Privacy Policy
Last updated: July 16, 2026
This Privacy Policy explains how OneBit ("OneBit", "we", "us", or "our") collects, uses, discloses, and protects personal data when you visit or use Driview, including its dashboards, reports, alerts, integrations, and related services (the "Service").
OneBit is the controller of personal data processed for its own purposes. Where a business customer submits personal data to the Service and determines why and how it is processed, that customer may be the controller and OneBit may process the data on its behalf.
1. Who We Are
Controller: OneBit
Country of establishment: Republic of Korea
Product: Driview
Privacy contact: support@driviewapp.com
2. Personal Data We Collect
- Account and contact data: email address, display or profile information, authentication provider identifiers, account status, and workspace membership.
- Subscription and transaction data: selected plan, subscription status, billing dates, Paddle customer, subscription, and transaction identifiers, and related support records. Paddle processes full payment-card and payment-method details; Driview does not store complete card numbers.
- Workspace and service data: workspace name, locale, time zone, app identifiers, competitor selections, countries, alert settings, reports, exports, and feature configuration.
- App-store and review data: public or connected-store data such as app listings, release information, review text, review titles, ratings, dates, country, language, app version, review URLs, and public reviewer names or usernames.
- Integration data: notification destinations and webhook URLs, Slack or other messaging configuration, App Store Connect issuer and key identifiers and private keys, Google Play service account information, and related connection status. Sensitive integration credentials are encrypted before storage.
- Content and communications: prompts, instructions, drafts, replies, support requests, and other information you submit or generate through the Service.
- Prospective business contact data: public business email addresses, contact names, company or app information, the official source URL, outreach history, replies, and opt-out records.
- Technical and usage data: IP address, browser and device information, operating system, session and authentication events, timestamps, requested pages, error logs, and security-related activity.
- Essential service-state telemetry: the account and workspace, timestamp, and source record for milestones such as onboarding completion, connecting an app, generating the first report, accepting or completing an action, and subscription lifecycle changes. These server-derived records do not contain page-query values, anonymous advertising identifiers, or campaign attribution.
- Cookies and similar technologies: session, authentication, security, and preference cookies needed to operate the Service.
3. Sources of Personal Data
We collect personal data:
- directly from you and other authorized workspace users;
- automatically when you use the Service;
- from authentication, payment, hosting, and integration providers;
- from Apple App Store, Google Play, and other public sources;
- from business contact details published on a developer's official public website; and
- from store accounts and communication destinations you choose to connect.
4. How and Why We Use Personal Data
We use personal data to:
- create accounts, authenticate users, and administer workspaces;
- provide app monitoring, review analysis, reports, alerts, exports, and reply workflows;
- process and administer trials, subscriptions, plan changes, cancellations, and refunds;
- operate connected store, messaging, and email integrations;
- generate AI-assisted classifications, summaries, recommendations, and drafts;
- provide support and communicate service, security, billing, and policy updates;
- send compliant business-to-business outreach about Driview and honor do-not-contact requests;
- monitor performance, troubleshoot errors, secure the Service, and prevent fraud or abuse;
- improve features and understand aggregate usage patterns; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Where applicable law requires a legal basis, we rely on performance of our contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is required. You may withdraw consent at any time, without affecting earlier lawful processing.
We do not use personal data from the Service to serve third-party behavioral advertising.
5. How We Disclose Personal Data
We disclose personal data only as reasonably necessary to the following recipients:
- Infrastructure and hosting providers: including Supabase and Vercel, which host the application, database, authentication, server functions, and related infrastructure.
- Analytics provider: Google Analytics, when enabled and subject to your analytics consent choice, helps us understand aggregate website and product-funnel usage.
- Payment provider: Paddle, our authorized reseller and Merchant of Record, which processes checkout, payments, taxes, invoices, refunds, and payment compliance. Paddle processes payment data under its own privacy notice.
