OneCatering Privacy Policy
Effective Date: May 1, 2026 Last Updated: September 8, 2026
XKARAT LLC, a Washington limited liability company doing business as OneCatering ("OneCatering," "we," "us"), provides software for catering and event businesses. This Policy explains how we handle personal information.
1. Our Two Roles — Please Read First
Our obligations depend on whose data is involved.
We are the controller (a "business" under U.S. state privacy laws) for information about:
- our own customers, their account administrators, and prospects;
- visitors to our websites; and
- anyone who contacts us directly.
We are a processor (a "service provider") for information that a catering business (our "Customer") puts into the platform about its own clients, event guests, staff and contractors. We process that information only on our Customer's documented instructions, under our Terms of Service and Data Processing Addendum.
If you are an event client, guest, or an employee of a catering business that uses OneCatering, the catering business — not OneCatering — controls your information. Please direct requests to access, correct or delete it to that business. If you contact us, we will refer you to them and may forward your request.
2. Information We Collect
2.1 Information you provide to us (we are controller)
- Account and contact data: name, business name, business address, email, phone, job title, login credentials.
- Billing data: billing contact and address, plan, transaction history, and the last four digits and expiry of a payment card. Full card numbers are collected and stored by our payment processor, not by us.
- Support and communications: the content of tickets, emails, chats, calls and survey responses.
- Marketing data: preferences, event and webinar registrations.
2.2 Information collected automatically (we are controller)
- Device and log data: IP address, browser and device type, operating system, language, referring URL, timestamps, crash and diagnostic data.
- Usage data: pages and features viewed, actions taken, session duration, and performance metrics.
- Cookies and similar technologies: see Section 8.
- Approximate location derived from IP address. We do not collect precise geolocation.
2.3 Information our Customers put into the platform (we are processor)
Our Customers may submit, among other things:
- End client data: names, contact details, event addresses, dates, headcounts, notes, quotes, invoices and payment status.
- Guest and dietary data: meal selections, dietary restrictions, allergies, intolerances and related notes.
- Staff data: names, contact details, roles, certifications, availability, schedules, shift and timekeeping records, and pay-related fields.
- Operational content: menus, recipes, ingredients, supplier records, photos and documents.
Sensitive data notice. Allergy, intolerance and dietary information may qualify as "consumer health data" under the Washington My Health My Data Act and as sensitive personal information under the California Consumer Privacy Act. We process it only as a processor, on our Customer's instructions, to provide the platform. We do not sell it, share it for cross-context behavioral advertising, or use it for our own purposes. Our Customer is responsible for obtaining any consent or authorization required before entering it into the platform.
2.4 Information from connected accounts and integrations
Where a user connects a third-party account, we receive data from that account as described in Sections 11 (Google) and 13 (other integrations, including QuickBooks). We also receive transaction status (not card numbers) from our payment processor, and signals from identity, fraud-prevention and security vendors.
We do not knowingly collect information from anyone under 16. If you believe a child's information has been submitted to us, contact constantine@onecatering.app.
3. How We Use Information (as controller)
We use personal information to:
- provide, operate, maintain and support the Service;
- bill, collect fees, and prevent payment fraud;
- authenticate users and secure accounts;
- monitor, debug and improve performance and features;
- detect, investigate and prevent abuse, fraud and security incidents;
- send service, security and billing notices;
- send marketing about our own products, subject to your opt-out;
- produce aggregated and de-identified analytics; and
- comply with law and enforce our agreements.
Sale and sharing of personal information
We do not sell personal information for money.
However, our marketing website (onecatering.app and related pages) uses advertising and analytics technologies — including the Meta Pixel, Google Ads / Google Tag with enhanced conversions, and the Apollo website tracker — that disclose identifiers, device and browsing information, and in some cases hashed contact information to those providers. Under the California Consumer Privacy Act and similar state laws, that activity may constitute a "sale" of personal information or "sharing" for cross-context behavioral advertising, even though we receive no money for it.
You can opt out. See Section 9, or use the Do Not Sell or Share My Personal Information link in our website footer. We honor the Global Privacy Control and other recognized opt-out preference signals as a browser-level opt-out.
