OneSender Privacy Policy
At OneSender (operated by ViDLabs), user privacy and data security are our highest priorities. We never sell, rent, or monetize your Google account data or WhatsApp customer contacts to advertisers, data brokers, or third parties. Our use of Google user data strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements.
11. Introduction & Scope of Application
This Privacy Policy governs the OneSender platform (“Application”, “Service”, or “we”), developed, owned, and operated by ViDLabs (“Company”, “we”, or “our”). This policy applies to all users accessing our public website at https://onesender.in, our customer web application at https://app.onesender.in (and https://dashboard-onesender.web.app), and our backend edge APIs at https://api.onesender.in.
OneSender is an enterprise WhatsApp Cloud API gateway and messaging automation platform that allows organizations and businesses to broadcast authorized WhatsApp campaigns, synchronize customer contacts, and monitor real-time message delivery.
22. Information We Collect
OneSender only collects data that is strictly necessary to deliver user authentication, account management, and authorized WhatsApp messaging automation:
When you choose to authenticate via "Sign in with Google", we request access strictly to standard, minimal OAuth 2.0 identity scopes:
- Primary Email Address (
userinfo.email): Used as your primary account identifier, for authentication, and for operational service notifications. - Basic Profile Information (
userinfo.profile): Your full name and profile avatar, used to personalize your OneSender workspace console. - Google User ID (
openid): A unique, cryptographic identifier managed by Firebase Authentication to persist your secure session across devices.
🔒 We NEVER request, access, or store your Google account password, Google Drive files, personal contacts, or private emails.
To execute campaigns, you provide or auto-connect your WhatsApp Business Account ID (WABA ID), Phone Number ID, App ID, and System User Access Tokens. These credentials are encrypted at rest with AES-256 in Google Cloud Firestore.
Customer phone numbers, recipient names, and custom attributes imported via CSV, along with real-time delivery timestamps (Sent, Delivered, Read, Failed) provided by Meta webhooks.
Google API Services User Data Policy & Limited Use Disclosure
In strict compliance with Google’s Limited Use standards, OneSender pledges and implements the following technical and operational guardrails:
OneSender does NOT use or transfer Google user data to serve advertisements, including personalized, retargeted, or interest-based advertising under any circumstances.
We do NOT sell, license, rent, or trade Google user data to data brokers, ad networks, analytics firms, or any other commercial third parties.
Google user data is NEVER used to train, retrain, or fine-tune non-personalized generalized artificial intelligence or machine learning models.
No human at ViDLabs is allowed to read user data unless: (1) we have obtained the user’s explicit affirmative consent for a specific support request, (2) it is necessary for security/bug investigation, (3) required by law, or (4) for internal system ops where data is aggregated and anonymized.
44. How We Use Collected Information
We use the collected information solely for the following explicit business purposes:
- Authentication & Account Management: Authenticating your identity via Google OAuth 2.0 and securing access to your workspace.
- WhatsApp Campaign Dispatching: Routing authorized broadcast templates through Meta WhatsApp Cloud API to your imported recipient lists.
- Delivery Auditing & Telemetry: Recording real-time Sent, Delivered, Read, and Failed message events for audit trails and analytics.
- Administrative Communication: Transmitting critical security advisories, billing invoices, and service health notifications.
55. Data Security, Storage & Infrastructure
We enforce enterprise-grade security protocols to protect your personal information:
🔒 Transport & Storage Encryption
All data in transit is encrypted using modern TLS 1.3 / HTTPS. All stored database records are encrypted at rest with AES-256 on Google Cloud Firestore.
🛡️ Cloudflare Anycast Edge Shield
All traffic passes through Cloudflare Enterprise DDoS shielding, Web Application Firewall (WAF), and strict HSTS headers with preload protection.
66. Data Retention, Deletion & Google Access Revocation
Users maintain sovereign control over their data at all times. You have the right to inspect, export, or permanently delete your records:
6.1 How to Request Permanent Account and Data Deletion
You may request permanent deletion of your OneSender account, contacts, and logs at any time by emailing our privacy team at vividapps.studio@gmail.com. Upon receiving your request, all personal data, contact directories, and workspace credentials will be irreversibly purged within 48 business hours.
6.2 How to Revoke OneSender Access to Your Google Account
You can disconnect and revoke OneSender’s access to your Google Account at any time via your official Google Account Security Settings:
77. Authorized Third-Party Subprocessors
OneSender exclusively relies on certified enterprise infrastructure partners to deliver platform uptime and messaging:
- Google Cloud Platform & Firebase: Identity management, OAuth authentication, and encrypted database storage.
- Meta Platforms, Inc. (WhatsApp Cloud API): Message routing, template submission, and recipient delivery webhooks.
- Cloudflare, Inc.: Global edge network, DNS routing, DDoS mitigation, and SSL/TLS termination.
88. Developer & Privacy Governance Contact
If you have any questions, inquiries, or feedback regarding this Privacy Policy, Google OAuth compliance, or data protection practices, please contact: