Privacy policy
Effective Date: August 2026
At OneDeck Ltd. (“OneDeck”, “we”, “us”, or “our”), we are committed to protecting privacy, safeguarding personal data, and complying with applicable data protection laws, including the Israeli Protection of Privacy Law, 1981, its amendments (including Amendment No. 13), and related regulations.
This Privacy Policy explains how we collect, use, store, secure, and disclose personal information when you interact with our website, platform, and mobile applications.
1. Scope of This Policy
This Privacy Policy applies to:
• Public Website: https://www.onedeck.com
• OneDeck Platform: Web-based platform and mobile applications (iOS and Android), operating on shared infrastructure.
This policy applies to users, customers, prospects, and visitors, as applicable.
2. Information We Collect
Account and Contact Information
• Name, email address, phone number (where provided);
• Company name, address, and registration number (where applicable);
• Encrypted password (for standard sign-up);
• No password is stored when using Google Sign-In.
Payment and Billing Information
Payments are processed by Chargebee.
OneDeck does not store credit card details.
Usage and Technical Information
• IP address;
• Device and browser information;
• Logs, timestamps, and system activity records.
Cookies and Similar Technologies
Described in detail in Section 16 below.
3. Database Ownership, Roles and Legal Responsibility
Controller and Processor Roles
For the purposes of the Israeli Protection of Privacy Law and, where applicable, the GDPR:
• Customers are the Data Controllers of all personal data and content uploaded or processed within their OneDeck accounts (“Customer Content”).
• OneDeck Ltd. acts as a Data Processor with respect to Customer Content and processes such data only on documented customer instructions, solely to provide the services, ensure security, and comply with legal obligations.
OneDeck does not determine the purposes or means of processing Customer Content and does not claim ownership of such data.
OneDeck-Owned Databases
OneDeck is the Data Controller with respect to its own business databases, including:
• Customer and prospect contact details;
• Contractual, billing, and support information;
• Operational, administrative, and compliance records.
Database Registration
As of the effective date of this policy, OneDeck’s databases are not registered with the Israeli Registrar of Databases.
If registration becomes legally required, OneDeck will comply accordingly.
4. Customer Content
Customers retain full ownership and responsibility for Customer Content.
OneDeck accesses Customer Content only:
• To provide and maintain the services;
• Upon customer authorization;
• Where required by law.
Customers are solely responsible for ensuring lawful collection, processing, disclosure, and use of Customer Content.
5. Purposes of Processing
Personal data is processed for the following purposes:
• Providing, operating, and improving the platform’s user-facing functionality. Google user data accessed through the Gmail integration is used only to provide user-configured Gmail automations, including receiving emails as automation triggers and sending emails through a connected Gmail account.
• Account management and customer support;
• Security, fraud prevention, abuse prevention, and incident detection;
• Service communications and system notifications;
• Legal compliance and enforcement of agreements.
6. Legal Bases for Processing
Processing is based on one or more of the following legal grounds:
• Contractual necessity
• Legitimate interests (security, stability, service improvement)
• Consent (analytics, marketing, cookies, where required)
• Legal obligations
7. Disclosure of Information
OneDeck does not sell personal data.
Information may be shared with trusted service providers, including:
• Cloud infrastructure providers (Google Cloud, AWS);
• Payment processors (Chargebee);
• Analytics, marketing, and support tools (Google, Meta, FirstPromoter, Intercom).
Google user data obtained through the Gmail integration is not used or disclosed for analytics, marketing, advertising, attribution, profiling, or any purpose unrelated to providing or improving OneDeck’s user-facing functionality. It is not sold and is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models.
All providers are bound by contractual obligations to protect personal data and process it solely for authorized purposes.
8. Google API Services and Limited Use
OneDeck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy.
In particular:
Google user data (including Gmail and Google Calendar data) is used only to provide user-facing features that the user has explicitly enabled, and is never sold, never used for advertising purposes, and never used to create, train, or improve machine learning or artificial intelligence models.
