Privacy Policy

Last updated: 1 May 2026

This Privacy Policy explains how One Right Solution ("we", "us", "our"), collects, uses, stores, and protects information when you use our website and SaaS application available at onerightsolution.com (the "Service"). By creating an account or using the Service, you agree to this Policy.

1. Information we collect

Account information

When you register, we collect your name, email address, mobile number, business name, and GSTIN (optional). If you sign in via Google, we receive your email and basic profile from Google.

Business data you upload

The Service lets you store information about your leads, clients, projects, invoices, expenses, and team members. This data belongs to you; we process it on your behalf to provide the Service.

Payment information

Subscription payments are processed by Razorpay. We receive a payment confirmation, order ID, and limited metadata. We do not store your full card number, CVV, or bank credentials.

Usage and device information

We log IP address, browser type, device type, pages visited, and timestamps to secure the Service, diagnose issues, and improve performance.

Cookies

We use strictly-necessary cookies for authentication and session management, and a small number of preference cookies (e.g., theme). We do not use advertising cookies.

Social platform connections

If you connect a Meta (Facebook / Instagram), LinkedIn, or YouTube account to the Service, we receive and store the data described in Section 9 below — including OAuth access and refresh tokens, the identifiers of the Pages, Instagram Business accounts, LinkedIn organisations, or YouTube channels you authorise, and metadata about posts you create or schedule through the Service. Tokens are encrypted at rest using AES-256-GCM. We never receive or store your Facebook, Instagram, LinkedIn, Google, or YouTube password.

2. How we use your information

  • To provide, maintain, and improve the Service.
  • To authenticate you and secure your account (including 2FA where enabled).
  • To process subscription payments and send billing receipts via Razorpay.
  • To send service-related emails — account notifications, billing alerts, security notices, and follow-up reminders you configure.
  • To respond to support requests.
  • To publish, schedule, or fetch metadata for content on the social platforms you have connected to your workspace, only at your explicit instruction. See Section 9 for the full social-platforms disclosure.
  • To comply with Indian legal obligations, including GST and income tax requirements.

3. Sharing and disclosure

We do not sell your personal information. We share it only in these limited cases:

  • Service providers acting on our instructions — hosting (India-based cloud), email delivery, Razorpay for payments, and optional integrations you enable (Google, WhatsApp, Telegram).
  • Social platforms you connect — when you authorise a Meta (Facebook / Instagram), LinkedIn, or YouTube / Google account, we exchange the content you ask us to publish (text, images, video) and the associated metadata with the relevant platform's official APIs (Meta Graph API, LinkedIn Marketing API, YouTube Data API) on your behalf. We never share your data with these platforms for advertising purposes, and we only call them to fulfil actions you initiate inside the Service.
  • Legal compliance — where disclosure is required by an Indian court or government authority acting under valid jurisdiction.
  • Business transfer — in the unlikely event of a merger or acquisition, with prior written notice to you.

4. Data storage and security

Data is stored on servers hosted in India. We use TLS for all data in transit, encrypted backups, role-based access controls within our team, and industry-standard security practices. No system is perfectly secure — if we become aware of a breach affecting your data, we will notify you promptly.

5. Data retention

While your account is active, we retain your data for as long as you use the Service. If you cancel or delete your account, we retain your data for 30 days to allow recovery, after which it is permanently deleted from active systems. Encrypted backups may persist for a limited additional period before being rotated out.

We may retain certain records (invoices, tax documents, audit logs) for up to 8 years as required by Indian tax law.

6. Your rights

You have the right to:

  • Access and export your data at any time from your workspace.
  • Correct inaccurate information in your account.
  • Delete your account and associated data (subject to legal retention rules above).
  • Withdraw consent for optional communications.

To exercise any of these rights, email us at info@onerightsolution.com. We respond within 1–2 business days.

7. Children

The Service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect data from minors.

8. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email or a banner in the app at least 7 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

9. Social platform integrations (Meta, LinkedIn, YouTube)

The Service includes an optional "Social Automation" module that lets you connect third-party social media accounts and schedule, generate, or publish content from inside the Service. This section describes that module specifically and is provided to comply with the Meta Platform Terms, the LinkedIn API Terms of Use, and the YouTube API Services Terms of Service. By connecting an account you also agree to the Google Privacy Policy.

9.1 Meta (Facebook & Instagram)

When you choose to connect a Facebook or Instagram account, the Service redirects you to Facebook to grant our application permission to act on your behalf. We request the following Meta permissions:

  • public_profile — your public Facebook name, profile picture, and Facebook user ID, used to identify you in your workspace.
  • pages_show_list — the list of Facebook Pages you administer, so you can pick which Page to publish to.
  • pages_read_engagement — basic Page metadata (Page name, category, picture) for the Pages you select, used for display and to verify the connection is healthy.
  • pages_manage_posts — to create, edit, or delete Page posts only when you explicitly schedule or publish them through the Service.
  • instagram_basic — to read the Instagram Business or Creator account linked to your selected Facebook Page (account ID, username, profile picture).
  • instagram_content_publish — to publish image, video, carousel, or Reels posts to your Instagram Business or Creator account, only when you initiate the action inside the Service.
  • business_management — to access Pages and Instagram accounts that are owned by a Meta Business Portfolio you manage.

We store the resulting OAuth access token, the long-lived refresh token where Meta provides one, the Page ID, the Instagram Business Account ID, the display name, and the profile picture URL. Tokens are encrypted at rest using AES-256-GCM. We do not store your Facebook password, your Facebook friends list, your private messages, your DMs, your ads-account financial data, or any data that requires a permission not listed above.

We use Meta data exclusively to: (a) display the connected accounts inside your workspace, (b) publish or schedule content you author or generate inside the Service, (c) fetch the metadata of posts you published through the Service so you can review status (succeeded, failed, pending). We do not use Meta data to build advertising audiences, train AI models, sell to third parties, or for any purpose unrelated to the action you initiated.

9.2 LinkedIn

When you connect a LinkedIn account, we request ther_liteprofile, r_emailaddress, w_member_social, and w_organization_social scopes (or their successors as LinkedIn evolves the API). We use these to read your basic profile, list the LinkedIn organisations you administer, and post on your behalf only when you initiate the action.

9.3 YouTube / Google

When you connect a YouTube channel, the Service uses the YouTube Data API v3 under the Google OAuth flow with theyoutube.upload and youtube.readonly scopes. We use these to upload videos you have authored or generated inside the Service, and to read video metadata for status reporting. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9.4 Token storage and security

All third-party access tokens, refresh tokens, and webhook secrets are encrypted at rest with AES-256-GCM using a key held only on our servers and never exposed via any API endpoint. Tokens are transmitted only over TLS. Only systems components that need to publish content can decrypt them; staff cannot read them.

9.5 Disconnecting and revoking access

You can disconnect any social account at any time from Social → [client] → Settings inside the Service. Disconnection immediately deletes the stored access and refresh tokens, removes the connection from your workspace, and prevents any further publishing on that account. You can additionally revoke access from the platform's own settings:

9.6 Data deletion

To delete all data we hold from a Meta, LinkedIn, or YouTube connection, either disconnect the account inside the Service (which deletes it immediately) or email info@onerightsolution.com with the subject "Social data deletion request" and the email address of your workspace. We respond within 1–2 business days and complete the deletion within 30 days. The data deletion callback URL we provide to Meta points at this same workflow.

10. Contact

Questions or concerns about this Policy? Reach us at:

One Right Solution
Near Kehrian Chowk Jawali, Dist. Kangra, Himachal Pradesh 176023, India
Email: info@onerightsolution.com