Privacy Policy

Effective date: March 13, 2026

This Privacy Policy explains how OneShare ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use our file delivery platform, website, and related services (the "Service").

We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and all other applicable data protection laws.

Please read this Privacy Policy carefully. By using the Service, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms and Conditions.

1. Introduction

This Privacy Policy applies to personal data processed through OneShare account creation, guest transfers, branded Delivery Pages, payment flows, support communications, tracking, and related product surfaces.

2. Data Controller

OneShare is the data controller responsible for your personal data. If you have questions or wish to exercise your data protection rights, you may contact us at:

OneShare
Email: [email protected]

3. Personal Data We Collect

We collect different categories of personal data depending on how you interact with the Service.

3.1 Data You Provide Directly

  • Account registration data: name, email address, and password when you create an Account.
  • Profile and branding data: company name, logo, brand colors, background images, and personal messages you configure for Delivery Pages.
  • Transfer data: recipient email addresses, file names, file sizes, optional password settings, and personal messages attached to transfers.
  • Payment data: billing name, billing address, and country. Full payment card details are collected and processed exclusively by Stripe and are never stored on our servers.
  • Communications: content of emails, support tickets, or messages you send to us.

3.2 Data Collected Automatically

  • Device and browser data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
  • Usage data: pages visited, features used, transfer history, volume consumption, timestamps, referral URLs, and click patterns.
  • Delivery tracking data: timestamps and metadata indicating when a delivery email was opened, when a Delivery Page was viewed, and when files were downloaded.
  • Cookie and tracking data: information collected via cookies, pixels, and similar technologies as described in Section 8.

3.3 Data from Third Parties

  • Advertising platforms: Google Ads and Meta may provide aggregated conversion data and audience insights based on interactions with our advertisements.
  • Payment processor: Stripe provides transaction confirmations, partial card details, and fraud risk assessments.

4. How We Use Your Personal Data

We process your personal data only when we have a valid legal basis to do so. The table below describes our purposes and corresponding legal bases under Article 6 of the GDPR.

How OneShare uses personal data
PurposeData usedLegal basis
Provide the ServiceAccount data, transfer data, file metadata, delivery tracking dataPerformance of contract (Art. 6(1)(b))
Process payments and issue receiptsBilling name, address, country, and Stripe transaction dataPerformance of contract (Art. 6(1)(b))
Send transactional emailsEmail address, name, transfer detailsPerformance of contract (Art. 6(1)(b))
Send marketing communicationsEmail address, name, usage preferencesConsent (Art. 6(1)(a))
Measure advertising effectivenessPseudonymized identifiers, conversion events, hashed IP addressConsent (Art. 6(1)(a)) via cookie banner
Improve the Service, analyze usage patterns, and fix bugsUsage data, device data, error logsLegitimate interest (Art. 6(1)(f))
Detect and prevent fraud, abuse, and security threatsIP address, usage patterns, device fingerprintLegitimate interest (Art. 6(1)(f))
Comply with legal obligationsAccount data, transaction records, transfer metadataLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting [email protected].

5. Your File Content

We do not access, view, analyze, or use the content of your files for any purpose other than providing the Service. Files are stored in encrypted form and transmitted to Recipients as-is.

We will never use your files to train artificial intelligence or machine learning models. This is a core commitment of the OneShare platform.

With respect to file Content, we act as a data processor on your behalf. If the files you transfer contain personal data of third parties, you are the data controller for that data and are responsible for ensuring you have a lawful basis to share it.

6. Third-Party Service Providers

We share personal data with categories of third-party service providers acting as data processors under data processing agreements that ensure GDPR-compliant protections.

OneShare third-party service providers
ProviderPurposeData sharedSafeguards
StripePayment processingBilling name, address, country, payment card details handled directly by StripePCI DSS Level 1 certified, EU SCCs, DPA in place
MailjetTransactional and marketing email deliveryRecipient email addresses, sender name, email content, delivery timestampsEU-based, GDPR-compliant, DPA in place
Google AdsAdvertising measurement and conversion trackingPseudonymized user identifiers, conversion events, hashed IP addressEU SCCs and consent-based activation
Meta AdsAdvertising measurement and conversion trackingPseudonymized user identifiers, conversion events, hashed IP addressEU SCCs and consent-based activation
Cloud infrastructure providerFile storage and delivery infrastructureEncrypted file content and account metadataAES-256 at rest, TLS in transit, DPA in place

We do not sell your personal data to any third party. We do not share your personal data with third parties for their own marketing purposes.

7. International Data Transfers

Some of our third-party service providers process data outside the European Economic Area (EEA). When personal data is transferred outside the EEA, we ensure adequate protection through one or more of the following mechanisms:

  • EU Standard Contractual Clauses: approved by the European Commission under Decision 2021/914 and incorporated into our data processing agreements.
  • Adequacy decisions: where the European Commission has determined that the recipient country provides an adequate level of data protection.
  • Supplementary measures: including encryption, pseudonymization, and contractual restrictions on data access.