Where our AI assistant features process Google Calendar data at the user's explicit direction, that data is sent to our AI service providers solely to generate the requested response, and is not used by us or by those providers to train their models.
Humans do not read Google user data except with the user's explicit permission, where necessary for security purposes, to comply with applicable law, or for internal operations on data that has been aggregated and anonymized.
9. International Data Transfers
Personal data may be stored or processed in Israel, the United States, and other jurisdictions where service providers operate.
Transfers are conducted in accordance with applicable law and subject to appropriate safeguards.
10. Information Security Measures
In accordance with the Israeli Protection of Privacy Regulations (Information Security), 2017, OneDeck implements reasonable and proportionate technical and organizational safeguards, including:
• Personal user accounts for employees (no shared credentials);
• Role-based access controls and least-privilege access;
• System-level logging and monitoring;
• Automated daily backups;
• Separation of application production environments from development and testing;
• Secure cloud infrastructure;
• No human access to customer data by external providers.
While reasonable measures are implemented, no system is completely secure, and OneDeck cannot guarantee absolute protection against unauthorized access, misuse, or loss.
11. Incident Response and Data Breach Notification
OneDeck maintains internal procedures for handling personal data security incidents.
In the event of a personal data breach, OneDeck will:
• Investigate and contain the incident;
• Assess potential risks to individuals;
• Notify affected users and relevant supervisory authorities where required by applicable law;
• Provide information reasonably necessary to mitigate potential harm.
12. Data Retention
Personal data is retained only for as long as reasonably necessary for:
• Service provision and account continuity;
• Legal, tax, and accounting compliance;
• Security investigations and dispute resolution.
Accounts are not automatically deleted upon cancellation.
Deleted data may remain in encrypted backups for a limited period and will be removed according to backup retention cycles.
13. Data Subject Rights
Subject to applicable law, individuals may exercise rights to:
• Access personal data;
• Correct or update inaccurate data;
• Request deletion;
• Restrict or object to processing;
• Withdraw consent.
Requests should be sent to [email protected].
OneDeck will make reasonable efforts to respond to verified requests within 30 days.
Where permitted by law, this period may be extended due to the complexity or volume of the request.
Requests relating to Customer Content must be addressed to the relevant customer as Data Controller.
14. Accountability and Governance (Amendment 13 Alignment)
OneDeck maintains internal policies and procedures designed to ensure compliance with applicable data protection laws, including access controls, security monitoring, incident documentation, and corrective actions where required.
15. Information Security and Privacy Responsibility
OneDeck has appointed an internal role responsible for information security and privacy compliance.
The designated person is:
Koren Tarshish, CEO of OneDeck Ltd.
This role includes oversight of data protection practices, information security measures, handling of data subject requests, and coordination of incident response and regulatory communications where required by applicable law.
16. Cookies and Tracking Technologies
OneDeck uses cookies and similar technologies.
Strictly Necessary Cookies
Required for authentication, session management, and security (including Google reCAPTCHA).
Functional and Preference Cookies
Store user preferences.
Analytics Cookies
Used for analytics (e.g., Google Analytics) and activated only after user consent, where required.
Marketing and Attribution Cookies
Used for marketing measurement (e.g., Meta, FirstPromoter) and activated only after user consent, where required.
Traffic Source Attribution
We may store traffic source attribution parameters, such as campaign source identifiers (e.g. UTM parameters or referral source classifications), for internal analytics, marketing attribution, and service improvement purposes.
Users may manage cookie preferences via browser settings or available consent tools.
Traffic source attribution does not use Google user data obtained through the Gmail integration.
17. Children’s Privacy
OneDeck services are intended for users aged 18 and older.
We do not knowingly collect personal data from children.
18. Updates to This Policy
This Privacy Policy may be updated periodically.
Updates will be posted with a revised effective date. Continued use of the services constitutes acceptance of the updated policy.
19. Contact Information
OneDeck Ltd.
Kibbutz Yifat, 3658300, Israel
📧 [email protected]



