Skip to content
Back to the homepage

Privacy policy

Last updated: 1 September 2026

This is a translation. The Swedish version at /integritet is the authoritative text and prevails in the event of any discrepancy. The translation has not yet been reviewed by a lawyer.

Introduction

Onesync, a service from Nordic Technologies AB (company reg. no. 559563-9146), respects your privacy and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Swedish law. In this policy "we", "us" and "our" mean Nordic Technologies AB. It explains how we collect, use, store and protect information when you use our platform as a business.

By using Onesync you accept the terms of this privacy policy.

Data controller

Company: Nordic Technologies AB

Company registration number: 559563-9146

Email: info@onesync.se

The personal data we collect

1. Information you give us directly

  • Account details: Name, email address, password (encrypted via Supabase Auth)
  • Business information: Business name, address, phone number, opening hours, logo
  • Business data: Menu information, prices, offers, lunch menus, images
  • Social media: OAuth tokens when connecting Facebook, Instagram, TikTok or Google Business Profile (encrypted with AES-256-GCM)

2. Information we collect automatically

  • Device information: IP address, browser, operating system
  • Usage data: Pages you visit, features you use
  • Cookies: See our cookie policy

How we use your data

Providing our services:

  • Creating and managing your business account
  • Managing menus, offers and lunch menus
  • Publishing content on connected social media platforms
  • Managing your Google Business Profile
  • AI generation of content based on your menu data

Analysis and improvement:

  • Analysing usage patterns in order to improve the service
  • Troubleshooting and technical support

Communication:

  • Sending transactional messages (account confirmations and the like)
  • Answering questions and support cases

Legal basis for processing

Under GDPR Article 6 our processing rests on the following grounds:

Performance of a contract (Art. 6(1)(b))

  • Creating and managing your business account
  • Providing the platform features (menu management, AI chat, social media)
  • Publishing content on connected platforms

Consent (Art. 6(1)(a))

  • Visit statistics for onesync.se (our own measurement, no analytics cookies)
  • Marketing cookies (Meta, Google) — prepared, none active today

You can withdraw your consent at any time through the cookie settings in the footer.

Legal obligation (Art. 6(1)(c))

  • Retention of transaction data under the Swedish Accounting Act (at least 7 years)
  • Compliance with consumer protection law

Legitimate interest (Art. 6(1)(f))

  • Improving and developing the service through analysis
  • Security measures and fraud prevention
  • Troubleshooting and technical support

Cookies

We use cookies to improve your experience. You can manage your cookie settings by clicking "Cookie" in the footer.

Necessary cookies (always on)

Required for sign-in, security and basic functionality.

Analytics and statistics (requires consent)

Our own anonymised visit statistics. They run on onesync.se, set no cookies and never leave our database.

Marketing cookies (requires consent)

Prepared for future use. No marketing cookies are active at present.

Social media integrations

When you connect your social media accounts we store:

  • Encrypted OAuth tokens: Access tokens are encrypted with AES-256-GCM before storage. We never have access to your password.
  • Account information: Page name and account ID, so we can publish to the right page or account.
  • Google Business Profile: Location name and account ID, to manage opening hours, reviews and photos.

You can disconnect your accounts at any time. On disconnection all stored tokens are deleted.

Google API Services and limited use

Onesync's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Requested OAuth scope and purpose:

https://www.googleapis.com/auth/business.manage

We request this scope in order to manage your Google Business Profile on your behalf. It allows us to:

  • Read and update the business profile (name, address, opening hours, categories)
  • Fetch and reply to customer reviews
  • Upload and manage photos
  • Publish posts and offers
  • Fetch statistics (views, searches, clicks, direction requests)

Limited use. We use data from Google APIs solely to provide the features described above. We do not use Google data to serve advertising, and we do not sell, rent or share Google data with third parties for advertising, data brokerage or any purpose beyond delivering our service.

Human access. Onesync staff may be granted read access to your Google Business Profile data only where it is required to give you technical support and you have asked for it, or where it is required by law. We do not read, copy, store or share your Google data beyond what is necessary to provide the service.

Revoking access. You can revoke Onesync's access to your Google Business Profile at any time via myaccount.google.com/permissions. We then delete all stored tokens immediately.

AI features

Our platform uses AI to:

  • Generate social media content based on your menu data (Claude by Anthropic)
  • Answer customer questions in the AI chat based on your menu information (OpenRouter and OpenAI)
  • Improve posts and content

Your data is sent to Anthropic's, OpenAI's and OpenRouter's APIs for processing in the United States. None of these providers use the data to train their models. What your own customers write in the chat on your website is passed on to OpenRouter and OpenAI — if a guest types their name or phone number into a message, it goes with it. We send nothing from your customer records to the AI services.

Your rights under the GDPR

Right of access: You can request a copy of all personal data we hold about you.
Right to rectification: You can update or correct inaccurate data.
Right to erasure: You can ask us to delete your personal data (the "right to be forgotten").
Right to restriction: You can ask us to restrict the processing.
Right to data portability: You can receive your data in a machine-readable format.
Right to object: You can object to certain processing, for example direct marketing.

How to exercise your rights:

  1. Contact us at info@onesync.se
  2. Describe which right you want to exercise
  3. We reply within 30 days

If you instead wrote to a business through the chat on its website, or through Instagram, Facebook Messenger or WhatsApp, and want that conversation deleted, that is described on Delete your data.

Right to lodge a complaint

If you believe we are processing your personal data incorrectly, you have the right to complain to:

The Swedish Authority for Privacy Protection (IMY)

Box 8114, 104 20 Stockholm, Sweden

Phone: +46 8 657 61 00

Email: imy@imy.se

Web: www.imy.se

Data security

  • HTTPS/TLS encryption for all data traffic
  • AES-256-GCM encryption for all stored OAuth tokens
  • Row Level Security (RLS) in the database
  • Supabase hosting inside the EU (Stockholm, Sweden)
  • Regular security reviews

Retention periods

Account details

Until you delete your account or request erasure.

Business data (menus, images, and so on)

Until you delete them or close your account.

Transaction data

At least 7 years, under the Swedish Accounting Act.

OAuth tokens (social media)

Until you disconnect the account. Deleted immediately on disconnection.

Visit statistics

Kept until further notice in anonymised form. The IP address is stored only as a hash with a salt that changes every day, so a visitor cannot be recognised the following day.

Third-party providers

Supabase Inc.

Database and authentication. EU (Stockholm, Sweden). GDPR compliant.

Vercel Inc.

Web hosting. USA with EU edge nodes. EU-US Data Privacy Framework. No analytics service — the visit statistics are collected and stored by us.

Anthropic (Claude AI)

AI content generation. USA. Data is not stored permanently and is not used for model training.

OpenAI Inc.

AI-powered customer chat. USA. EU-US Data Privacy Framework. Data stored for at most 30 days.

OpenRouter, Inc.

Routes the customer chat’s calls to the language model. USA.

Resend

Email service for transactional messages.

Transfers outside the EU/EEA

Some providers process data in the USA. Safeguards: the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.

Contact us

Questions about privacy, or about how we handle your data?

Company: Nordic Technologies AB (company reg. no. 559563-9146)

Email: info@onesync.se