Privacy Policy
Effective September 24, 2026
This policy explains what information OnePane collects, why, and your choices. OnePane is operated by 2395145 Ontario Inc., doing business as SMW Digital, based in Ontario, Canada ("we", "us"). We keep it simple: no ads, no tracking, and we don't sell your information.
What we collect
| Information | Why |
|---|---|
| Account: email address and password (the password is stored in scrambled form; we can't see it) | To sign you in, send sign-up codes and password resets, and reply to you |
| Your settings and content: widget layout and settings, places you add (name, address text and map coordinates), notes, bookmarks, calendar subscription links and which Google calendars you picked, news sources and search shortcuts | To show your start page on any device |
| Subscription: trial dates, plan status and renewal date, plus Stripe customer and subscription IDs | To manage your trial and subscription |
| Support messages: what you send through the support form or Help, and your email if you ask for a reply | To answer you and improve OnePane |
| Technical data: IP address and basic request details, kept for a short time | To prevent spam and abuse, and to keep the service secure and working |
Payment details: card and payment information goes directly to Stripe. We never see or store your full card number.
Outlook mail and calendar: if you connect a Microsoft account, you sign in with Microsoft and allow OnePane to read your inbox and/or calendar. Microsoft gives us a sign-in token, which we store encrypted in our database so the connection works on all your computers without signing in again. When an Outlook widget loads, our server fetches your latest messages (sender, subject, time and an optional preview line) or your upcoming events and passes them straight to your browser. We don't store your email or calendar content, and access is read-only. You can disconnect at any time from the widget, which deletes the token, or remove OnePane from your Microsoft account's app permissions.
Google Calendar: if you connect a Google account, you sign in with Google and allow OnePane to read your calendar list and events. We only ask for read-only access, plus your email address so you can see which account is connected. Google gives us a sign-in token, which we store encrypted in our database so your calendars keep working without signing in again. When your Calendar widget loads, our server fetches the events for the days you chose and passes them straight to your browser. We don't store your events or calendar content, and we never change anything in your Google account. You can disconnect at any time from the Calendar widget's settings, or remove OnePane's access from your Google account's security page. Disconnecting deletes the token.
OnePane's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to show your calendar to you. We don't use it for advertising, don't sell it, don't use it to train AI models, and people at OnePane don't read it unless you ask us to for support, it's needed for security, or the law requires it.
Where your information is stored
Your account and data are stored with Amazon Web Services in Canada (Montreal region). Some service providers listed below may process information in other countries, including the United States. When that happens, it's protected by contract and the laws of those countries may apply.
Who we share it with
We only share what's needed to run OnePane:
- Amazon Web Services: hosting, database, sign-in and email delivery.
- Stripe: payments, billing and sales tax. Stripe may act as the reseller or merchant of record for your purchase, and handles payment data under its own privacy policy.
- Data sources your widgets use: weather providers receive the map coordinates of your places; our place-lookup provider receives the place names or addresses you look up; news, calendar and aviation sources receive requests for the feeds you add. These requests come from our servers or your browser and don't include your name or email.
- Microsoft: only if you connect an Outlook account, to read your inbox and calendar.
- Google: only if you connect a Google account, to read your calendars.
- When required by law: or to protect people, our users or OnePane.
We don't sell or rent your personal information, and we don't use it for advertising.
Cookies and browser storage
OnePane doesn't use advertising or tracking cookies. The app keeps your sign-in and a copy of your settings in your browser's local storage so it loads quickly. Stripe's checkout and billing pages use their own cookies for payment security.
How long we keep it
- Account data and content: for as long as you have an account, then deleted within 30 days of your request. Backups roll off within a further 35 days.
- Support messages: up to 2 years.
- Technical and anti-abuse data: usually a few hours, and no more than 30 days in server logs.
- Billing records: kept as long as tax and accounting laws require, usually 7 years.
Your rights
Depending on where you live, including under Canada's PIPEDA, Quebec's Law 25 and Europe's GDPR, you can ask to see, correct, download or delete your personal information, or object to how we use it. Most settings you can change yourself in the app. For anything else, contact us through the support form and we'll respond within 30 days. You can also complain to your privacy regulator, such as the Office of the Privacy Commissioner of Canada.
Security
We use encryption in transit and at rest, limited access to production systems, and trusted providers. No system is perfectly secure. If a breach affects you, we'll tell you and the authorities as the law requires.
Children
OnePane isn't meant for anyone under 16, and we don't knowingly collect their information. If you think a child has given us information, contact us and we'll delete it.
Changes
If we make significant changes to this policy, we'll tell you by email or in the app before they take effect. The date at the top shows when it was last updated.
Contact and privacy officer
Our privacy officer is responsible for this policy. Reach them through the support form (choose "Something else" and mention privacy).