Privacy Policy
How OnCee handles personal data. This document describes what the product actually does today.
Counsel review needed
Data we collect
To operate the service, OnCee stores:
- Account identity: your email address and display name, held in Firebase Authentication.
- An optional phone number, if you provide one, so we can reach you by SMS or voice call for alerts.
- Your organization membership and role, and the teams you belong to.
- On-call rotations, schedules, shift trades, and the availability you set.
- Alerts and their contents (including any payload sent by your integrations), together with the notification and action history for each alert.
- Your notification preferences, quiet hours, and saved alert filters.
- Mobile push-device tokens, if you enable push notifications, so we can deliver alerts to your device.
How we use it
Your data is used to run the service you signed up for: routing and de-duplicating alerts, resolving who is on call, escalating until an alert is acknowledged, and delivering notifications by email, SMS, voice call, and push. Billing information is used to manage your subscription.
Sub-processors
OnCee relies on the following third parties to deliver the service. Each processes only the data needed for its function:
- Google Cloud and Firebase: authentication and data storage.
- SendGrid: email delivery.
- Twilio: SMS and voice-call delivery.
- Stripe: billing and payment processing.
Depending on how a given deployment is hosted, infrastructure providers may also include Vercel (application hosting), Neon (managed PostgreSQL), and Upstash (managed Redis). These are environment-dependent and should be confirmed for your specific deployment.
Counsel review needed
Data retention
Alerts and their full history are retained for 3 years, after which they are automatically and permanently purged. Your account and organization data are kept for as long as your account and organization exist; deleting your account or your organization removes that data as described below.
Your rights
You can exercise the following directly in the product:
- Access and portability. Download a machine-readable copy of your personal data from Settings → Account → Data & privacy. Organization superadmins can export their organization’s data from Organization Settings.
- Erasure. Delete your account and personal data from Settings → Account → Data & privacy. When you delete your account, your identity is removed and historical records that referenced you are kept only in anonymized form. A superadmin can delete an entire organization and all of its data.
Counsel review needed
Security
Data is transmitted over encrypted connections. Each organization’s data is isolated so one organization cannot read another’s. Integration credentials are held in a dedicated secrets manager rather than in the application database, and are never included in data exports.
Contact and changes
Counsel review needed