in another language, and — only when a participant explicitly requests translation of a specific message — the text of that private message. See Section 6.
Technical and security data
ONETO's authentication cookie and CSRF protection, your language-preference cookie, a short-lived post-login redirect cookie, and, transiently, your IP address and similar request metadata used for rate-limiting abusive traffic. ONETO also records a coarse "recently active" status derived from when you last used the platform, shown to other users as part of presence indicators — the precise timestamp itself is not shown to other users.
How We Collect Information
Directly from you
When you register, complete your profile, publish a Task or Signal, send a message, submit Evidence, open a Contact Center case, or apply for professional qualification review.
Generated through your use of the platform
Workflow records such as status changes, timestamps, Work Order versions, and the internal financial and audit records described above, created automatically as you use Task, Signal, and messaging features.
From other users or Organizations you interact with
For example, an Organization you are a member of, another participant's message in a shared Task thread, or a comment or report another user files on your Signal content.
ONETO does not purchase personal data from third-party data brokers, and does not currently collect personal data about you from external sources beyond what is described above.
How We Use Information
ONETO uses the information described above to:
- Provide and operate the platform, including account and session management
- Run the Task execution workflow — publishing, execution requests, Work Orders, evidence review, and acceptance
- Support Signal publishing, discovery, comments, and subscriptions
- Support direct messaging and Global Network contact requests
- Review submitted professional qualification materials and maintain the resulting platform display
- Operate the Contact Center and respond to inquiries
- Provide translation of public content, and of private messages when explicitly requested
- Maintain platform security, detect abuse, and enforce rate limits
- Keep platform records that support traceability, review, and dispute-related history, consistent with Platform Governance
- Support ONETO staff in the limited administrative functions described in Section 5
- Comply with applicable legal obligations, where they apply
ONETO does not use personal data for targeted advertising, does not sell personal data to third parties, does not build automated profiles for credit-scoring or similar purposes, and does not currently operate any marketing analytics or advertising-tracking system.
Public, Shared and Private Information
What is visible, and to whom, differs by feature:
Public
Public profile fields (display name, avatar, bio, self-declared specializations and regions where you choose to show them), published Signal content and its public comments, and public Task marketplace fields (title, country/city, budget, deadline, brief) are visible to other users or, where the relevant page is public, to visitors.
Shared with participants
A Task's Work Order, evidence, and private execution details (exact address, contact information, access instructions) are visible to that Task's requester and assigned executor, and to ONETO staff where necessary for an authorized operational function (for example, investigating a related Contact Center case) — they are not made public. Direct messages are visible only to the participants in that conversation.
Admin / operational access
Contact Center cases, professional-qualification review materials, Signal reports, and the records ONETO's limited administrative tools need to operate are accessible to authorized ONETO staff performing that specific function — not to the general platform team, and not published anywhere. Signal reports are platform-internal operational data: normal users do not see report counts, report status, or who filed a report, and this does not represent a unified, staff-wide moderation console — only the specific operational functions described in this policy.
Restricted / private
Professional-qualification evidence files, internal Contact Center notes, and private messages are the most restricted category: they are not public, not shown to other users outside the relevant workflow, and are accessed by ONETO staff only where necessary for the function described in this policy (for example, reviewing a submitted qualification, or investigating a Contact Center case).
Access to administrative functions is limited to accounts with an elevated platform role, gated at the system level — it is not a general staff-wide permission.
Translation and Automated Processing
Public content — Signals, Tasks, and profile fields — may be translated automatically so it can reach readers in another language. Private messages are translated only when a participant explicitly requests translation of that specific message; ONETO does not automatically translate private messages as a background process. Automated translation can be inaccurate, and the original content remains authoritative.
ONETO also uses AI-assisted functionality to support specific workflows, including helping structure a Task into a plan. This assistance supports a human decision — it does not decide on your behalf whether a request is lawful, accurate, or advisable, and it is not used to make automated legal, safety, or eligibility decisions about you.
Service Providers and Third Parties
ONETO uses a small number of third-party service providers to operate the platform, each processing personal data only to the extent needed for its function:
- Cloud hosting and infrastructure, to run the platform and its database
- Object storage, to store uploaded files such as Task reference images and Signal images, using presigned, access-controlled uploads
- External providers used for translation and AI-assisted Task planning, which may not be the same provider for each function
- Transactional email delivery, to send account and platform-related emails (for example, verification or notification emails)
ONETO does not currently connect to a live payment provider (see Section 2 and the Terms of Service); if real payment-provider capability is added in the future, that provider will process payment data under its own terms, and this section will be updated accordingly.
ONETO uses these providers for defined platform functions and limits the data shared to what is needed for those functions. Provider processing is also subject to the applicable provider terms and technical configuration.
Pending — Owner / Legal Decision Required
Formal data-processing agreements and a public sub-processor list are not yet finalized.
International / Cross-Border Processing
ONETO is a cross-border platform: its users, and the infrastructure and service providers described in Section 7, may be located in different countries. Providing the service necessarily involves processing personal data across borders — for example, a Task published by a user in one country may be reviewed by an executor in another, and content may be sent to a translation provider located elsewhere.
