Privacy Policy
Effective date: March 13, 2026
This Privacy Policy explains how OneShare ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use our file delivery platform, website, and related services (the "Service").
We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and all other applicable data protection laws.
Please read this Privacy Policy carefully. By using the Service, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms and Conditions.
1. Introduction
This Privacy Policy applies to personal data processed through OneShare account creation, guest transfers, branded Delivery Pages, payment flows, support communications, tracking, and related product surfaces.
2. Data Controller
OneShare is the data controller responsible for your personal data. If you have questions or wish to exercise your data protection rights, you may contact us at:
OneShare
Email: [email protected]
3. Personal Data We Collect
We collect different categories of personal data depending on how you interact with the Service.
3.1 Data You Provide Directly
- Account registration data: name, email address, and password when you create an Account.
- Profile and branding data: company name, logo, brand colors, background images, and personal messages you configure for Delivery Pages.
- Transfer data: recipient email addresses, file names, file sizes, optional password settings, and personal messages attached to transfers.
- Payment data: billing name, billing address, and country. Full payment card details are collected and processed exclusively by Stripe and are never stored on our servers.
- Communications: content of emails, support tickets, or messages you send to us.
3.2 Data Collected Automatically
- Device and browser data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage data: pages visited, features used, transfer history, volume consumption, timestamps, referral URLs, and click patterns.
- Delivery tracking data: timestamps and metadata indicating when a delivery email was opened, when a Delivery Page was viewed, and when files were downloaded.
- Cookie and tracking data: information collected via cookies, pixels, and similar technologies as described in Section 8.
3.3 Data from Third Parties
- Advertising platforms: Google Ads and Meta may provide aggregated conversion data and audience insights based on interactions with our advertisements.
- Payment processor: Stripe provides transaction confirmations, partial card details, and fraud risk assessments.
4. How We Use Your Personal Data
We process your personal data only when we have a valid legal basis to do so. The table below describes our purposes and corresponding legal bases under Article 6 of the GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service | Account data, transfer data, file metadata, delivery tracking data | Performance of contract (Art. 6(1)(b)) |
| Process payments and issue receipts | Billing name, address, country, and Stripe transaction data | Performance of contract (Art. 6(1)(b)) |
| Send transactional emails | Email address, name, transfer details | Performance of contract (Art. 6(1)(b)) |
| Send marketing communications | Email address, name, usage preferences | Consent (Art. 6(1)(a)) |
| Measure advertising effectiveness | Pseudonymized identifiers, conversion events, hashed IP address | Consent (Art. 6(1)(a)) via cookie banner |
| Improve the Service, analyze usage patterns, and fix bugs | Usage data, device data, error logs | Legitimate interest (Art. 6(1)(f)) |
| Detect and prevent fraud, abuse, and security threats | IP address, usage patterns, device fingerprint | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Account data, transaction records, transfer metadata | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting [email protected].
5. Your File Content
We do not access, view, analyze, or use the content of your files for any purpose other than providing the Service. Files are stored in encrypted form and transmitted to Recipients as-is.
We will never use your files to train artificial intelligence or machine learning models. This is a core commitment of the OneShare platform.
With respect to file Content, we act as a data processor on your behalf. If the files you transfer contain personal data of third parties, you are the data controller for that data and are responsible for ensuring you have a lawful basis to share it.
6. Third-Party Service Providers
We share personal data with categories of third-party service providers acting as data processors under data processing agreements that ensure GDPR-compliant protections.
| Provider | Purpose | Data shared | Safeguards |
|---|---|---|---|
| Stripe | Payment processing | Billing name, address, country, payment card details handled directly by Stripe | PCI DSS Level 1 certified, EU SCCs, DPA in place |
| Mailjet | Transactional and marketing email delivery | Recipient email addresses, sender name, email content, delivery timestamps | EU-based, GDPR-compliant, DPA in place |
| Google Ads | Advertising measurement and conversion tracking | Pseudonymized user identifiers, conversion events, hashed IP address | EU SCCs and consent-based activation |
| Meta Ads | Advertising measurement and conversion tracking | Pseudonymized user identifiers, conversion events, hashed IP address | EU SCCs and consent-based activation |
| Cloud infrastructure provider | File storage and delivery infrastructure | Encrypted file content and account metadata | AES-256 at rest, TLS in transit, DPA in place |
We do not sell your personal data to any third party. We do not share your personal data with third parties for their own marketing purposes.
7. International Data Transfers
Some of our third-party service providers process data outside the European Economic Area (EEA). When personal data is transferred outside the EEA, we ensure adequate protection through one or more of the following mechanisms:
- EU Standard Contractual Clauses: approved by the European Commission under Decision 2021/914 and incorporated into our data processing agreements.
- Adequacy decisions: where the European Commission has determined that the recipient country provides an adequate level of data protection.