These advertising technologies are limited to our marketing website. They are not deployed inside the authenticated OneCatering application, and they do not have access to Customer Data — including any client, guest, dietary, allergen or staff information.
Google user data obtained through Google APIs is excluded entirely from advertising, marketing and analytics uses. See Section 11.
Automated decision-making. We do not use personal information to make decisions producing legal or similarly significant effects about individuals without human involvement. AI features in the platform generate suggestions that our Customer must review; our Customer, not OneCatering, is responsible for any decision it makes using them.
AI training. We do not use identifiable Customer Data to train publicly available foundation models. We do not use Google Workspace API data to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models (see Section 11).
4. When We Disclose Information
- Subprocessors and vendors who help us operate the Service — hosting, storage, analytics, email and SMS delivery, payment processing, AI model providers, support tooling and security — under written contracts limiting their use. Current list: https://onecatering.app/subprocessors.
- Our Customer, where the information relates to that Customer's account.
- Integrations you or our Customer enable, at your direction.
- Advertising and marketing analytics providers (Meta, Google, Apollo), in respect of marketing-website visitors only, as described in Sections 3 and 8.
- Professional advisors (legal, accounting, insurance) under confidentiality.
- Legal and safety disclosures: to comply with law, subpoena or legal process; to enforce our agreements; or to protect the rights, safety or property of OneCatering, our customers or the public. Where legally permitted, we will make reasonable efforts to notify the affected Customer first.
- Corporate transactions: in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to this Policy or a successor policy with equivalent protections.
We do not disclose personal information for any other purpose without a lawful basis. Additional restrictions apply to Google user data — see Section 11.
5. Where We Operate
OneCatering is based in Seattle, Washington, and processes information in the United States. We do not currently offer the Service to catering businesses established in the European Economic Area, the United Kingdom or Switzerland. If you access the Service from outside the United States, you understand that your information will be processed in the United States. If we begin serving customers in those regions, we will update this Policy and implement an appropriate transfer mechanism before doing so.
6. Retention
We keep personal information for as long as needed for the purposes described in this Policy.
- Account and billing records: for the term plus 3 years, for tax, audit and legal-claim purposes.
- Customer Data (processor role): for the subscription term, plus a 30-day post-termination export window. After that window we delete it from production systems within 60 days. See the Terms of Service and DPA.
- Google user data: see Section 12.
- Support records: 12 months. Security and access logs: 6 months.
- Backups: deleted data may persist in vendor-managed database backups for up to 35 days before being overwritten.
- Aggregated and de-identified data: retained indefinitely; we do not attempt to re-identify it.
7. Security
The OneCatering application runs on Supabase, a managed platform provider, with our production database in the US-West-1 (Northern California) region. We do not operate our own servers or data centers.
Our current safeguards are:
- Encryption of personal information in transit and at rest, provided through the Supabase platform.
- Role-based access controls, with permissions and tenant isolation enforced server-side so that each customer's users can reach only that customer's data.
- Daily vendor-managed database backups.
- Encrypted storage of authentication credentials and OAuth tokens, accessible only to the systems that need them.
We also rely on the security programs and independent certifications of our service providers, including Supabase and Stripe. Those certifications belong to those providers and are not certifications of OneCatering. OneCatering does not currently hold a SOC 2, ISO 27001 or equivalent certification of its own. Our providers are listed at https://onecatering.app/subprocessors.
We are working toward additional controls — required multi-factor authentication for administrative access, centralized audit logging, automated dependency scanning, documented incident-response and disaster-recovery plans, annual restore testing, and formal personnel security training. These are planned and are not yet in place.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting Customer Data, we will notify the affected Customer without undue delay as required by law and our DPA.
More detail: https://onecatering.app/security.
8. Cookies, Tracking and Consent Management
We use cookies and similar technologies on our marketing website and, for essential purposes only, in the application.
