Your data, handled with care.
Privacy isn't an afterthought at WoneSuite — it's built into how the platform is designed, isolated, and operated. Here's exactly how we collect, use, protect, and retain information across your whole business.
At a glance
The short version — before the fine print
We never sell your data
WoneSuite does not sell or rent personal information — not your business's data, and not your customers'.
Cookieless by design
Our built-in website analytics are first-party and privacy-first: no third-party ad trackers, no cross-site profiling, anonymized visitor IDs.
Isolated & encrypted
Every tenant's data is isolated at the database level (row-level security), encrypted in transit, with hashed credentials, strict access controls and MFA.
You stay in control
Access, correct, export, or delete your data and withdraw consent. For data you process on WoneSuite, you remain the controller.
This summary is for convenience only and does not replace the full text below.
Introduction
WoneSuite is an all-in-one business operating system. In one workspace, businesses run their customers, sales, commerce, finance, people, projects, support, website, and marketing — replacing the five-to-ten disconnected tools they would otherwise stitch together.
Because our platform can process a wide range of business, financial, employee, and customer information on behalf of the organizations that use it, privacy is not an administrative checkbox for us. It is a design constraint: it shapes how the platform is architected, operated, monitored, and governed.
This Privacy Policy explains how we collect, use, disclose, store, protect, and retain information when you visit our website, sign up, use the platform and its modules, connect integrations, or contact us. It is written with reference to major privacy frameworks — the EU/UK GDPR, Canada's PIPEDA, and the California CCPA/CPRA — and applied according to your jurisdiction.
Who We Are & Scope
"WoneSuite", "we", "us", and "our" refer to the entity that operates the WoneSuite platform and the wonesuite.com website. This policy applies to information handled through:
- The WoneSuite marketing website
- Account signup & authentication
- The WoneSuite workspace and its business modules
- Tenant websites built with our CMS & website builder
- Custom domains connected to a workspace
- First-party website analytics
- Public capability links (invoices, quotes, portals)
- Forms, demo requests & lead capture
- Email we send on your behalf
- APIs & integrations
- Support & sales communications
It applies to the people we interact with, including:
- Business customers (tenants)
- Workspace owners, admins & team members
- Website visitors & prospects
- A tenant's own end-customers who interact via public links or portals
- Job applicants who apply through a tenant's careers page
- Partners & authorized users
Our Role: Controller vs. Processor
The same platform serves two very different data relationships, and our obligations depend on which one applies:
3.1 When we are the Controller
For information we determine the purpose and means of — website analytics, account registration and security, sales and marketing inquiries, billing, and service communications — WoneSuite acts as the data controller.
3.2 When we are the Processor / Service Provider
For the business data you put into your workspace — your CRM contacts, leads, deals, orders, invoices, employee records, tickets, documents, and the content of your website — you are the controller and WoneSuite is a processor acting on your instructions. You decide what to collect, why, and for how long; we provide the secure infrastructure to do it.
If you are an employee, customer, applicant, or contact of a business that uses WoneSuite, that business — not WoneSuite — controls your data. Please direct access or deletion requests to them; we will support them in responding.
Information We Collect
The categories below reflect the full breadth of the platform. Most tenants use only a subset of modules, so not all of this applies to every account.
4.1 Account & Identity
- Name
- Work email
- Password (hashed with Argon2 — never stored in plaintext)
- Workspace/organization name
- Role & permissions
- Two-factor authentication secrets
- Session & device metadata
- Audit-trail records
4.2 Business Contact & Billing
- Company name
- Business address
- Phone number
- Job title
- Industry & company size
- Subscription & module entitlements
- Plan & billing status
- Communication preferences
4.3 Tenant-Submitted Business Data (you are the controller)
- CRM contacts, leads & companies
- Deals & pipeline
- Orders, quotes & catalog
- Invoices, payments & ledger entries
- Employee & HR records
- Payroll & time-off data
- Support tickets & messages
- Projects, tasks & documents
- Custom fields & activities
4.4 Website & CMS Content
- Pages, layouts & design tokens
- Media & uploaded files
- Forms & form submissions
- SEO metadata & content
- Custom domain configuration
- Published articles & product pages
4.5 Website Analytics (first-party, cookieless)
- Anonymized daily visitor identifier (a rotating one-way hash)
- Page paths & referrers
- Approximate country (derived on-server)
- Device & browser type
- Engagement time & scroll depth
- Core Web Vitals performance samples
- Bot / automated-traffic signals
4.6 Public Link & Portal Activity
- Invoice, quote & document views
- E-signature acceptance events
- Support-portal replies
- Email open & click events (where you enable tracking)
- IP address & user-agent tied to a capability token
4.7 Communications & Support
- Emails & support requests
- Demo & contact-form submissions
- Onboarding & implementation notes
- Feedback & survey responses
Sensitive Information
Some modules can hold information that certain laws treat as sensitive — for example employee identifiers in HR/payroll, or financial account references in invoicing. Where this exists, it is almost always tenant-submitted business data for which the tenant is the controller.
We only process sensitive information where it is necessary to provide the service you configured, or where you (or your administrator) have instructed us to. We do not mine it for advertising and we never sell it.