Pending — Owner / Legal Decision Required
The specific international-transfer mechanism applicable to this processing (for example, standard contractual clauses, an adequacy decision, or another lawful transfer basis), and the jurisdictions in which ONETO's infrastructure and controller entity are based, have not yet been finalized. This document does not invent a specific transfer mechanism or legal basis.
Data Retention
ONETO retains personal data for as long as reasonably necessary to operate the platform, maintain the integrity of platform records described in Platform Governance, support safety and security, meet legal obligations, and resolve disputes or history-related needs — for example, keeping a Task's Work Order and evidence available for as long as that record remains relevant to the parties or to platform integrity.
Pending — Owner / Legal Decision Required
A formal, field-by-field retention schedule (specific time periods for account data, Task records, Evidence, Signal content, messages, Contact Center cases, professional-qualification materials, and security records) has not yet been finalized. This document does not invent specific retention periods.
Deletion and Account Closure
ONETO does not currently have a self-service account-deletion or data-deletion flow built into the product. A user who wants to close their account, or has a question or request about their data, can contact ONETO through the Contact Center.
Deletion or removal of data may be limited where ONETO needs to retain related records for legal, security, financial, or platform-integrity reasons — for example, records connected to a completed Task, a financial workflow record, or a security-relevant event.
Pending — Owner / Legal Decision Required
The specific deletion process, response timeline, and the precise scope of what can and cannot be deleted have not yet been finalized; this document does not promise instant deletion or complete removal from every system component.
User Privacy Rights
You can contact ONETO through the Contact Center to ask about, correct, or request deletion of your personal data, or to raise another privacy-related question. ONETO will respond taking into account the request and applicable law.
The specific legal rights available to you — such as a formal right of access, correction, deletion, portability, or objection — depend on the law that applies to you and to ONETO, which varies by jurisdiction.
Pending — Owner / Legal Decision Required
Jurisdiction-specific rights language (for example, under the EU/UK GDPR, US state privacy laws, or other applicable regimes) has not yet been finalized and will be added once ONETO's controller entity, operating jurisdictions, and applicable legal regimes are confirmed. This document does not assume every user everywhere has an identical bundle of legal rights.
Cookies and Similar Technologies
ONETO currently uses only essential cookies needed to operate the platform:
- An authentication/session cookie, so you stay signed in
- A language-preference cookie, so the site remembers your chosen language
- A short-lived cookie used only to return you to the right page after signing in
CSRF protection is implemented using a signed token tied to your session, not a separate tracking cookie. ONETO does not currently use advertising cookies, marketing cookies, or third-party analytics cookies, and does not operate a cookie-preference or consent-management center, because no non-essential cookies exist today to manage. If that changes in the future, this section — and the consent mechanism it describes — will be updated accordingly.
Security
ONETO uses technical and organizational measures appropriate to the service to help protect personal data, including authentication and session controls, CSRF protection, rate limiting against abusive traffic, restricted and role-gated administrative access, and internal audit records of security-relevant events.
No platform can guarantee absolute security, and ONETO does not promise that a breach will never occur. ONETO does not publish operational security details that could themselves create risk.
Children / Minimum Age
ONETO is not directed at children, and use of the platform requires meeting ONETO's minimum age requirement.
Pending — Owner / Legal Decision Required
Consistent with the Terms of Service, a specific minimum age has not yet been finalized in policy, and registration does not currently collect date of birth or otherwise gate on age. This document does not select a specific age threshold on its own.
Changes to Privacy Policy
ONETO may update this Privacy Policy as the platform and its data practices change. An updated version will be published at this location, and additional notice will be given where appropriate or required by law.
Pending — Owner / Legal Decision Required
The specific notice method for material changes (for example, an in-product notice or an email) has not yet been finalized, consistent with the same open item in the Terms of Service.
Contact
You can reach ONETO about privacy questions, requests, or concerns through the Contact Center, which accepts general privacy inquiries and requests.
Pending — Owner / Legal Decision Required
A dedicated data-protection contact or officer, and a formal statutory privacy-notice address, have not yet been established; until they are, the Contact Center is the available channel, consistent with the same open item in the Terms of Service.
Owner / Legal Decisions Still Required
This master intentionally leaves the following open rather than inventing them.
- 1
Privacy controller / contracting legal entity and registered address (Sections 1, 16).
- 2
Final minimum age requirement, aligned with the Terms of Service (Section 14).
- 3
International-transfer mechanism and the jurisdictions ONETO's infrastructure and controller entity are based in (Section 8).
- 4
Formal, field-by-field data retention schedule (Section 9).
- 5
Self-service account/data deletion process, timeline, and scope (Section 10) — not yet built in product.
- 6
Jurisdiction-specific privacy-rights wording (e.g., GDPR, UK GDPR, US state laws, other applicable regimes) (Section 11).
- 7
Whether a dedicated Data Protection Officer or privacy contact is required, and who that is (Section 16).
- 8
Cookie-consent obligations and mechanism, if non-essential cookies are introduced in the future (Section 12).
- 9
Applicable legal-basis framework for processing (e.g., a GDPR Article 6–style basis list), if required for ONETO's eventual operating jurisdictions (Sections 4, 8).
- 10
Formal data-processing agreements and a public sub-processor list for third-party service providers (Section 7).