Privacy Policy
Our commitment to data privacy, tenant isolation, and zero tracking
Your data belongs to you. We believe that privacy is a fundamental right, and our philosophy is simple: we collect only what is strictly necessary to run 1ERP for your organization, and we never sell, rent, monetize, or track your data.
This Privacy Policy explains what information we collect, why we collect it, how your organization's records are protected and isolated, and your rights over your data.
1. What We Collect and Why
Our guiding principle is minimal collection. Specifically, we collect:
- Identity & Authentication: When you register or sign in using your account provider or credentials, we store your name, email address, avatar, and unique user identifier to establish your account identity and verify your workspace permissions.
- Organization ERP Data: All operational business data you create within 1ERP—including items, stock movements, bills of materials, purchase orders, sales transactions, customer contacts, supplier locations, and team assignments—are processed to provide you with active ERP workflows.
- Essential Session Cookies: We issue first-party authentication tokens and essential session cookies strictly to keep you securely signed in and preserve your active organization workspace context across tabs. We do not use third-party analytics cookies, advertising pixels, or cross-site tracking scripts.
- Operational Logs: When requests reach our backend servers, we maintain standard technical server logs (request timestamp, endpoint path, and HTTP status) for debugging system errors, mitigating brute-force attacks, and ensuring platform reliability.
2. Architecture & Tenant Isolation
1ERP is designed from the ground up with strict multi-tenant boundary isolation. Each organization operates within its own dedicated SQLite database file. Your transactional ledgers, financial figures, and inventory records are isolated at the database storage layer and protected by cryptographic session authorization checks.
3. Zero Data Selling & Third-Party Sharing
- We do not sell, rent, or lease your personal or business information to third parties, data brokers, or advertising networks.
- We do not display third-party advertisements within our application.
- We do not use your business documents or workflow records to train public artificial intelligence models without your explicit instruction.
4. Access & Disclosure Restrictions
Our team does not access your private workspace data except under the following strictly limited conditions:
- To Assist with Support: When you explicitly request customer assistance or technical support and grant permission to inspect a specific record or workflow execution.
- System Security & Integrity: When necessary to prevent or remediate an active security threat, denial-of-service attack, or severe database corruption.
- Legal Compliance: If compelled by lawful governmental court orders or statutory warrants, strictly adhering to due process of law.
5. Data Retention & Permanent Deletion
- Active Accounts: We retain your operational data for as long as your workspace account remains active.
- Account Deletion: If you delete your organization workspace, active access is revoked immediately. All underlying database files, user memberships, and audit trails are queued for permanent deletion and completely purged across our primary systems and rotating backup cycles.
6. Your Rights & Data Portability
You have complete control over your business data at all times. Within 1ERP, you have the right to:
- Access, view, and inspect all records and personal details associated with your profile and organization.
- Export your data at any time into structured JSON, tabular formats, or Typst vector PDF documents.
- Correct or update inaccurate information directly through the user settings and entity forms.
- Request full closure and irreversible deletion of your account and related organization database.
7. Security & Safeguards
We implement comprehensive technical and organizational safeguards to ensure data integrity and confidentiality, including transport encryption (HTTPS / TLS 1.3), write-ahead logging (WAL) with strict transactional safety, rotating session secret keys, and fine-grained role-based access control.
8. Policy Updates & Inquiries
We may update this Privacy Policy as our services develop and evolve. When significant changes are made, we will update the revision date at the top of this document and notify active organization administrators. If you have any questions or feedback regarding our privacy practices, our team is available to assist you.