How We Collect Information
We collect information:
- Directly from you when you sign up, configure, or contact us
- From your workspace administrator
- Through your use of the platform
- Through content and files you upload
- Through first-party analytics on our website
- Through integrations you connect
- Through public links your customers open
- From public forms and lead-capture
- From publicly available business sources where needed for verification
How We Use Information
8.1 Provide the Platform
- Create & secure your account
- Run the modules you enable
- Store and process your business data
- Render and host your website
- Deliver invoices, quotes & portals
- Send email on your behalf
- Generate reports & insights
8.2 Secure & Protect
- Authenticate users & enforce MFA
- Isolate tenants at the database level
- Detect fraud, abuse & bots
- Maintain audit trails
- Monitor availability & performance
- Investigate incidents
8.3 Improve & Support
- Diagnose and fix errors
- Improve features & usability
- Provide onboarding & support
- Measure our own website's performance
8.4 Communicate
We use contact information to respond to inquiries, send account and security notices, share product updates, and — where permitted — send marketing you can opt out of at any time.
Legal Bases for Processing
Where the GDPR or similar law applies, we rely on one or more of these bases:
- Performance of a contract
- Consent
- Legal obligation
- Legitimate interests (security, service improvement, and running our business)
- Protection of vital interests where relevant
For tenant-submitted data we process as a processor, the tenant (as controller) is responsible for establishing the legal basis for that processing.
Sub-processors & Infrastructure
WoneSuite runs on a deliberately sovereign, consolidated stack to minimize third-party data exposure. We self-host our database, application, website analytics, email delivery, and geo-lookup rather than outsourcing them.
Where we do rely on a sub-processor (for example cloud hosting or infrastructure), we engage them under contractual data-protection terms and use only what is needed to run the service. A current list is available on request and, where required, via our Sub-processors page.
International Data Transfers
We may process or store information in a country other than yours. Where personal data is transferred internationally, we apply appropriate safeguards, which may include standard contractual clauses, data-processing agreements, access controls, and encryption.
Data Security
We apply administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, loss, or destruction. These include:
- Database-level tenant isolation (row-level security, enforced & tested)
- Encryption in transit
- Argon2 password hashing
- Multi-factor authentication
- Role-based access control
- Least-privilege database roles
- Audit logging
- Bot & abuse defenses
- Continuous security monitoring (independent security oversight)
- Incident response procedures
No system can guarantee absolute security, but we continuously work to strengthen our controls and require security sign-off before changes go live.
Data Retention
We retain personal information only as long as necessary to provide the service, meet our contractual and legal obligations, resolve disputes, and enforce our agreements.
Retention varies by data type and your configuration. Raw website-analytics events are pruned on a rolling retention window you can configure; aggregated, non-identifying statistics may be kept longer. When you delete your workspace, we delete or anonymize your data within a commercially reasonable period, subject to legal holds and backup cycles.
AI-Assisted Features
Some modules offer optional AI-assisted help — for example summarizing a note or drafting a reply. By default these run with an in-product, on-platform assistant; your business data is not sent to an external AI provider unless you explicitly enable and configure one.
Where automated assistance is used, it supports — it does not replace — human judgment for decisions that materially affect people or finances.
Your Privacy Rights
Depending on your jurisdiction, you may have rights to:
- Access your information
- Correct inaccuracies
- Delete your data
- Restrict or object to processing
- Withdraw consent
- Data portability
- Opt out of marketing
- Opt out of "sale" or "sharing" (we do neither)
- Lodge a complaint with a regulator
California residents have rights under the CCPA/CPRA; EU/UK residents under the GDPR; Canadians under PIPEDA. We honor verified requests as those laws require.
How to Exercise Your Rights
Contact us at privacy@wonesuite.com. We may need to verify your identity before acting on a request.
If your data is held in a workspace controlled by a business that uses WoneSuite, we will refer your request to that business, who is the controller, and support them in responding.
Tenant Responsibilities
If you use WoneSuite to process other people's data, you are the controller for that data. You are responsible for having a lawful basis, providing your own privacy notice, honoring your customers' and employees' rights, and configuring access appropriately.
We provide the tools — isolation, access controls, audit logs, export, and deletion — to help you meet those obligations.
Your Customers' & Employees' Data
When a tenant's end-customer opens an invoice or quote link, replies on a support portal, or applies to a careers page, WoneSuite processes that interaction on the tenant's behalf.
Questions about that data should go to the business you interacted with. WoneSuite will assist that business in responding to you.
Third-Party Integrations
You may connect optional integrations — for example a search console, an advertising pixel, or a payment method. These are controlled by you and governed by the third party's own terms and privacy policy.
- Search-console connections
- Advertising pixels & conversion APIs
- Payment methods
- Custom-domain DNS providers
Children's Privacy
WoneSuite is built for businesses and professional users and is not directed to children. We do not knowingly collect personal information from children, except where a business submits limited employment-related information under a lawful basis.
Breach Response
If we become aware of a security incident affecting personal information, we will contain the risk, investigate, and notify affected parties and regulators where required by law or contract.
For tenant-submitted data, we will notify the affected tenant (as controller) so they can meet their own notification obligations.
Accountability & Governance
We maintain privacy and security governance appropriate to the sensitivity of the data we handle:
- Documented policies & procedures
- Data minimization
- Access reviews
- Vendor due diligence
- Immutable audit trails
- Independent security oversight & pre-release sign-off
- Incident-response planning
Marketing Communications
You can unsubscribe from marketing email at any time via the unsubscribe link or by contacting us.
Even after opting out of marketing, you may still receive transactional, security, billing, and service messages.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology, or legal obligations. When changes are material, we will notify you through the website, the platform, or email, and update the "Effective" date above.
Contact Us
For privacy questions, requests, or complaints, contact us at privacy@wonesuite.com. We take every concern seriously and aim to respond promptly.
WoneSuite Privacy
Questions, requests, or complaints about how we handle data? Reach our privacy team directly.
One workspace. Total confidence.
Protecting the information you and your customers entrust to WoneSuite is central to the promise of running your whole business in one place.