Strictly necessary — required for the Service to function; cannot be switched off:
- Supabase — authentication, session management and application infrastructure
- Stripe — payment processing and payment fraud prevention
Functional — features you choose to use:
- Calendly — meeting scheduling
- Luma — event registration
- Google Maps — address and map display
- Google Fonts — typography
- YouTube (embedded video, where used) — we use privacy-enhanced mode where available
Analytics and performance:
- Sentry — error and performance monitoring
- Lovable — website analytics and telemetry
Advertising and marketing (marketing website only):
- Meta Pixel — conversion measurement and advertising audiences
- Google Ads / Google Tag, including enhanced conversions — conversion measurement and advertising, which may involve sending hashed contact information to Google
- Apollo website tracker — visitor identification for business-to-business marketing
Consent management. We use a consent management platform that blocks non-essential advertising and analytics technologies until consent is given where consent is required, and that honors the Global Privacy Control and other recognized opt-out preference signals. You can change your choices at any time at https://onecatering.app/cookies, and you can also manage cookies through your browser settings.
Advertising and analytics technologies in the "Advertising and marketing" group above are not deployed inside the authenticated application and have no access to Customer Data.
9. Your Rights
Depending on where you live, you may have the right to: access or obtain a copy of your personal information; correct it; delete it; obtain it in a portable format; opt out of sale, sharing for targeted advertising, or profiling with significant effects; limit use of sensitive personal information; withdraw consent; and appeal a denial. You will not be discriminated against for exercising these rights.
How to exercise them: email constantine@onecatering.app or use https://onecatering.app/privacy-request. We will verify your identity and respond within the time required by applicable law (generally 45 days, extendable by 45 more). An authorized agent may submit a request with proof of authority.
Opting out of sale and sharing for targeted advertising
As explained in Section 3, our marketing website uses advertising technologies that may constitute a "sale" or "sharing" under state privacy law. You have three ways to opt out:
- Use the "Do Not Sell or Share My Personal Information" link in our website footer, or go to https://onecatering.app/privacy-request.
- Adjust your choices in our cookie banner or at https://onecatering.app/cookies.
- Enable the Global Privacy Control in your browser or extension. We treat a GPC signal as a valid opt-out request for the browser that sends it, without requiring you to identify yourself.
An opt-out applies to the browser and device on which it is made. If you clear cookies or use a different browser, you will need to opt out again. We do not require an account, and we will not discriminate against you, for exercising these rights.
Appeals. If we deny your request, you may appeal by replying to our decision or writing to constantine@onecatering.app with "Appeal" in the subject line. We will respond within the statutory period. Washington residents may also contact the Washington State Attorney General; residents of other states may contact their own Attorney General.
Requests about data held on behalf of a catering business will be forwarded to that business, which is the controller.
10. Washington My Health My Data Act Notice
This Section applies to Washington consumers and to consumer health data collected in Washington. **[If dietary, allergen or health-adjacent data is in scope, the MHMDA requires a separate, clearly linked Consumer Health Data Privacy Policy — a distinct page, not a section of this one. Confirm scope with counsel and publish it separately at https://onecatering.app/consumer-health-data.]**
We collect allergy, intolerance and dietary information only as a processor, at the direction of the catering business that uses our platform, and only to provide the platform to that business. We do not collect it for our own purposes, do not use it for advertising, and do not sell it. We do not collect information about the precise location of any consumer's health-care-facility visits.
Washington consumers have the right to confirm whether we collect, share or sell their consumer health data, to obtain a list of third parties with whom it has been shared, to withdraw consent, and to have it deleted. Contact constantine@onecatering.app; where the data belongs to a catering business's account, we will refer the request to that business.
11. Google API Services User Data
Any provisions elsewhere in this Privacy Policy concerning advertising, marketing, analytics, profiling, or promotional uses of data do not apply to Google user data obtained through Google APIs.
OneCatering allows users to connect their Google accounts to enable Gmail and Google Calendar functionality. Access to Google user data occurs only after the user explicitly authorizes OneCatering through Google OAuth.
Google data we access
Depending on the permissions authorized by the user, OneCatering may access:
- Gmail data, including email messages, message metadata, sender and recipient information, threads, and related information necessary to display and manage email communications within OneCatering.
- Gmail sending permissions, to allow users to send emails from their connected Google account through OneCatering, including proposals, invoices, confirmations, event communications, and other communications initiated by the user.
