Skip to content
Onegoin Onegoin
FeaturesPricingDemoContact
Log in Start Free Trial

Legal

Privacy Policy

Effective date: 16 July 2026 · Last updated: 16 July 2026

Plain-language summary

  • Onegoin collects account, billing, device, usage and support information needed to operate the service.
  • Your organisation controls the project files and business records uploaded to its workspace. Onegoin processes that content to provide the service.
  • Onegoin may use trusted cloud, payment, communication, analytics and AI service providers. We do not sell personal data.
  • Users may request access, correction, deletion, withdrawal of consent and grievance redressal, subject to applicable law and the organisation that controls the workspace.

The summary is provided for convenience only. The complete text below controls.

Contents

  • 1. Who we are and scope of this Policy
  • 2. Our role and your organisation’s role
  • 3. Personal data we collect
  • 4. How we collect personal data
  • 5. How we use personal data
  • 6. Legal grounds for processing
  • 7. Artificial intelligence and automated features
  • 8. How we disclose personal data
  • 9. Organisation administrators and shared workspaces
  • 10. International data transfers
  • 11. Cookies and similar technologies
  • 12. Data security
  • 13. Data retention and deletion
  • 14. Your rights and choices
  • 15. Account closure, exports and workspace deletion
  • 16. Children’s privacy
  • 17. Third-party services and links
  • 18. Business transfers
  • 19. Changes to this Policy
  • 20. Contact and grievance redressal

Privacy at Onegoin

Onegoin is a software-as-a-service platform designed for architecture firms, interior-design studios, consultants, contractors and related project teams. This Privacy Policy explains how Onegoin collects, uses, discloses, stores and protects personal data when people use our websites, application, client portals, support channels and related services.

This Privacy Policy should be read together with the Onegoin Terms of Use and any organisation-specific order form or Data Processing Addendum that applies to your use of the Services.

1. Who we are and scope of this Policy

This Privacy Policy applies to services provided under the “Onegoin” brand by Onegoin Private Limited, a company incorporated in India under the Companies Act, 2013. In this Policy, “Onegoin”, “we”, “us” and “our” refer to that legal entity.

This Policy applies when you:

  • visit onegoin.com or another Onegoin website that links to this Policy;
  • create or use an account at app.onegoin.com;
  • join an organisation workspace as an owner, administrator, employee, contractor, consultant, client or vendor;
  • use Onegoin project-management, document, financial, collaboration, client-portal or AI-assisted features;
  • contact sales, support, privacy or legal teams;
  • participate in a trial, demonstration, survey, webinar or product-research session; or
  • interact with a Onegoin email, notification, integration or related service.

This Policy does not govern websites, applications or services operated independently by third parties, even where Onegoin links to or integrates with them. Their own privacy notices apply to their processing.

2. Our role and your organisation’s role

2.1 Information Onegoin controls directly

Onegoin generally determines why and how personal data is processed for account registration, authentication, billing, product administration, security, support, service communications, website analytics, product improvement and Onegoin’s own business operations. For this processing, Onegoin acts as the data fiduciary, controller or equivalent responsible entity under applicable law.

2.2 Customer Content processed for an organisation

An organisation may upload or generate project records containing information about its employees, clients, consultants, contractors, vendors, site personnel and other individuals. The organisation usually decides why this information is collected, who may access it and how it is used. For this Customer Content, the organisation generally acts as the data fiduciary or controller and Onegoin acts as its data processor or service provider.

The organisation is responsible for providing required privacy notices, obtaining required permissions or consent, assigning appropriate access and ensuring that its use of personal data through Onegoin is lawful. Where you have a privacy request concerning data uploaded by an organisation, we may direct the request to that organisation or assist it in responding.

2.3 Definitions

“Personal data” means information relating to an identified or identifiable individual, or another equivalent definition under applicable privacy law. “Customer Content” means files, records, communications and other information submitted to or generated within an organisation workspace. “Services” means Onegoin’s websites, applications, software, portals, integrations, support and related offerings.

3. Personal data we collect

3.1 Account and profile information

  • name, profile photograph, email address and telephone number;
  • job title, professional role, company or studio name and business contact details;
  • account identifier, username, authentication-provider identifier and password hash;
  • language, time zone, notification and accessibility preferences; and
  • organisation membership, role, permissions and invitation status.

