What onelinktoken collects, why we collect it, how long we keep it, and who processes it on our behalf.
Effective date: [Effective date] · Version: draft
Draft for legal review — not legal advice
This document is a working draft prepared for review by qualified counsel. It is not legal advice
and is not yet the operative privacy notice for onelinktoken. Every bracketed value — for example
[Legal entity name] or [Retention period] —
must be completed, and the document reviewed in full, before publication.
onelinktoken is a one-time token and magic-link service operated by [Legal entity name] (“we”, “us”), registered at [Registered address]. This policy covers the onelinktoken website at onelinktoken.com, the onelinktoken REST API, and the onelinktoken MCP server.
For most of what we handle, we act as a processor on behalf of the customer whose account issued the token. That customer decides which end-user data is sent to us. For our own account, billing, and support records we act as a controller. Where a data processing agreement is in place, that agreement governs.
| Category | What it includes | Source |
|---|---|---|
| Account data | Account and tenant identifiers, sign-in identity, plan, API key metadata. | You / your IdP |
| Token records | Token type, target address supplied by you, expiry, max uses, status, redirect URL, and a SHA-256 hash of the token value. | Your API / MCP calls |
| Audit events | Create, redeem, and revoke events with timestamp, IP address, user agent, and acting identity. | Automatic |
| Operational logs | Request metadata, rate-limit counters, and error traces used to run and secure the service. | Automatic |
| Billing data | Plan, subscription state, and invoice records. Card details are handled by our payment processor and never reach our servers. | You / Stripe |
A magic link, OTP, or bearer token is returned to the caller once, at creation. What we persist is a SHA-256 hash of the value, used to validate a later redemption. We cannot reconstruct or re-issue the original token, and neither we nor an attacker with database access can read it out of storage.
We do not sell personal data, we do not run advertising trackers on this site, and we do not use customer token data to train machine-learning models.
Retention periods below are placeholders pending review and must be confirmed against the product's actual database and log configuration before this page is published.
We use the third parties below to run the service. Any entry marked [Subprocessor] is a placeholder
that must be replaced with the confirmed vendor, purpose, and processing location before publication.
| Subprocessor | Purpose | Data reached |
|---|---|---|
| Stripe | Payment processing and subscription billing | Billing contact, payment details (held by Stripe, not by us) |
| Resend | Transactional email delivery for magic links and OTPs | Recipient email address, message content |
| Keycloak (auth.pnebula.com) | Identity provider for account sign-in and SSO | Sign-in identity, session metadata |
| [Subprocessor] | Cloud hosting and managed database | [Confirm before publishing] |
| [Subprocessor] | Monitoring, logging, and error tracking | [Confirm before publishing] |
Where personal data moves between jurisdictions, transfers rely on [Transfer mechanism]. Primary processing region: [Processing region].
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing relies on consent. You can also complain to your local supervisory authority.
If the data was sent to us by a customer using onelinktoken to authenticate you, that customer is the controller — we will forward your request to them and support them in answering it. We aim to respond to rights requests within [Statutory response window].
Controls in place today include hash-only token storage, single-use tokens by default, short configurable expiry, hot revocation, per-tenant and per-IP rate limits, encryption in transit, and an append-only audit trail of every create, redeem, and revoke.
onelinktoken is designed against the control expectations of SOC 2, HIPAA, and GDPR. This document makes no assertion that any audit has been completed, that any certification has been issued, or that a Business Associate Agreement is available on any given plan. If you need current attestation status, an executed DPA, or a BAA, ask us and we will tell you exactly where things stand. [Marked for review: confirm attestation status and align with site-wide marketing claims.]
No system is perfectly secure. If you believe you have found a vulnerability, please use the reporting route on our support page rather than a public channel.
This marketing site does not set advertising cookies. Any cookie used by the dashboard is strictly necessary for sign-in and session management. Current analytics configuration: [Analytics tooling — confirm or state "none"].
onelinktoken is a developer tool sold to businesses. It is not directed at children, and we do not knowingly collect data from children under [Minimum age].
We will post any change on this page and update the effective date. For material changes affecting existing customers we will give notice at least [Notice period] in advance by email or in the dashboard.
Privacy questions, rights requests, and DPA requests:
For anything that is not a privacy matter, see Support.