Privacy notice.
Effective September 29, 2026
Who we are
OneSend, Inc., a Delaware corporation ("OneSend", "we", "us"), operates onesend.com and the OneSend service. OneSend powers what happens inside a message: buying, paying, verifying and signing, with no redirect and no app. Brands add OneSend to the emails and texts they already use, so the message you open becomes an interactive, secure message.
OneSend is not yet generally available. Today, onesend.com collects only what you choose to send us through the request form. No biometric data is collected on this website. The sections about OneSend-powered messages describe how the service handles information once it launches, and we will update this notice before then if anything changes.
This website
If you request information, we collect your name, work email, telephone number (if you give it), company or agency, role, organization type, what brings you to us, and what you tell us about your use case.
We use this to reply to you, and we send you one email confirming we received your request. If you tick the box to receive launch updates, we will also email you news about OneSend's launch. Every update includes an unsubscribe link, and you can also write to privacy@onesend.com to stop them.
Our hosting and email providers process technical information, such as your IP address and browser type, to deliver the site and keep it secure. onesend.com uses no advertising or analytics cookies. Our site does not respond differently to browser "Do Not Track" signals, because it does not track you across other sites.
What OneSend never places in a message
OneSend never places personal, health or financial information in a message, not even in masked form. That information is not present in the message while it is in transit.
Sensitive information is transmitted only after a secure link has been established and the right person has been confirmed. It is not retained in the message, and it appears again only if you are authenticated again.
Identity verification, including biometrics
How we confirm who you are depends on where the message reaches you.
Interactive email. When a OneSend-powered message reaches you as an interactive email (AMP email, or Microsoft's interactive messages in Outlook), we do not run our own identity check. We rely on your email provider's authentication of the person signed in to the account where the message is opened. We do not collect biometric data for email.
RCS business messages. When a message reaches you as an RCS business message from a brand's verified agent, we confirm the person holding the phone is the person the message is for before any sensitive information is transmitted. Depending on what the message is for, that check is a sign-in with the brand, a one-time code, or a face check. The rest of this section describes the face check.
Who performs it. Face checks are performed by our identity-verification provider, Realeyes (VerifEye), which processes the data on our behalf. OneSend is responsible for that data.
Your consent comes first. Before any capture, you are shown a notice explaining what will be collected and why, and you are asked for your explicit consent. The camera is never opened without it. You can decline or cancel at any time; declining means the sensitive information is not shown, and nothing else happens. If you would rather not use a face check, tell the brand behind the message or contact us, and another verification method will be offered.
What is collected. A short live camera capture is used to confirm a real person is present and to derive a facial template, a mathematical representation designed so that it cannot be turned back into a picture of your face. The video itself is deleted automatically within minutes of the check. The template is kept so that later checks can be compared against it. OneSend keeps only a reference identifier and the outcome of each check (passed, failed or declined) with its time.
How long it is kept. We destroy the facial template at the earliest of: when you withdraw consent or ask us to delete it; when the purpose for which it was collected has been satisfied; or 24 months after your last face check. Where a law in your region sets a shorter period, we follow it.
What it is never used for. OneSend does not use your face to identify you in any other context, does not sell, rent or share biometric data, does not use it for advertising or profiling, and does not use it to train models. Realeyes describes its own handling of verification data, including any use of anonymized data, in its privacy policy.
Payment, health and other regulated data
Card, account, health and other regulated data are tokenized by our tokenization provider and handled as regulation requires. OneSend systems hold tokens, never the underlying values.
Records of interactions
We keep a record of each step of an interaction, such as message received, message opened, verification attempted and information shown, so a brand can show its regulator what happened and when.
These records contain no personal, health or financial details. Recipients are identified only by a hashed or tokenized reference, and sensitive data is tokenized as described above.
Your phone number
When a brand uses OneSend to bring an RCS business message to your phone, we process your mobile number so the message reaches you, to confirm it arrived, and to honor your opt-out.
We store the number as a one-way cryptographic hash wherever we can, so our records identify a recipient without holding the number itself. If you opt out, we keep that hash on a suppression list so the brand's messages stop reaching you.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes.
Message frequency varies. Message and data rates from your carrier may apply. Reply STOP to opt out, or HELP for support.
How we use information
We use information to provide, secure and improve the OneSend service and this website, to respond to your requests, and to meet our legal obligations.
We do not sell or rent your data
OneSend does not sell or rent your data, and our providers and contractors are contractually prohibited from doing so. That is not our business model.
We use a small set of providers under contract, each limited to what they need: website hosting, cloud hosting, databases and email delivery, the mobile carriers and network providers that carry a message to your phone, our identity-verification provider, and our tokenization provider. They process data on our instructions. We may also disclose information where the law requires it.
How long we keep information
We keep the content of a message so it is still there whenever you want to come back and read it, just as an email stays in your inbox. OneSend adds no personal, health or financial information to that content.
We keep other information only for as long as it is needed and as the regulations of your region allow or require. Biometric templates follow the schedule above. We will delete retained data at your request, and as the regulations of your region require.
Security
We use reasonable administrative, technical and physical safeguards designed to protect information, including encryption in transit, hashing and tokenization. No system is perfectly secure, and we will notify you and the relevant authorities of a breach where the law requires.
Your choices and rights
You can opt out of a brand's text messages at any time (reply STOP), ask what we hold about you, ask us to correct or delete it, withdraw consent to biometric processing, and ask us to delete a biometric template. Depending on where you live you may have additional rights, including under the GDPR, the CCPA/CPRA, the Colorado Privacy Act, and state biometric-privacy laws. We will respond to these requests wherever you live, in the way the law of your region requires, and we will not treat you differently for making one. To protect you, we may need to confirm your identity before acting on a request.
Where the GDPR or UK GDPR applies, we rely on your explicit consent for biometric processing, on our legitimate interest in responding to requests you send us, on your consent for launch updates, and on the instructions of the brand for messages we handle on its behalf. Our providers may process data in the United States. You may also complain to your local data-protection authority.
Children
Our service is not directed to children, and we do not knowingly collect data, biometric or otherwise, from anyone under 18.
Changes and contact
We will post any changes to this notice on this page and update the effective date above. For questions, requests or deletion, contact OneSend, Inc. at privacy@onesend.com.
Back to home