Privacy Policy

How OnCee handles personal data. This document describes what the product actually does today.

Counsel review needed

The effective date, the identity and contact details of the data controller, the legal bases for processing, and any region-specific disclosures (GDPR, UK GDPR, CCPA/CPRA) still need to be set and reviewed by qualified counsel before this policy is published or relied upon. The sections below state the product’s real data practices and are the factual input for that review.

Data we collect

To operate the service, OnCee stores:

  • Account identity: your email address and display name, held in Firebase Authentication.
  • An optional phone number, if you provide one, so we can reach you by SMS or voice call for alerts.
  • Your organization membership and role, and the teams you belong to.
  • On-call rotations, schedules, shift trades, and the availability you set.
  • Alerts and their contents (including any payload sent by your integrations), together with the notification and action history for each alert.
  • Your notification preferences, quiet hours, and saved alert filters.
  • Mobile push-device tokens, if you enable push notifications, so we can deliver alerts to your device.

How we use it

Your data is used to run the service you signed up for: routing and de-duplicating alerts, resolving who is on call, escalating until an alert is acknowledged, and delivering notifications by email, SMS, voice call, and push. Billing information is used to manage your subscription.

Sub-processors

OnCee relies on the following third parties to deliver the service. Each processes only the data needed for its function:

  • Google Cloud and Firebase: authentication and data storage.
  • SendGrid: email delivery.
  • Twilio: SMS and voice-call delivery.
  • Stripe: billing and payment processing.

Depending on how a given deployment is hosted, infrastructure providers may also include Vercel (application hosting), Neon (managed PostgreSQL), and Upstash (managed Redis). These are environment-dependent and should be confirmed for your specific deployment.

Counsel review needed

Confirm the final sub-processor list for the production deployment, add each processor’s legal entity and the safeguards for any international transfers, and publish it in the form your jurisdiction requires (for example, a linked sub-processor list with a change-notice commitment).

Data retention

Alerts and their full history are retained for 3 years, after which they are automatically and permanently purged. Your account and organization data are kept for as long as your account and organization exist; deleting your account or your organization removes that data as described below.

Your rights

You can exercise the following directly in the product:

  • Access and portability. Download a machine-readable copy of your personal data from Settings → Account → Data & privacy. Organization superadmins can export their organization’s data from Organization Settings.
  • Erasure. Delete your account and personal data from Settings → Account → Data & privacy. When you delete your account, your identity is removed and historical records that referenced you are kept only in anonymized form. A superadmin can delete an entire organization and all of its data.

Counsel review needed

Add the formal statement of data-subject rights required for your jurisdiction (access, rectification, erasure, restriction, objection, portability, and the right to lodge a complaint with a supervisory authority) and the channel for requests that cannot be self-served.

Security

Data is transmitted over encrypted connections. Each organization’s data is isolated so one organization cannot read another’s. Integration credentials are held in a dedicated secrets manager rather than in the application database, and are never included in data exports.

Contact and changes

Counsel review needed

Provide the contact address for privacy enquiries (and a Data Protection Officer or EU/UK representative if one is required), and the process and notice period for changes to this policy.