Privacy policy
Last updated: 1 September 2026
This is a translation. The Swedish version at /integritet is the authoritative text and prevails in the event of any discrepancy. The translation has not yet been reviewed by a lawyer.
Introduction
Onesync, a service from Nordic Technologies AB (company reg. no. 559563-9146), respects your privacy and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Swedish law. In this policy "we", "us" and "our" mean Nordic Technologies AB. It explains how we collect, use, store and protect information when you use our platform as a business.
By using Onesync you accept the terms of this privacy policy.
Data controller
The personal data we collect
1. Information you give us directly
- Account details: Name, email address, password (encrypted via Supabase Auth)
- Business information: Business name, address, phone number, opening hours, logo
- Business data: Menu information, prices, offers, lunch menus, images
- Social media: OAuth tokens when connecting Facebook, Instagram, TikTok or Google Business Profile (encrypted with AES-256-GCM)
2. Information we collect automatically
- Device information: IP address, browser, operating system
- Usage data: Pages you visit, features you use
- Cookies: See our cookie policy
How we use your data
Providing our services:
- Creating and managing your business account
- Managing menus, offers and lunch menus
- Publishing content on connected social media platforms
- Managing your Google Business Profile
- AI generation of content based on your menu data
Analysis and improvement:
- Analysing usage patterns in order to improve the service
- Troubleshooting and technical support
Communication:
- Sending transactional messages (account confirmations and the like)
- Answering questions and support cases
Legal basis for processing
Under GDPR Article 6 our processing rests on the following grounds:
Performance of a contract (Art. 6(1)(b))
- Creating and managing your business account
- Providing the platform features (menu management, AI chat, social media)
- Publishing content on connected platforms
Consent (Art. 6(1)(a))
- Visit statistics for onesync.se (our own measurement, no analytics cookies)
- Marketing cookies (Meta, Google) — prepared, none active today
You can withdraw your consent at any time through the cookie settings in the footer.
Legal obligation (Art. 6(1)(c))
- Retention of transaction data under the Swedish Accounting Act (at least 7 years)
- Compliance with consumer protection law
Legitimate interest (Art. 6(1)(f))
- Improving and developing the service through analysis
- Security measures and fraud prevention
- Troubleshooting and technical support
Cookies
We use cookies to improve your experience. You can manage your cookie settings by clicking "Cookie" in the footer.
Necessary cookies (always on)
Required for sign-in, security and basic functionality.
Analytics and statistics (requires consent)
Our own anonymised visit statistics. They run on onesync.se, set no cookies and never leave our database.
Marketing cookies (requires consent)
Prepared for future use. No marketing cookies are active at present.
Social media integrations
When you connect your social media accounts we store:
- Encrypted OAuth tokens: Access tokens are encrypted with AES-256-GCM before storage. We never have access to your password.
- Account information: Page name and account ID, so we can publish to the right page or account.
- Google Business Profile: Location name and account ID, to manage opening hours, reviews and photos.
You can disconnect your accounts at any time. On disconnection all stored tokens are deleted.
Google API Services and limited use
Onesync's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Requested OAuth scope and purpose:
https://www.googleapis.com/auth/business.manageWe request this scope in order to manage your Google Business Profile on your behalf. It allows us to:
- Read and update the business profile (name, address, opening hours, categories)
- Fetch and reply to customer reviews
- Upload and manage photos
- Publish posts and offers
- Fetch statistics (views, searches, clicks, direction requests)
Limited use. We use data from Google APIs solely to provide the features described above. We do not use Google data to serve advertising, and we do not sell, rent or share Google data with third parties for advertising, data brokerage or any purpose beyond delivering our service.
Human access. Onesync staff may be granted read access to your Google Business Profile data only where it is required to give you technical support and you have asked for it, or where it is required by law. We do not read, copy, store or share your Google data beyond what is necessary to provide the service.
Revoking access. You can revoke Onesync's access to your Google Business Profile at any time via myaccount.google.com/permissions. We then delete all stored tokens immediately.
AI features
Our platform uses AI to:
- Generate social media content based on your menu data (Claude by Anthropic)
- Answer customer questions in the AI chat based on your menu information (OpenRouter and OpenAI)
- Improve posts and content
Your data is sent to Anthropic's, OpenAI's and OpenRouter's APIs for processing in the United States. None of these providers use the data to train their models. What your own customers write in the chat on your website is passed on to OpenRouter and OpenAI — if a guest types their name or phone number into a message, it goes with it. We send nothing from your customer records to the AI services.
Your rights under the GDPR
How to exercise your rights:
- Contact us at info@onesync.se
- Describe which right you want to exercise
- We reply within 30 days
If you instead wrote to a business through the chat on its website, or through Instagram, Facebook Messenger or WhatsApp, and want that conversation deleted, that is described on Delete your data.
Right to lodge a complaint
If you believe we are processing your personal data incorrectly, you have the right to complain to:
The Swedish Authority for Privacy Protection (IMY)
Box 8114, 104 20 Stockholm, Sweden
Phone: +46 8 657 61 00
Email: imy@imy.se
Web: www.imy.se
Data security
- HTTPS/TLS encryption for all data traffic
- AES-256-GCM encryption for all stored OAuth tokens
- Row Level Security (RLS) in the database
- Supabase hosting inside the EU (Stockholm, Sweden)
- Regular security reviews
Retention periods
Account details
Until you delete your account or request erasure.
Business data (menus, images, and so on)
Until you delete them or close your account.
Transaction data
At least 7 years, under the Swedish Accounting Act.
OAuth tokens (social media)
Until you disconnect the account. Deleted immediately on disconnection.
Visit statistics
Kept until further notice in anonymised form. The IP address is stored only as a hash with a salt that changes every day, so a visitor cannot be recognised the following day.
Third-party providers
Supabase Inc.
Database and authentication. EU (Stockholm, Sweden). GDPR compliant.
Vercel Inc.
Web hosting. USA with EU edge nodes. EU-US Data Privacy Framework. No analytics service — the visit statistics are collected and stored by us.
Anthropic (Claude AI)
AI content generation. USA. Data is not stored permanently and is not used for model training.
OpenAI Inc.
AI-powered customer chat. USA. EU-US Data Privacy Framework. Data stored for at most 30 days.
OpenRouter, Inc.
Routes the customer chat’s calls to the language model. USA.
Resend
Email service for transactional messages.
Transfers outside the EU/EEA
Some providers process data in the USA. Safeguards: the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
Contact us
Questions about privacy, or about how we handle your data?
Company: Nordic Technologies AB (company reg. no. 559563-9146)
Email: info@onesync.se