- Supplementary measures: including encryption, pseudonymization, and contractual restrictions on data access.
You may request a copy of the applicable safeguards by contacting [email protected].
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service, analyze usage, and deliver relevant advertising.
8.1 Strictly Necessary Cookies
These cookies are essential for the Service to function and cannot be disabled. They include session cookies for authentication, security tokens, and cookie consent preferences. No consent is required for these cookies under the ePrivacy Directive.
8.2 Analytics Cookies
With your consent, we use analytics cookies to understand how visitors interact with the Service. These cookies collect aggregated, anonymized usage data such as page views, session duration, and feature adoption.
8.3 Advertising Cookies
With your consent, we use advertising cookies and tracking pixels from Google Ads and Meta Ads to measure advertising effectiveness and to deliver relevant advertisements on third-party platforms.
- Google Ads: We use Google Ads conversion tracking and may use remarketing tags to identify users who visited our site or completed specific actions. You can manage preferences at adssettings.google.com.
- Meta Pixel: We use the Meta Pixel to track conversions from Facebook and Instagram advertisements and to build custom audiences. You can manage advertising preferences in your Facebook account settings.
8.4 Your Cookie Choices
When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You may change your preferences at any time by clicking the Cookie Settings link in the footer of our website.
You can also control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
9. Delivery Tracking and Recipient Privacy
When a Sender transfers files through OneShare, we collect limited data from Recipients to provide the delivery tracking feature.
- The timestamp when a delivery email is opened via a tracking pixel embedded in the email.
- The timestamp and IP address when a Delivery Page is viewed.
- The timestamp when files are downloaded.
This data is collected under the legitimate interest of the Sender under Article 6(1)(f) GDPR to confirm successful file delivery. We minimize the data collected and retain it only for the duration described in Section 11.
Recipients who have not created an Account are not subject to advertising cookies. Delivery Pages for Recipients contain only strictly necessary cookies.
10. Email Communications
We use Mailjet to send both transactional and marketing emails.
10.1 Transactional Emails
These include delivery notifications, volume usage alerts, account verification emails, password reset emails, and payment confirmations. You cannot opt out of transactional emails as they are necessary to provide the Service.
10.2 Marketing Emails
With your explicit consent, we may send newsletters, product updates, promotions, and tips for using the Service. Every marketing email contains a clear unsubscribe link. You may also manage your email preferences in your Account settings. We will honor unsubscribe requests within forty-eight (48) hours.
We do not share your email address with third parties for their own marketing purposes.
11. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law.
| Data category | Retention period |
|---|---|
| Account data | Duration of account plus 30 days after deletion request |
| File content (paid transfers) | Minimum 14 days from transfer, deleted after availability period |
| File content (guest transfers) | 7 days from transfer |
| Delivery tracking data | 12 months from the date of transfer |
| Payment and billing records | 7 years |
| Marketing consent records | Duration of consent plus 3 years after withdrawal |
| Server access logs | 90 days |
| Cookie data | As specified in cookie consent settings, up to 13 months for advertising cookies |
When data is no longer needed, we securely delete or anonymize it.
12. Your Data Protection Rights
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
- Right to restriction: You may ask us to restrict processing of your personal data in certain circumstances.
- Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to object: You may object to processing based on legitimate interest or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: You may file a complaint with your local data protection authority if you believe your rights have been violated.
To exercise any of these rights, please contact [email protected]. We will respond to verified requests within thirty (30) days, as required by the GDPR. We may ask you to verify your identity before processing a request.
13. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
- Encryption in transit using TLS 1.2 or higher for all data transmissions.
- Encryption at rest using AES-256 or equivalent for stored files and sensitive data.
- Access controls limiting employee and contractor access to personal data on a need-to-know basis.
- Regular security assessments and vulnerability testing.
- Secure development practices including code review and dependency auditing.
- Incident response procedures to detect, investigate, and report data breaches within seventy-two (72) hours to the relevant supervisory authority where required.
No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
14. Children's Privacy
The Service is not directed to individuals under the age of sixteen (16). We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that data promptly.
If you believe a child has provided us with personal data, please contact us at [email protected].
15. Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you, as defined under Article 22 of the GDPR. Advertising audience segmentation by Google Ads and Meta Ads occurs on their platforms and is governed by their respective privacy policies.
16. Do Not Track Signals
Some browsers transmit a Do Not Track signal. There is currently no universally accepted standard for how websites should respond to those signals. We honor your cookie consent preferences as described in Section 8 and treat the rejection of advertising cookies as equivalent to a Do Not Track request.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational reasons. If we make material changes, we will notify you via email or a prominent notice within the Service at least thirty (30) days before the changes take effect.
The Effective Date at the top of this policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.
18. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
OneShare - Data Protection
Email: [email protected]
General support: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.