3.2 Organisation, client and project information

Depending on the features used, Customer Content may include:

  • project names, descriptions, addresses, timelines, milestones and status information;
  • client, consultant, contractor, vendor and team contact details;
  • drawings, plans, floor plans, photographs, videos, renders, presentations and specifications;
  • meeting notes, messages, comments, approvals, tasks, schedules and site updates;
  • proposals, budgets, estimates, bills of quantities, invoices, expenses and payment-tracking records;
  • material, furniture, fixture and equipment selections;
  • contracts, purchase orders, change orders and other business records;
  • files imported from devices, email, cloud drives or connected services; and
  • any personal data that an authorised user chooses to include in a file, note or communication.

3.3 Billing and transaction information

  • billing name, organisation name, billing address and country;
  • GSTIN, tax information or other invoicing details where provided;
  • subscription plan, seat count, billing cycle and renewal status;
  • payment status, transaction identifier, invoice number, amount, currency and payment date; and
  • limited payment-method information received from the payment processor, such as card brand and last digits, where available.

Payment-card, UPI, net-banking or other payment credentials are generally collected and processed directly by Razorpay or another authorised payment provider. Onegoin does not intentionally store complete card numbers, CVV values, UPI PINs or online-banking passwords.

3.4 Device, usage and log information

  • IP address, approximate location derived from IP address and internet-service information;
  • browser, device type, operating system, screen size and application version;
  • login dates, session identifiers, referring pages and pages or features viewed;
  • actions within the Services, including creation, editing, sharing, download and deletion events;
  • error reports, performance data, diagnostics, crash information and support logs;
  • security events, access logs, audit trails and suspected abuse information; and
  • cookie, local-storage and similar technology identifiers.

3.5 Communications and support information

  • emails, support tickets, chat messages and call notes;
  • feedback, survey responses, feature requests and product-research responses;
  • sales and demo enquiries; and
  • information you provide when reporting an error, privacy concern, security incident or legal issue.

3.6 AI Inputs and Outputs

When you use an AI-assisted, OCR, document-extraction or automated feature, we may process the text, files, images, prompts and instructions you submit (“AI Inputs”), together with the generated summary, extraction, suggestion, answer or other result (“AI Output”). AI Inputs and Outputs may contain personal data if you or your organisation include it.

3.7 Integrations and imported data

When an authorised user connects a third-party service, Onegoin may receive account identifiers, files, folders, calendar entries, contacts or other information permitted by the user and the integration. The information received depends on the permissions granted and the integration’s settings.

3.8 Information we do not require

Onegoin is not designed to store authentication secrets, full payment credentials, health records, biometric templates or government identity credentials. Do not upload Aadhaar numbers, passwords, CVV values, UPI PINs, medical records or other highly sensitive information unless Onegoin expressly supports the relevant use and your organisation has confirmed that the processing is lawful and necessary.

4. How we collect personal data

We collect personal data from the following sources:

  • directly from you when you register, subscribe, configure your profile, upload content or contact us;
  • from your organisation, workspace administrator or another user who invites you or enters your information;
  • automatically from your browser, device and activity when you use the Services;
  • from payment processors, authentication services, communication providers and connected integrations;
  • from publicly available business sources where used for legitimate B2B sales or verification purposes; and
  • from service providers that help us detect fraud, secure accounts, analyse performance or provide support.

Where another person provides your information to Onegoin, that person or organisation is responsible for having appropriate authority to do so and for providing any notice required by law.

5. How we use personal data

Onegoin may use personal data to:

  • create, authenticate, administer and secure accounts and organisation workspaces;
  • provide project-management, client-portal, document, collaboration, billing, reporting and other requested features;
  • store, organise, search, transmit, export and back up Customer Content;
  • process subscriptions, invoices, renewals, taxes, refunds and payment status;
  • provide customer support, onboarding, demonstrations and troubleshooting;
  • send security alerts, service notices, project invitations, billing notices and other operational communications;
  • enable integrations and carry out instructions from authorised users;
  • operate AI-assisted, OCR, extraction, search, recommendation and automation features;
  • monitor availability, diagnose errors, improve performance and understand feature usage;
  • protect users and Onegoin against fraud, abuse, malware, unauthorised access and security threats;
  • enforce contracts, resolve disputes and investigate violations;
  • comply with tax, accounting, legal, regulatory and law-enforcement obligations;
  • develop, test and improve the Services using aggregated, de-identified or appropriately controlled information;
  • send marketing communications where permitted and manage opt-out preferences; and
  • support a merger, financing, acquisition, restructuring or other corporate transaction.

