Last updated: August 9, 2026
Encrypted in transit, passwords hashed (bcrypt)
We do not sell your personal data
A dataroom's owner sees who viewed what
Exercise them by email: privacy@onefive.app
The data controller is YC STRATEGIC VENTURES, a French société par actions simplifiée registered with the Paris Trade and Companies Register under number 103 274 072, with its registered office at 229 rue Saint-Honoré, 75001 Paris, France ("Onefive", "we").
This policy covers the onefive.app website and the Onefive platform (accounts, feed, messaging, datarooms, profiles). For any question, or to exercise your rights, write to privacy@onefive.app. We have not appointed a Data Protection Officer, and we are not required to, so your request is handled by the company directly.
| Purpose | Data involved | Legal basis (GDPR art. 6) |
|---|---|---|
| Providing the service: account, profiles, feed, messaging, datarooms, spotlight | Account, profile, content, startup data | Performance of the contract |
| Transactional emails (verification, security, invitations, notifications) | Email, name, language | Performance of the contract |
| Account security and fraud prevention | IP, user-agent, sessions, FingerprintJS identifier | Legitimate interest (protecting the service and its users) |
| Informing a dataroom's owner of who viewed it | Access events (signed-in viewer identity, documents, timestamps) | Legitimate interest (transparency when sharing confidential documents) |
| Syncing your LinkedIn background | Professional background | Consent (you trigger the sync) |
| Audience measurement and product improvement | Usage data (PostHog) | Legitimate interest |
| Complying with our legal obligations | Strictly necessary data | Legal obligation |
Datarooms exist to share sensitive documents (deck, cap table, legal documents) in a controlled way. In return, when you view a dataroom that has been shared with you, its owner can see that you opened it, which documents you viewed, and when. If you access a dataroom through an anonymous link, the viewing is recorded without being linked to an account. By viewing a dataroom, you are informed of this tracking.
Some data may be kept longer where the law requires it (for example for accounting purposes or in case of litigation), for the strictly necessary duration.
We never sell your data. We share it only with the providers that make the service work:
| Provider | Role | Location |
|---|---|---|
| Railway | Backend and database hosting (PostgreSQL) | US company |
| Vercel | Web front-end hosting | US company |
| Cloudflare | File and document storage (R2) and CDN | US company |
| PostHog | Audience measurement | Data hosted in the EU (eu.posthog.com) |
| Resend | Transactional email delivery | US company |
| Google, LinkedIn, Apple | OAuth sign-in (only if you use it) | See their own privacy policies |
Several of our providers are US companies. The resulting data transfers are governed by the European Commission's standard contractual clauses and, where applicable, by the provider's certification under the EU–US Data Privacy Framework. You can request a copy of the applicable safeguards at privacy@onefive.app.
You have the following rights over your data:
To exercise them, write to privacy@onefive.app. We answer within one month. If you are not satisfied with our answer, you can lodge a complaint with the CNIL, the French data protection authority, or with the supervisory authority of your country of residence.
All exchanges with our servers are encrypted (HTTPS). Passwords are hashed with bcrypt and never stored in clear text. Session cookies are protected (httpOnly). Access to data is restricted to what is needed to operate the service. No system is infallible: should a data breach put you at risk, we will notify you as the GDPR requires.
Onefive is aimed at a professional audience and is not intended for anyone under 15, the age of digital consent in France. We do not knowingly collect their data, and will delete it if we learn we have.
We may update this policy. If a change is material, we will inform you by email or through the platform before it takes effect.
Access, correction, deletion, portability, objection. Email us and we will action it. There is no self-serve privacy dashboard yet; when there is, it will be linked here.
privacy@onefive.app