Privacy Policy — Onelo
Effective date: 23 August 2026
How Onelo handles personal data — the data we control about our own customers, and the end-user data we only process on their behalf.
1. Who we are
Onelo is a toolkit for app developers — sign-in, payments, waitlists, feedback and roadmaps, with a hosted dashboard. This Privacy Policy explains how Adrian Magiera, a natural person operating the Onelo service, of ul. Mieszczańska 42/13, 53-206 Wrocław, Poland (“Onelo”, “we”, “us”) handles personal data. You can contact us about privacy at [email protected]. We have not appointed a Data Protection Officer.
It is written for two different audiences, and which one you are decides what applies to you — so please read “Our two roles” next before anything else.
2. Our two roles — read this first
Onelo handles personal data in two distinct roles, and this Privacy Policy only covers one of them.
Account Data — we are the controller. This is information about the developers and businesses who sign up for Onelo: your account, billing, and how you use the dashboard. This Privacy Policy governs Account Data, and we decide how it is processed.
End-User Data — we are only a processor. Onelo’s products let our customers collect and manage information about their own end users — sign-in profiles, waitlist signups, form and feedback submissions, subscription status (“End-User Data”). We process End-User Data only as a processor, on behalf of and under the documented instructions of the relevant customer, in accordance with our Terms and our Data Processing Agreement.
This Privacy Policy does not apply to End-User Data. The developer or business that operates the app is the controller of that data and is solely responsible for establishing a lawful basis, providing the required privacy notices to their end users, obtaining any necessary consents, and for the legality and content of the data they put through Onelo.
If you are an end user of an app built with Onelo and want to access, correct or delete your information, please contact the developer or business that runs that app and read their privacy policy — they control that data, not us. If you send such a request to Onelo, we will ask you to identify the app so we can refer it to that customer to handle as the controller.
3. Information we collect (Account Data)
You give us:
- Your email and name — entered directly, or taken from your Google, GitHub or Apple account if you sign in with one.
- Your password, stored only as a one-way hash (never in readable form).
- What you configure in the dashboard, and any messages you send our support.
We collect automatically:
- Basic log and usage data needed to run and secure the service.
- A hashed (not raw) IP address and user-agent, kept for security and audit purposes.
- Anonymous, aggregated visit statistics for our public marketing pages only — no cookies, and no profile that could identify you. See Cookies.
- Strictly-necessary cookies, plus one referral cookie if you arrive through an affiliate link — see Cookies. We do not run advertising trackers.
We receive from others: billing identifiers from our payment providers when you subscribe, and basic profile details from an OAuth provider when you choose to sign in with one.
4. How we use Account Data
We use Account Data to:
- Provide, maintain and secure the Onelo service and your account.
- Process your subscription and send you transactional and service messages (e.g. receipts, security and account notices).
- Detect, prevent and investigate abuse, fraud and security incidents.
- Comply with our legal, tax and accounting obligations.
- Improve the product, and — only where you have opted in — send you product updates.
Legal bases (EEA/UK): performance of our contract with you; our legitimate interests in securing and improving the service; compliance with a legal obligation; and your consent where we ask for it (for example, optional marketing, which you can withdraw at any time).
5. How we share it — subprocessors
We do not sell personal data. We share Account Data with vendors that process it on our behalf, under contract and only as needed to run Onelo:
- Database, authentication & storage — our cloud database provider (EU region).
- Hosting — Hetzner Online GmbH (EU, Germany).
- Payments — Stripe (processing payments your customers make), and Lemon Squeezy (merchant of record for our own subscription billing, and referral tracking for our affiliate programme).
- Email delivery — our transactional email provider, for service and lifecycle emails.
- Sign-in providers — Google, GitHub and Apple, when you choose to sign in with them.
- Bot protection & content delivery — Cloudflare (abuse prevention on public forms, and edge delivery).
- Visit statistics — Umami, a privacy-focused analytics service, for our own public marketing pages only.
A current list of our subprocessors is kept at <https://onelo.tools/legal/subprocessors>. We may also disclose data where required by law, or as part of a sale of the business or its assets (with notice where required).
6. International data transfers
Account Data is primarily stored in the European Union. Some of our subprocessors may process data outside the EEA or UK; where they do, those transfers are protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum). You can ask us for more detail at [email protected].
7. Data retention
We keep Account Data while your account is active. If you delete your account, there is a 30-day grace period (during which you can cancel), after which we erase or pseudonymise your personal data — except records we are required to keep for legal, tax or accounting reasons, such as invoices.
Retention of End-User Data is controlled by the developer (the controller). Some operational and security logs are automatically pruned on a rolling window (roughly 7–90 days, depending on plan).
8. Security
We protect data with encryption in transit (TLS), authenticated encryption of sensitive secrets, hashed credentials, per-tenant access checks and more — described on our Security page. No method of transmission or storage is 100% secure; while we use appropriate safeguards, we cannot guarantee absolute security. We will notify the relevant controller and, where required, the authorities and affected individuals, of a personal-data breach as the law requires.
9. Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, restrict, port or object to the processing of your personal data, to withdraw consent, and to lodge a complaint with a data-protection authority (in Poland: the President of the Personal Data Protection Office, UODO, <https://uodo.gov.pl>).
- For Account Data (you are an Onelo customer): email [email protected] and we will handle your request.
- For End-User Data (you used an app built with Onelo): contact the developer or business that runs that app — they are the controller. We will assist them as their processor.
10. Cookies
Onelo uses strictly-necessary cookies: a session token to keep you signed in, your interface preferences (such as light/dark theme and your last-selected app), and a record of your consent choices. We do not use advertising cookies, and we do not track you across other websites.
On our public marketing pages only (not in the dashboard, and not on any page your own users see) we measure visits with Umami, a privacy-focused analytics service. It sets no cookies and stores no identifier on your device — it records only anonymous, aggregated figures such as page, referring site, country, browser and device type. It cannot identify you or follow you to other sites.
If you reach us through an affiliate link, our affiliate provider, Lemon Squeezy, stores a referral cookie (ls_aff_ref) so the person who referred you is credited if you later subscribe. That cookie is not strictly necessary: we set it only for visitors who arrive through such a link, it is used solely to pay referral commission, and it is never used for advertising. Deleting it in your browser stops it, with no effect on your account.
11. Children
Onelo is a tool for developers and is not directed to children. We do not knowingly collect Account Data from anyone under 16. Whether an app built with Onelo is used by children, and any related obligations, are the responsibility of the developer that operates it.
12. Third-party links & services
Onelo may link to, or integrate with, third-party websites, applications and services that we do not control. We are not responsible for the privacy practices or content of those third parties; their own terms and privacy policies apply.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will take reasonable steps to notify you. The “Effective date” at the top always reflects the current version.
14. Contact us
Questions about this policy or your personal data? Email [email protected], or write to Adrian Magiera, ul. Mieszczańska 42/13, 53-206 Wrocław, Poland.
15. Region-specific notes
EEA / UK / Switzerland. Where we process End-User Data for a customer, that customer is the controller and Onelo is the processor; our processing is governed by our Data Processing Agreement (<https://onelo.tools/legal/dpa>), which includes the Standard Contractual Clauses where relevant. You have the rights described in Your rights & choices and may complain to your local supervisory authority.
California / US. We do not sell or “share” personal data as those terms are defined under California law. Where we handle End-User Data for a customer, we act as a service provider under that customer’s instructions.
If you process end-user personal data through Onelo, our Data Processing Agreement (<https://onelo.tools/legal/dpa>) applies to that processing.