Privacy Policy
Last updated: 15 June 2026
OneBooks (“OneBooks”, “we”, “us”) provides cloud accounting software. This policy explains what information we collect, why we collect it, how we protect it, and the choices you have. It covers our websites and the OneBooks application. By using OneBooks, you agree to the practices described here.
1. Information you provide
When you create an account and run your books, you give us:
- Account details — your name, email address, country, and a password. Your password is stored only as a secure one-way hash (bcrypt), never in plain text. We email you links to verify your address and to reset your password.
- Business profile — your business and legal name, address, phone, logo, tax registration number (VAT/GST/sales tax), currency and, where relevant, your business name in Arabic.
- Accounting data you enter — invoices, quotes, customers, suppliers, items, purchases, expenses, payments, journal entries, bank statements and reconciliations. This can include contact details and tax numbers of your customers and suppliers, and supplier bank details you choose to store.
- Attachments — files you upload, such as receipts and contracts (PDF or images, up to 10 MB each).
2. Information we collect automatically
We use no advertising trackers at all. On our public website we offer optional analytics (Google Analytics), which loads only if you accept it in the cookie banner — decline, or ignore it, and nothing is set. The app itself carries no analytics. Beyond that we collect the minimum needed to run and secure the service:
- Technical data — IP address, browser type and basic request logs, used to operate the service, keep it secure and prevent abuse (for example, rate-limiting sign-in attempts).
- Essential session cookie — a single first-party cookie that keeps you signed in (see “Cookies” below).
- Audit logs — a record of key actions in your workspace (who created or changed a record, and when) for your security and accountability.
3. How we use your information
We use your information to:
- Provide, maintain and secure the OneBooks service and your workspace.
- Authenticate you and process subscription billing.
- Send transactional emails — verification, password resets, team invitations and important service notices.
- Provide customer support and respond to your requests.
- Meet legal, accounting and tax obligations, and enforce our terms.
- Improve reliability and performance.
4. Payments
Subscriptions are processed by Stripe. When you subscribe, your card details are entered directly with Stripe on their PCI-DSS-compliant systems — OneBooks never receives or stores your full card number, security code or expiry date. We retain only your Stripe customer and subscription identifiers and your plan and billing status. Stripe's handling of your payment data is governed by Stripe's own privacy policy.
5. Cookies
The OneBooks app uses only the cookies strictly necessary to keep you signed in and secure: they are first-party, HttpOnly and, in production, Secure (sent over HTTPS only), and the session expires after a period of inactivity. Our public website sets optional analytics cookies only with your consent. Neither uses advertising or cross-site tracking cookies. The full list, with how long each one is kept, is in our cookie policy. The app may store non-sensitive interface preferences in your browser's local storage; this never contains your password or accounting data.
6. How we share information
We do not sell your personal data. We share it only with the service providers that help us run OneBooks, and only as needed:
- Stripe — payment processing and subscription billing.
- Email delivery — a transactional email provider sends account and service emails such as verification and password-reset links.
- Cloud hosting & database — infrastructure providers host the application and store your data.
- Tax authorities — where the law requires e-invoicing, OneBooks transmits invoice data on your behalf. In Saudi Arabia, e-invoices (including buyer and seller details and line items) are submitted to ZATCA's FATOORA platform for clearance or reporting. In India, GSTR data is prepared for you to file — OneBooks does not transmit it to the GST portal automatically.
- Applications you connect — if you link a POS or partner app (such as LithosPOS) over OAuth, sales data flows between that app and OneBooks at your direction.
- Legal & safety — we may disclose information when required by law, or to protect our rights, our users or the public.
7. AI assistant and connected AI agents
OneBooks includes an optional AI assistant and an MCP interface that lets AI applications you explicitly authorize (such as Claude or ChatGPT) read your business data and prepare documents. When you use these features:
- What is shared — the accounting records needed to answer the request: report figures, invoices, purchases, expenses, customer and supplier names and contact details, item names and amounts.
- AI processing — for the built-in assistant, your request and the relevant records are sent to our AI providers under API terms that prohibit using your data to train their models. Your data is never shared between businesses.
- Connected agents — when you connect an external AI application through our MCP interface, that application receives the data its authorized requests return and handles it under its own privacy policy. You approve each connection explicitly and can revoke it at any time from Settings → Integrations.
- You stay in control — AI can only propose new documents; nothing is posted to your books without your explicit confirmation, and AI has no ability to delete or modify your records.
- Minimized responses — connector responses exclude internal system identifiers and cryptographic signing artefacts.
8. International transfers
OneBooks serves customers across many countries, so your data may be processed in a country other than your own. Where we transfer data internationally, we take steps to ensure it remains protected to the standard described in this policy.
9. Data retention
We keep your account and accounting data for as long as your account is active. Accounting records are typically subject to statutory retention periods (often several years), and both you and we may be legally required to keep them even after your account is closed. When data is no longer required, we delete or anonymize it.
10. How we protect your data
Security measures we apply include:
- Passwords hashed with bcrypt; email-verification and password-reset tokens stored only as hashes.
- Encryption in transit over HTTPS.
- Strict tenant isolation — each business's data is scoped to its own workspace.
- Rate-limiting and abuse protection on authentication endpoints.
- Encrypted storage of signing-key material used for Saudi Arabia e-invoicing.
11. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing.
- Access & portability — download everything we hold about you as JSON from your account, and export your customers, suppliers, items and transactions to Excel (XLSX) at any time from within OneBooks.
- Correction — edit your account and business details directly in the app.
- Deletion — erase your personal data from your account at any time. Accounting records are kept for the period tax law requires, with your name and contact details removed so they no longer identify you. You can also erase a customer or supplier from your own books the same way.
- Complaint — if you think we have handled your data wrongly you may complain to your local data protection supervisory authority, wherever you live or work in the EU or UK.
12. Children
OneBooks is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the date above; we will notify you of significant changes in-app or by email.
14. Contact us
Questions or requests about your privacy? Write to [email protected] or [email protected].