5.1 Product improvement and analytics

We may analyse usage patterns, error information, feature adoption and feedback to improve Onegoin. Where practical, we use aggregated or de-identified information. We do not use Customer Content for unrelated advertising or sell it to data brokers.

5.2 Marketing

We may use business contact information to send information about Onegoin products, events, educational content or offers where permitted by law. You may unsubscribe through the link in the message or by contacting us. Essential security, billing and service communications cannot be disabled while the relevant account remains active.

6. Legal grounds for processing

Onegoin processes personal data only for lawful purposes. Depending on the context and applicable law, processing may be based on:

  • your consent, including consent for optional marketing or non-essential cookies;
  • steps requested by you before entering into a contract and performance of the Onegoin contract;
  • the provision of a service or feature requested by you or your organisation;
  • compliance with legal, tax, accounting, regulatory, security or law-enforcement obligations;
  • certain legitimate uses or legitimate interests recognised by applicable law, such as account security, fraud prevention, service improvement and B2B administration; or
  • another lawful ground that applies to the specific processing.

Where processing is based on consent, you may withdraw that consent using the method described at the time of collection, through available account settings or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal and may prevent us from providing a feature that depends on the relevant data.

7. Artificial intelligence and automated features

7.1 How AI information is processed

Onegoin may send AI Inputs, relevant project context and technical metadata to AI model, OCR or infrastructure providers solely to provide, secure and support the requested feature. The provider may process the information in India or another country where it or its subprocessors operate.

7.2 Model training

Unless we separately notify you and obtain any permission required by law, Onegoin does not use Customer Content to train a general-purpose AI model for unrelated customers. Onegoin seeks to configure third-party AI services so that submitted Customer Content is not used to train the provider’s general-purpose models where such controls are commercially available. Organisation administrators should review any feature-specific notice before enabling an AI integration.

7.3 Human review and accuracy

AI Outputs may be incomplete, inaccurate or unsuitable. Onegoin does not use AI Outputs to make binding legal, employment, credit, safety or professional decisions about individuals. Users must review AI Outputs before relying on them, especially for design, construction, quantity, cost, safety, contractual or compliance matters.

7.4 Avoid unnecessary personal data

Do not include unnecessary personal data, confidential credentials or sensitive personal information in an AI Input. Your organisation remains responsible for deciding what Customer Content may be submitted to an AI feature.

8. How we disclose personal data

Onegoin may disclose personal data in the following circumstances. We require service providers to process information only for agreed purposes and to use appropriate safeguards.

8.1 Service providers and subprocessors

  • cloud hosting, database, storage, content-delivery and backup providers, including services such as Render and Cloudflare;
  • payment processors, including Razorpay;
  • email, SMS, notification, customer-support and communication providers;
  • authentication, security, monitoring, error-reporting and fraud-prevention providers;
  • analytics and product-experience providers;
  • AI model, OCR and document-processing providers;
  • professional advisers, auditors, insurers and contractors; and
  • other vendors necessary to operate a feature requested by you.

8.2 Your organisation and authorised users

Personal data and Customer Content may be visible to organisation owners, administrators, team members, clients, vendors, consultants or other users according to the workspace permissions configured by your organisation. Onegoin is not responsible for an authorised administrator’s decision to grant, change or remove access.

8.3 Integrations

When an authorised user enables an integration, we may share information with the connected service as instructed. The third party’s privacy policy governs its independent processing. Disconnecting an integration stops future exchange but may not delete information already transferred to that third party.

8.4 Legal, security and rights protection

We may disclose information where reasonably necessary to comply with applicable law, court orders or lawful government requests; report or investigate cyber incidents; protect the security and integrity of the Services; prevent fraud or abuse; enforce our agreements; or protect the rights, safety and property of Onegoin, users or others.

8.5 With your direction or consent

We may disclose information when you or an authorised organisation administrator directs us to do so, or where you otherwise provide consent.