- AI providers: OpenAI or Google Gemini, depending on Service configuration. Relevant review text, report content, prompts, and instructions may be sent to the selected provider to produce requested analysis or drafts.
- Authentication and platform providers: including Google, Apple App Store Connect, and Google Play when you sign in or use connected store functionality.
- Communication providers: including Resend for email and Slack, Discord, or Microsoft Teams destinations selected by you. Information included in an alert, report, or business outreach message is sent to the applicable destination.
- Professional advisers and authorities: when reasonably necessary for legal, accounting, security, compliance, or dispute-resolution purposes.
- Business transfers: in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
We do not sell personal data for money. We do not share personal data for cross-context behavioral advertising as those terms are defined under applicable US state privacy laws.
6. International Data Transfers
We operate from the Republic of Korea and use providers that process data in multiple countries, including the United States and other locations where they maintain facilities. These countries may have data-protection laws different from those in your country.
Where required, we rely on recognized transfer mechanisms and contractual protections made available by us or our providers, such as adequacy decisions, standard contractual clauses, or equivalent safeguards. You may contact us for more information about safeguards relevant to your personal data.
7. Data Retention
We retain account, workspace, review, report, integration, and usage data for as long as needed to provide the Service, maintain security and continuity, comply with law, and resolve disputes. Retention depends on the type of data, the purpose of processing, customer instructions, contractual requirements, and applicable limitation periods.
Integration credentials are retained until the integration is disconnected, the workspace is deleted, or they are no longer needed. When you request deletion or an account is closed, we delete or anonymize personal data unless retention is required for legal, security, fraud-prevention, backup, or transaction record purposes. Residual copies may remain temporarily in protected backups until they are overwritten. Paddle retains transaction records under its own legal obligations and retention policy.
We retain a minimal suppression record for an email address that opts out so we can prevent future marketing messages and demonstrate compliance. We do not use a suppressed address for outreach.
Raw product-usage and essential service-state telemetry is retained for up to 400 days by default and is then deleted in bounded batches, unless a shorter period is required by law or an account-deletion request applies. Aggregated, non-identifying statistics may be retained for longer.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encrypted transport, restricted service credentials, and encryption of connected-store secrets before storage. No system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your account credentials and configuring connected accounts appropriately.
9. Your Privacy Rights
Depending on where you live, you may have the right to request access, correction, deletion, restriction, portability, or a copy of personal data; object to certain processing; withdraw consent; and appeal a decision concerning a privacy request. You may also have the right not to receive discriminatory treatment for exercising privacy rights.
Driview does not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals.
To exercise a right, email support@driviewapp.com. We may need to verify your identity and authority before completing a request. If your data was submitted by a Driview business customer, we may direct your request to that customer.
If you are in the EEA, United Kingdom, or another jurisdiction that provides this right, you may complain to your local data-protection authority. We encourage you to contact us first so we can address your concern.
10. Cookies
Driview uses cookies and similar storage that are necessary for authentication, session continuity, security, and language or interface preferences. When Google Analytics is enabled, analytics storage is denied by default and is enabled only after you allow analytics cookies. Advertising storage, advertising user data, and ad personalization remain disabled. Google Analytics may process page URLs, approximate location, browser and device information, and product-funnel events; we do not send email addresses or other directly identifying account data in those events.
Your analytics-cookie choice controls Google Analytics and browser-based product-funnel collection. It does not disable the minimal first-party service-state records described in Section 2, which are created from completed Service operations for subscription administration, reliability, and aggregate feature measurement under the legal bases described in Section 4. Those records do not use analytics cookies.
11. Children
The Service is intended for adults and business users and is not directed to anyone under 18. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.
12. Third-Party Services and Links
Third-party services and websites have their own privacy practices. This policy does not govern how Paddle, Apple, Google, messaging platforms, or other third parties process data for their own purposes.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Service, our providers, or applicable law. We will post the revised policy and update the date above. Where required, we will provide additional notice of material changes through the Service or by email.
Privacy questions and requests may be sent to support@driviewapp.com.