- Google Calendar data, including calendars, calendar events, event details, dates, times, attendees, and related scheduling information required to synchronize OneCatering events with Google Calendar.
How we use Google user data
OneCatering uses Google user data only to provide or improve user-facing features that the user chooses to use within OneCatering. These uses may include:
- displaying and synchronizing relevant email communications;
- associating communications with leads, clients, and events;
- sending emails on behalf of the authenticated user when requested by the user;
- synchronizing catering events and schedules with Google Calendar;
- creating, updating, or removing calendar events when initiated through OneCatering; and
- maintaining the user's connected Google integration.
OneCatering does not use Google user data for purposes unrelated to providing or improving these user-facing features.
Advertising and marketing
Google user data obtained through Google APIs is not used for advertising, retargeting, personalized advertising, advertising audiences, data brokerage, or marketing OneCatering to users.
If a OneCatering customer chooses to use OneCatering's email communication or email marketing functionality, Google account access is used only to carry out communications initiated or configured by that authenticated customer. Google user data is not used by OneCatering to independently advertise or market OneCatering products.
Sharing and transfer of Google user data
OneCatering does not sell Google user data.
OneCatering does not transfer Google user data to advertising networks, data brokers, information resellers, or other third parties for advertising or unrelated commercial purposes.
Google user data may only be shared with service providers when necessary to provide or maintain a user-facing OneCatering feature, protect the security of the service, comply with applicable law, or as otherwise permitted under the Google API Services User Data Policy, including its Limited Use requirements.
Artificial intelligence and machine learning
Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
Data storage and security
OneCatering maintains reasonable administrative, technical, and organizational safeguards designed to protect Google user data from unauthorized access, disclosure, alteration, or destruction.
Authentication credentials and OAuth tokens are restricted to authorized systems and are used only to maintain the Google integrations authorized by the user.
Human access
OneCatering personnel do not read, access or process Google user data except: with the user's explicit written consent for a specific purpose (such as troubleshooting a support request the user has raised); where necessary for security purposes, such as investigating abuse; to comply with applicable law; or where the data has been aggregated and de-identified for internal operations.
12. Google Data Retention and Deletion
OneCatering retains Google user data only for as long as necessary to provide the Google-connected functionality requested by the user.
Users may disconnect their Google account from OneCatering at any time from the integrations settings in the application, or by revoking access at https://myaccount.google.com/permissions. When a Google integration is disconnected, OneCatering stops accessing the user's Google account and removes or invalidates the associated OAuth credentials in accordance with our data-retention practices.
Users may also request deletion of Google-derived data associated with their OneCatering account by contacting constantine@onecatering.app.
13. Other Integrations
QuickBooks (Intuit)
Where a user connects an Intuit QuickBooks Online account, OneCatering accesses that account only after the user explicitly authorizes it through Intuit's OAuth flow, and only to the extent of the scopes the user grants.
Data we access. Depending on the permissions authorized, OneCatering may access and exchange: company and account profile information; customer and contact records; items, products and services; invoices, estimates, sales receipts, credit memos and payment records; tax codes and rates; classes, departments and chart-of-accounts references; and related metadata necessary to synchronize OneCatering records with QuickBooks.
How we use it. QuickBooks data is used solely to provide user-facing accounting and invoicing features that the user chooses to use, including: creating, updating and syncing customers, invoices, estimates and payments between OneCatering and QuickBooks; reconciling payment status; mapping items and tax codes; and maintaining the connected integration.
Restrictions. OneCatering does not sell QuickBooks data, does not transfer it to advertising networks or data brokers, does not use it for advertising or to market OneCatering, and does not use it to train generalized or non-personalized artificial intelligence or machine-learning models. QuickBooks data is shared with service providers only as necessary to provide or maintain the integration, secure the Service, or comply with law.
Accuracy. The QuickBooks integration exchanges data between two systems that the Customer controls. OneCatering does not verify the accuracy of accounting or tax data in either system, provides no accounting or tax advice, and is not responsible for sync errors, duplicate records, misapplied tax codes, or any resulting accounting, tax or audit consequence. Customers must reconcile their own books.