8.6 No sale of personal data

Onegoin does not sell or rent personal data to data brokers or third parties for their own independent marketing. We do not disclose Customer Content for third-party targeted advertising.

9. Organisation administrators and shared workspaces

When your account belongs to an organisation workspace, the organisation owner or administrator may be able to:

  • view your name, email address, role, status and workspace activity;
  • access project information and communications created within the workspace;
  • change your permissions or profile fields;
  • connect integrations and configure organisation settings;
  • export, archive, restore or delete workspace information;
  • suspend or remove your access; and
  • receive information concerning security, billing and compliance events.

Use your organisation workspace only for information that you are authorised to share with that organisation. When employment, engagement or membership ends, contact the organisation administrator regarding continued access or copies of project information.

10. International data transfers

Onegoin and its service providers may process or store personal data outside the state or country where you are located, including in locations where cloud, payment, communication or AI providers operate. Privacy laws in those locations may differ from the laws in your location.

Where required, Onegoin uses contractual, organisational and technical safeguards for international transfers and complies with restrictions notified under applicable Indian law. An organisation requiring specific data-residency commitments should contact Onegoin before purchasing an enterprise plan and should record those commitments in a signed order form or Data Processing Addendum.

11. Cookies and similar technologies

Onegoin may use cookies, local storage, pixels, software development kits and similar technologies to operate websites and applications. These technologies may be used for:

  • strictly necessary functions such as login, session management, load balancing and security;
  • remembering language, appearance and other preferences;
  • measuring website performance, errors and feature usage;
  • understanding the effectiveness of campaigns; and
  • marketing or advertising only where such tools are enabled and the required choice or consent has been obtained.

You may control cookies through the cookie banner, available privacy settings and your browser. Blocking necessary cookies may prevent sign-in or other core functions.

12. Data security

Onegoin uses technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. Depending on the system and risk, measures may include:

  • encryption in transit and encryption at rest where supported by the relevant service;
  • role-based access controls and least-privilege access;
  • password hashing, session controls and optional multi-factor authentication;
  • logging, monitoring, audit trails and suspicious-activity detection;
  • backups, recovery procedures and business-continuity measures;
  • secure development, vulnerability management and dependency updates;
  • confidentiality and data-protection obligations for personnel and service providers; and
  • incident-response procedures and periodic security review.

No online service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate permissions, removing former users promptly and maintaining independent copies of critical project records.

12.1 Personal data breaches

If Onegoin becomes aware of a personal data breach, we will investigate, contain and remediate the incident and provide notices to affected individuals, customer organisations and authorities when required by applicable law. Notices may describe the nature and likely consequences of the incident, mitigation measures, actions users can take and contact information for questions.

13. Data retention and deletion

Onegoin retains personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, protect security, resolve disputes and comply with legal obligations. The period depends on the type of data, account status, organisation instructions and applicable law.

Data categoryTypical retention approach
Account and profile dataWhile the account is active and for a reasonable period after closure for security, dispute and legal purposes.
Customer ContentWhile the workspace is active, followed by the post-termination export and deletion process.
BackupsDeleted information may remain in restricted backups until overwritten on the normal backup cycle.
Billing, invoices and tax recordsFor the statutory accounting, tax and audit periods applicable to Onegoin.
Security, access and processing logsGenerally at least 180 days and, where required for security or legal reasons, longer.
Support and legal communicationsFor as long as needed to resolve the matter, maintain an audit record and meet legal obligations.
Marketing contactsUntil you opt out, the information becomes inaccurate, or it is no longer needed.
AI Inputs and OutputsAccording to the workspace retention period and any shorter provider-specific period.

We may retain information longer where required by law, necessary for an active dispute or security investigation, or stored in a restricted backup pending scheduled deletion. Where feasible, information retained only for legal or security reasons will be isolated from ordinary product use.

14. Your rights and choices

Subject to applicable law and verification of your identity, you may have the right to:

  • obtain a summary of personal data processed about you and information about processing activities;
  • request correction, completion or updating of inaccurate or incomplete personal data;
  • request erasure of personal data when it is no longer required, subject to lawful retention;
  • withdraw consent where processing is based on consent;
  • raise a grievance concerning Onegoin’s handling of personal data;
  • nominate another individual to exercise rights in the event of death or incapacity, where applicable;
  • receive or export information in an available format;
  • object to or request restriction of certain processing where required by the law applicable to you; and
  • opt out of marketing communications and control non-essential cookies.

