Privacy Policy
Effective Date: August 3, 2026
At ONE CLICK DESIGN (PTY) LTD ("One Click Design," "we," "us," or "our"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our Point-of-Sale (POS) mobile applications, web storefronts, AI-powered chat assistants, and hosting services (collectively, the "Services").
This policy complies with the Protection of Personal Information Act (POPIA) and the Electronic Communications and Transactions Act (ECTA) of South Africa, as well as global data protection frameworks including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the developer policies of Google Play and the Apple App Store.
1. Roles and Data We Collect
Because our Services encompass POS terminals, AI assistants, and e-commerce storefronts, we collect different types of data depending on how you interact with us. Under POPIA and GDPR, we act as a Data Controller (Responsible Party) for our Merchants, and a Data Processor (Operator) for End-Consumers.
A. Merchant Data (You as our Customer)
- Account & Billing: Name, email address, biometric login data (stored locally on device), business details, and subscription billing info.
- Financial Setup & KYC: For our South African PayFac model, we collect KYC documentation. For our Global BYOK (Bring Your Own Key) model, we securely collect and encrypt your third-party payment API keys (e.g., Paystack).
- Knowledge Base Data: Proprietary documents, PDFs, SOPs, and FAQs you upload to train your custom AI Chat Assistant.
B. End-Consumer Data (Processed on your behalf)
- Transaction Data: Dynamic A2A payment logs, purchase history, and delivery details processed via the POS or Next.js storefronts.
- WhatsApp & CRM Data: Customer phone numbers collected for digital receipts and Meta WhatsApp Business API marketing blasts.
- AI Chat Logs: Conversation transcripts between consumers and the AI Chat Assistant, processed for natural language responses and sentiment analysis (human takeover triggers).
2. How We Use Your Information
- To Operate the POS & Storefronts: Enabling offline cash mode via local device caching (SQLite), real-time cloud syncing (Firebase), and automated Next.js storefront generation.
- To Process Payments Safely: Routing instant A2A bank payments and splitting transactions safely via Paystack subaccounts or encrypted BYOK routing.
- To Power AI Features (No Training Clause): We use Google Cloud Vertex AI to generate 60-second store setups and process chatbot inputs. We do NOT use Merchant data, uploaded Knowledge Base documents, or End-Consumer chat logs to train the base AI models. Data is strictly vectorized and siloed for your specific bot's Retrieval-Augmented Generation (RAG) engine.
- To Ensure Platform Safety: Utilizing sentiment engines and automated moderation to prevent the generation of harmful AI content and trigger human takeover alerts, in compliance with Google Play AI policies.
3. Legal Basis for Processing (POPIA & GDPR)
We process Personal Information based on the following legal grounds:
- Consent: Where required, you or your consumers have opted-in (e.g., agreeing to receive WhatsApp digital receipts and marketing).
- Contractual Necessity: To fulfill our Terms of Service (e.g., processing a POS transaction or hosting your webstore).
- Legitimate Interests: To improve our software, ensure security, and detect fraud.
4. How We Share Your Information (Sub-Processors)
We do not sell your personal information. We share data strictly with certified infrastructure partners to facilitate our Services:
- Payment Processors: Paystack (for A2A routing and PayFac KYC).
- Cloud Infrastructure: Google Cloud / Firebase (for real-time database, authentication, and secure secret vaults) and Vercel/Firebase App Hosting (for Next.js storefront deployment).
- AI & Messaging Integrations: Meta / WhatsApp Business API (for chat automation and digital receipts) and Google Vertex AI. Note: While standard WhatsApp is end-to-end encrypted, messages sent to our business bots are decrypted on our secure servers to enable AI processing and human takeover dashboards.
- Logistics APIs: Uber Direct and Bob Go (only when an end-consumer requests storefront delivery).
5. International Data Transfers
Our infrastructure spans multiple regions. Data may be transferred to and maintained on secure servers outside of your home country (e.g., Google Cloud servers in Europe or the US). By using our Services, you consent to this transfer. We enforce Standard Contractual Clauses (SCCs) and ensure all sub-processors comply with strict GDPR and POPIA data transfer standards.
6. Your Data Protection Rights & Account Deletion
To comply with global data laws, as well as strict Google Play and Apple App Store requirements, you possess the following rights:
- Right to Access & Portability: Request copies of your POS data and Z-Reports.
- Right to Rectification: Correct inaccurate information in your profile.
- Right to Erasure (Account Deletion): You may request the complete deletion of your account, API keys, AI knowledge bases, and related personal data.
How to Request Account & Data Deletion
Users can delete their account directly within the POS App by navigating to Settings > Account > Delete Account. Alternatively, you may submit a deletion request to our Information Officer using the email below. We will permanently wipe your data from our active Firebase databases within 30 days.
admin@oneclickenterprise.com7. AI Transparency & End-Consumer Disclosure
Our AI Chat Assistant generates automated responses. To comply with international AI regulations, Merchants using our WhatsApp integration are required to clearly disclose to their customers that they are interacting with an AI bot. One Click Design provides the tools to escalate complex queries to a human agent ("Human Takeover") at any time.
8. Data Security & Retention
We deploy industry-standard security, including TLS encryption in transit, strict Firestore Security Rules, role-based access control (Owner vs. Cashier claims), and Google Cloud Secret Manager for vaulting BYOK API keys. POS data operates locally offline via SQLite caches and syncs to the cloud only when connections are secure.
Retention: Financial and Z-Report data is retained as required by local tax and business laws. AI chat logs and sentiment analysis data are retained for a limited window (up to 90 days) to facilitate human takeover features, after which they are automatically anonymized or purged, unless the Merchant deletes them earlier via their dashboard.
9. Changes to This Privacy Policy
We may update our Privacy Policy to reflect changes in AI regulations, App Store developer guidelines, or platform architecture. We will notify you by updating the "Effective Date" at the top of this document, and for material changes, via an in-app POS notification.
10. Trademark Disclaimer
All third-party trademarks, logos, and brand names (including Paystack, Uber, Meta, and Google) are the property of their respective owners. Their use on this website and within our Services is strictly for integration identification purposes and does not imply an official partnership, sponsorship, or endorsement by these entities.
For inquiries regarding this Privacy Policy or your data rights, please contact our Information Officer at:
admin@oneclickenterprise.com