You may request a copy of the applicable safeguards by contacting [email protected].

8. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Service, analyze usage, and deliver relevant advertising.

8.1 Strictly Necessary Cookies

These cookies are essential for the Service to function and cannot be disabled. They include session cookies for authentication, security tokens, and cookie consent preferences. No consent is required for these cookies under the ePrivacy Directive.

8.2 Analytics Cookies

With your consent, we use analytics cookies to understand how visitors interact with the Service. These cookies collect aggregated, anonymized usage data such as page views, session duration, and feature adoption.

8.3 Advertising Cookies

With your consent, we use advertising cookies and tracking pixels from Google Ads and Meta Ads to measure advertising effectiveness and to deliver relevant advertisements on third-party platforms.

  • Google Ads: We use Google Ads conversion tracking and may use remarketing tags to identify users who visited our site or completed specific actions. You can manage preferences at adssettings.google.com.
  • Meta Pixel: We use the Meta Pixel to track conversions from Facebook and Instagram advertisements and to build custom audiences. You can manage advertising preferences in your Facebook account settings.

8.4 Your Cookie Choices

When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You may change your preferences at any time by clicking the Cookie Settings link in the footer of our website.

You can also control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.

9. Delivery Tracking and Recipient Privacy

When a Sender transfers files through OneShare, we collect limited data from Recipients to provide the delivery tracking feature.

  • The timestamp when a delivery email is opened via a tracking pixel embedded in the email.
  • The timestamp and IP address when a Delivery Page is viewed.
  • The timestamp when files are downloaded.

This data is collected under the legitimate interest of the Sender under Article 6(1)(f) GDPR to confirm successful file delivery. We minimize the data collected and retain it only for the duration described in Section 11.

Recipients who have not created an Account are not subject to advertising cookies. Delivery Pages for Recipients contain only strictly necessary cookies.

10. Email Communications

We use Mailjet to send both transactional and marketing emails.

10.1 Transactional Emails

These include delivery notifications, volume usage alerts, account verification emails, password reset emails, and payment confirmations. You cannot opt out of transactional emails as they are necessary to provide the Service.

10.2 Marketing Emails

With your explicit consent, we may send newsletters, product updates, promotions, and tips for using the Service. Every marketing email contains a clear unsubscribe link. You may also manage your email preferences in your Account settings. We will honor unsubscribe requests within forty-eight (48) hours.

We do not share your email address with third parties for their own marketing purposes.

11. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law.

OneShare data retention periods
Data categoryRetention period
Account dataDuration of account plus 30 days after deletion request
File content (paid transfers)Minimum 14 days from transfer, deleted after availability period
File content (guest transfers)7 days from transfer
Delivery tracking data12 months from the date of transfer
Payment and billing records7 years
Marketing consent recordsDuration of consent plus 3 years after withdrawal
Server access logs90 days
Cookie dataAs specified in cookie consent settings, up to 13 months for advertising cookies

When data is no longer needed, we securely delete or anonymize it.

12. Your Data Protection Rights

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of access: You may request a copy of the personal data we hold about you.
  • Right to rectification: You may ask us to correct inaccurate or incomplete personal data.
  • Right to erasure: You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
  • Right to restriction: You may ask us to restrict processing of your personal data in certain circumstances.
  • Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
  • Right to object: You may object to processing based on legitimate interest or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: You may file a complaint with your local data protection authority if you believe your rights have been violated.

To exercise any of these rights, please contact [email protected]. We will respond to verified requests within thirty (30) days, as required by the GDPR. We may ask you to verify your identity before processing a request.

13. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

  • Encryption in transit using TLS 1.2 or higher for all data transmissions.
  • Encryption at rest using AES-256 or equivalent for stored files and sensitive data.
  • Access controls limiting employee and contractor access to personal data on a need-to-know basis.
  • Regular security assessments and vulnerability testing.
  • Secure development practices including code review and dependency auditing.
  • Incident response procedures to detect, investigate, and report data breaches within seventy-two (72) hours to the relevant supervisory authority where required.

No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

14. Children's Privacy

The Service is not directed to individuals under the age of sixteen (16). We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that data promptly.

If you believe a child has provided us with personal data, please contact us at [email protected].

15. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you, as defined under Article 22 of the GDPR. Advertising audience segmentation by Google Ads and Meta Ads occurs on their platforms and is governed by their respective privacy policies.

16. Do Not Track Signals

Some browsers transmit a Do Not Track signal. There is currently no universally accepted standard for how websites should respond to those signals. We honor your cookie consent preferences as described in Section 8 and treat the rejection of advertising cookies as equivalent to a Do Not Track request.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational reasons. If we make material changes, we will notify you via email or a prominent notice within the Service at least thirty (30) days before the changes take effect.

The Effective Date at the top of this policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.

18. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

OneShare - Data Protection
Email: [email protected]
General support: [email protected]

If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.

Privacy Policy - OneShare