Disconnection and deletion. Users may disconnect QuickBooks at any time from the integrations settings, or by revoking access in their Intuit account. On disconnection, OneCatering stops accessing the QuickBooks account and invalidates the associated OAuth credentials. Records already synced into either system remain in that system unless separately deleted. Deletion requests: constantine@onecatering.app.
Other third-party services
The Service may also interoperate with payment processors, email and SMS providers, calendar and mapping services, and AI model providers. Each is listed at https://onecatering.app/subprocessors. Your use of a third-party service is governed by that provider's own terms and privacy policy; OneCatering does not control and is not responsible for their data practices.
14. SMS and Mobile Information
If you provide a mobile number and separately opt in, XKARAT LLC d/b/a OneCatering may use that number to send the categories of text messages you selected. Message frequency varies; the combined total is up to 6 messages per month. Message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is optional and is not a condition of purchase or use of OneCatering.
We do not sell, rent, or share mobile phone numbers, SMS opt-in data, or messaging consent with third parties or affiliates for their own marketing or promotional purposes. We may disclose this information only to service providers that help us operate the OneCatering messaging program, subject to confidentiality and use restrictions, or when required by law.
Terms: https://onecatering.app/terms Messaging preferences: https://onecatering.app/sms-consent
Message categories. Informational messages cover demo confirmations and reminders, trial and account notices, onboarding, and customer support. Marketing messages cover product updates, offers, and event invitations. Each category requires its own separate opt-in; consenting to one never enrolls you in the other.
Consent. We send text messages only to people who have separately opted in on our SMS consent page or on another OneCatering form that displays the same disclosure beside its own unchecked, optional checkbox. Entering a phone number, booking a demo, creating an account, starting a trial, purchasing, or accepting these policies never creates SMS consent. We never enroll numbers from purchased, rented, imported or pre-existing contact lists.
Proof of consent. For each consent decision we keep a permanent record of the name, business name, email address, mobile number in E.164 format, the category selected, whether consent was granted or withdrawn, the exact disclosure text with its version and fingerprint, the time in UTC, the page and form version the decision came from, campaign parameters, and the IP address and browser user agent used, together with the time and source of any later withdrawal. Consent records are never overwritten.
Rates. Message and data rates may apply. Your mobile carrier's standard messaging and data charges are your responsibility, and carriers are not liable for delayed or undelivered messages.
Opting out and help. Reply STOP to any message to stop receiving texts, or HELP for assistance. Opt-outs are honored immediately. Opting out of text messages does not close your account and does not stop email notifications required to operate the Service.
Questions about our messaging program: constantine@onecatering.app or +1-949-593-5564.
15. Additional U.S. State Disclosures
For the 12 months preceding this Policy's date, the categories of personal information we collect, the purposes, and the categories of recipients are described in Sections 2–4 and 11–13.
Sensitive personal information. As a processor only, we may process health-related dietary and allergy information and, where a Customer enables it, account credentials for connected services. We do not use or disclose sensitive personal information for purposes beyond those permitted for service providers under the CCPA, and we do not use it to infer characteristics about any individual.
Sale and sharing. We do not sell personal information for monetary consideration. As described in Section 3, advertising and analytics technologies on our marketing website may constitute a "sale" or "sharing" for cross-context behavioral advertising under the CCPA and similar laws. The categories involved are online identifiers, device and internet activity information, approximate location derived from IP address, and — through enhanced conversions — hashed contact information. The categories of recipients are advertising and marketing analytics providers (Meta, Google, Apollo). Opt-out mechanisms are in Section 9.
We do not knowingly sell or share the personal information of consumers under 16.
Customer Data is never sold or shared. Client, guest, dietary, allergen and staff information submitted to the application by our Customers is processed only as a service provider, on that Customer's instructions.
16. Changes
We may update this Policy. Material changes will be announced by email to account administrators or by in-Service notice at least 30 days before they take effect. The "Last Updated" date reflects the most recent revision. Prior versions: https://onecatering.app/legal-archive.
17. Contact
XKARAT LLC d/b/a OneCatering 1701 NW 56th St, Seattle, WA 98107 Privacy, security and legal: constantine@onecatering.app