Privacy Policy

OneFront (“we”, “our”, or “us”) operates onefront.me. This policy explains what data we collect, why we collect it, and how we protect it.

1. Who This Applies To

This policy covers two groups: Providers — professionals who create an OneFront profile — and Visitors — people who visit a provider’s public storefront and may submit a booking enquiry.

2. Data We Collect

From Providers (you, when you sign up):

  • Name and email address from your Google account (via OAuth).
  • Profile information you enter: business name, bio, photo, phone number, office address, areas of practice, and similar fields.
  • Cal.com integration tokens, if you connect your calendar.
  • Payment status (paid / trial) — we do not store card details.

From Visitors (people viewing your storefront):

  • Name, email, phone number, and notes submitted through the booking form.
  • Anonymous analytics events: page views, booking intent clicks, contact saves, and share clicks. No cookies or fingerprinting are used — events are tied to the provider’s account, not to individual visitors.

3. How We Use Your Data

  • To create and maintain your provider profile and dashboard.
  • To forward booking enquiries from visitors to you (the provider).
  • To display aggregate analytics on your dashboard (views, booking funnel).
  • To send transactional emails related to your account (e.g. auth confirmations).
  • To enforce the free trial period and paid subscription status.

We do not sell your data, use it for advertising, or share it with third parties beyond the services listed below.

4. Third-Party Integrations

  • Google Sign In — used only to authenticate your identity. We receive your name and email; we do not receive access to your contacts, calendar, or any other account data.
  • Cal.com — if you connect your calendar, booking availability and confirmation are handled by Cal.com under their own privacy policy.

5. Data Retention

Provider profile data is retained for as long as your account is active. Anonymous analytics events older than 30 days are automatically purged. If you delete your account, all associated profile and booking data is permanently deleted within 30 days.

Visitor booking submissions are visible in your dashboard and are deleted when you delete your account or the individual booking record.

6. Your Rights

Depending on where you are located, you may have rights over your personal data including access, correction, deletion, portability, and the right to object to processing (e.g. under GDPR, CCPA, or equivalent laws in your jurisdiction). To exercise any of these rights, email us at the address below. Providers can also delete their account and all associated data directly from the dashboard. For visitors, requests may be directed to the provider who received your booking, or to us directly.

7. Security

Your data is stored securely with access controls enforced at the database level. Server-side operations use privileged keys that are never exposed to the client. We do not store passwords — authentication is handled via Google Sign In.

8. Children

OneFront is not directed at children under 13. We do not knowingly collect data from anyone under 13.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered providers. Continued use of OneFront after changes take effect constitutes acceptance.

10. Contact

Questions about this policy? Email us at support@onefront.me.