14.1 How to submit a request

You may use available account settings or email privacy@onegoin.com. Include your registered email address, organisation name, the right you wish to exercise and enough detail for us to identify the relevant information. Do not send passwords, full payment credentials or unnecessary identity documents by email.

14.2 Verification and organisation-controlled data

We may take reasonable steps to verify identity and authority before acting on a request. If the information is controlled by a customer organisation, we may forward the request to that organisation, ask you to contact its administrator, or respond on its instructions. Onegoin cannot delete information that an organisation is legally required to retain or that is still necessary for the organisation’s specified purpose.

14.3 Response and appeals

We will respond within the period required by applicable law. If we cannot fulfil all or part of a request, we will explain the reason where legally permitted. You may raise the matter with the Onegoin grievance contact below and, after using the available grievance process, with the competent data-protection authority where applicable.

15. Account closure, exports and workspace deletion

Cancelling a paid subscription does not necessarily delete the account or Customer Content. The organisation owner should separately request workspace deletion or use the available deletion controls.

Before closure, the organisation owner should export required project, accounting and statutory records. When a workspace is scheduled for deletion, Onegoin may:

  • place the workspace in read-only or restricted mode;
  • provide a limited export or recovery period;
  • remove Customer Content from active systems after that period;
  • retain limited billing, security and legal records; and
  • retain encrypted or restricted backup copies until the normal backup cycle completes.

Individual workspace members generally cannot require Onegoin to delete project records owned or controlled by the organisation. Such requests should be addressed to the organisation owner or administrator.

16. Children’s privacy

Onegoin is a business service intended for users who are at least 18 years old. Children must not create Onegoin accounts or use the Services independently.

An organisation must not upload a child’s personal data unless the processing is lawful, necessary for a genuine project or business purpose and supported by any required verifiable consent of a parent or lawful guardian. Onegoin does not knowingly use children’s personal data for behavioural monitoring or targeted advertising.

If you believe a child has created an account or that personal data has been submitted unlawfully, contact privacy@onegoin.com.

17. Third-party services and links

The Services may contain links to third-party websites or allow integrations with cloud drives, calendars, communication tools, payment services or other applications. Onegoin does not control those third parties’ independent privacy practices. Review their privacy policies before enabling an integration or providing information directly to them.

A third-party integration may retain information previously transferred even after it is disconnected from Onegoin. Contact that third party to exercise rights concerning information it independently controls.

18. Business transfers

If Onegoin is involved in a merger, acquisition, financing, reorganisation, insolvency, sale of assets or transfer of the relevant business, personal data may be disclosed to advisers and prospective or actual transaction parties under appropriate confidentiality protections. The recipient may continue processing personal data in accordance with this Policy or will provide notice of material changes as required by law.

19. Changes to this Policy

We may update this Privacy Policy to reflect changes in the Services, service providers, legal requirements or processing practices. The revised version will display an updated “Last updated” date.

Where a change materially affects how personal data is used or your rights, we will provide reasonable notice through the Services, email or another appropriate method before the change takes effect, where required. We may request renewed consent where the law requires it.

20. Contact and grievance redressal

Questions, requests and grievances concerning this Privacy Policy or Onegoin’s handling of personal data may be directed to:

Legal entityOnegoin Private Limited
BrandOnegoin
Privacy / grievance emailprivacy@onegoin.com
Supportsupport@onegoin.com
Websitehttps://onegoin.com

Please include your registered email address, organisation name and a clear description of your request. Onegoin will acknowledge and respond within the period required by applicable law. You should first use Onegoin’s grievance process before approaching the competent data-protection authority, where such a requirement applies.

Onegoin Onegoin

The all-in-one workspace for architecture, interior design and build studios.

Start Free Trial →
Product
FeaturesPricingDemoContact
Security Log in
For studios Architecture firms Interior designers vs spreadsheets vs task tools Free templates
Legal
Privacy PolicyTerms
sales@onegoin.com
© 2026 Onegoin · onegoin.com Made for studios that design & build.