Legal
Privacy Policy
This Privacy Policy explains how There Consulting (“we,” “us,” or “our”) handles personal information in connection with OneSpot (the “Service”). We take a plain, minimal approach: we collect what we need to run the Service, we do not sell personal information, and we tell you who we rely on to operate.
It should be read together with our Terms of Service.
1.Overview and our role
We handle personal information in two distinct roles:
- As a controller — for information about our accounts, website visitors, and billing, we decide how and why it is processed, and this Policy governs it.
- As a service provider (processor) — for the content an organization and its members put into their workspace (“Customer Data”), we process it on that organization’s behalf and under its instructions. The organization is responsible for that data and for its own privacy practices. If you are a member of an organization, direct questions and requests about your workspace data to your organization’s administrator.
2.Information we collect
Account and profile
Your name, email address, and the organization and role you belong to. OneSpot signs you in with a one-time email link, so we do not store a password for you. You may add optional profile details such as an avatar or title.
Organization content (Customer Data)
The discussions, decisions, broadcasts, courses, documents, files, comments, and similar material created within a workspace, along with related metadata such as authorship, timestamps, read receipts, and audience.
Usage and device information
Basic technical information such as IP address, browser and device type, pages viewed, and actions taken, collected through server logs and similar means to keep the Service secure and working.
Billing information
If your organization is on a paid plan, our payment provider (Stripe) processes payment details. We receive limited billing information such as the plan, status, and the last four digits of a card — we do not store full card numbers.
Communications
If you contact us for support, we keep your messages and contact details to respond and keep a record.
3.How we use information
- to provide, operate, secure, and maintain the Service;
- to authenticate you and send sign-in links;
- to send service messages such as invitations, notifications, and important notices;
- to process payments and manage subscriptions;
- to provide support and respond to requests;
- to understand and improve how the Service is used, and to develop new features;
- to detect, prevent, and address abuse, security incidents, and technical issues; and
- to comply with legal obligations and enforce our Terms.
Where OneSpot shows leaders engagement insight — such as whether a broadcast was read — it exists to help an organization communicate well with its people, not to monitor individuals, and administrative access to it is itself recorded in an audit log.
4.Consent and legal basis
We collect, use, and disclose personal information with your consent and as permitted or required by applicable privacy law, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Consent may be express or implied depending on the sensitivity of the information and the circumstances, and you may withdraw it subject to legal and contractual limits — though doing so may mean we can no longer provide the Service. Where we process Customer Data, we do so on the instructions of the organization that controls it.
6.Service providers
We rely on a small set of trusted providers to operate the Service. Each processes personal information only as needed to provide their service to us:
- Supabase — database, authentication (including sign-in emails), and file storage.
- Vercel — application hosting and content delivery.
- Stripe — payment processing for paid plans.
- A transactional email provider — delivery of product emails such as invitations and notifications.
We may update this list as our providers change, and will keep it current here.
7.Where your data is stored
Your organization’s workspace data is stored in Canada, in the Canadian region of our database provider. Some of our service providers — such as those handling hosting, payments, or email delivery — may process limited personal information in other countries, including the United States. Where information is processed outside your province or country, it may be accessible to authorities in those jurisdictions in accordance with their laws, and we rely on appropriate contractual and technical safeguards to protect it.
8.How long we keep it
We keep personal information for as long as your account or your organization’s workspace is active, and as needed to provide the Service. When an account or workspace is closed, we delete or de-identify the associated Customer Data within a reasonable period, except where we must retain certain information to comply with law, resolve disputes, or enforce our agreements, and except for residual copies held in routine backups for a limited time.
9.How we protect it
We use technical and organizational measures appropriate to the sensitivity of the information, including encryption in transit (TLS) and at rest, role-based access controls, tenant isolation between organizations, and an immutable audit log of administrative actions. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to issues. You can read more on our Security & trust page.
10.Your rights and choices
Subject to applicable law, you may ask to access the personal information we hold about you, to correct it if it is inaccurate, and to delete it or withdraw your consent to its use. To make a request, email hello@onespotaccess.com. We will respond within the time required by law and may need to verify your identity first.
If you are a member of an organization, that organization controls your workspace data, so we may refer your request to its administrator or act on their instructions.
If you have a concern we have not resolved, you have the right to contact the Office of the Privacy Commissioner of Canada or your local privacy regulator.
12.Children
The Service is intended for organizations and their adult members. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13.Changes to this policy
We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice in the Service or by email. Your continued use of the Service after an update means you accept the revised Policy.
14.Contact us
To ask a question or exercise a right under this Policy, contact:
There Consulting
Ontario, Canada
hello@onespotaccess.com
Questions about this document? Email hello@onespotaccess.com.