What we hold, and what we do with it.
An association's software holds its members' personal details. This page says exactly what happens to them — including the parts that are structural rather than promises.
This is a plain-language document written to be read, not to be impressive. It has not yet been reviewed by a lawyer. If your board needs a counsel-reviewed agreement or a signed DPA before it can proceed, email hello@oneams.ai and we will tell you honestly where that stands rather than pointing at a badge.
1. Two different relationships
This is the distinction everything else depends on, so it comes first.
Your members’ data belongs to your association, not to us. When your association stores a member’s name, email, dues history, or committee role in OneAMS, your association decides what is collected and why. We only hold and process it on your instructions. In data-protection terms your association is the controller and we are the processor. We do not decide what to do with your members’ data, we do not use it for our own purposes, and we do not sell it, rent it, or use it to train any model.
Your own account details belong to us to manage. For the people who sign in to administer OneAMS — name, email, password hash, sign-in records — we are the controller, because we decide what is needed to run the service.
If you are a member of an association and want your data corrected or deleted, contact your association first. They control it; we act on their instruction. If they need help doing that, we will help them.
2. What we collect
Data your association puts in
Whatever your association chooses to store: member names and contact details, membership levels and status, dues and payment records, event registrations, form responses, committee rosters, volunteer hours, community posts, and the email we have sent on your behalf. The shape of this is up to you — configured forms and source records mean we cannot enumerate it exhaustively, which is precisely why the controller/processor split above matters.
Data we collect to run the service
- Account details for administrators: name, email, and a hashed password. We never store a password in a form we can read.
- Session records, so you stay signed in and can be signed out.
- Operational logs, including errors, kept to diagnose faults.
3. What we do not do
These are absences worth stating explicitly, because they are common and we have chosen against them:
- No advertising or tracking cookies. The only cookies we set are the ones that keep you signed in.
- No third-party analytics. There is no Google Analytics, no Meta pixel, and no product-analytics SDK in this application.
- No session replay. We do not record what an administrator does on screen. A replay of someone working through a member roster would ship exactly the data this page promises to protect.
- No selling or sharing data. Not to advertisers, not to data brokers, not to anyone.
- No training AI on your data. Your members’ records are not training material, ours or anyone else’s.
- No card numbers. If online payments are activated in the future, card details go from the payer’s browser to the payment provider. They do not pass through our servers and we do not store them.
4. Cookies
We use cookies for one purpose: knowing you are signed in. There is an administrator session cookie, and a separate first-party session cookie on an association’s own website for members viewing members-only pages. Both are strictly necessary for the service to work, which is why you have not been shown a consent banner asking about tracking we do not do.
5. Who else processes it
Running OneAMS means a small number of other companies may handle data. Some, such as Stripe, Anthropic, and Sentry, process data only when the corresponding capability and production configuration are enabled. This is the complete approved list as of 4 September 2026:
| Service | What it does | What it sees | Where |
|---|---|---|---|
| Vercel | Application hosting, CDN, DNS, and uploaded-file storage | All application data in transit; uploaded images and documents | United States |
| Neon | The Postgres database | All application data at rest | United States |
| Stripe | Optional payment processing when activated for an association | Payer name, email, and payment details entered directly into Stripe rather than OneAMS | United States |
| Resend | Sending email — receipts, reminders, newsletters | Recipient address, subject, and message content | United States |
| Anthropic | Optional AI-assisted report interpretation, writing, and migration mapping | Administrator prompts, draft content, column headers, and redacted samples when the feature is explicitly enabled; report answers are computed by OneAMS rather than sent as raw member datasets | United States |
| Sentry | Optional error monitoring when production credentials are configured | Scrubbed error context and stack traces; request bodies, cookies, credential headers, and direct user fields are removed before sending | United States |
A service being listed does not mean it is enabled for every association. Your launch plan can exclude optional AI or payment processing. We update this list before adding another provider that may process customer data.
Data is stored and processed in the United States. If your association is subject to UK or EU data-protection law, this is a transfer you should be aware of, and it is something to raise with us before you sign up rather than after.
6. How it is protected
Every record carries the organization that owns it, and every read is scoped to it, so one association’s data cannot be reached from another’s. Permissions are enforced on the server for every action rather than hidden in the interface. Election ballots are anonymous by database design — there is no stored link between a voter and their vote, so no query, administrator, or request to us can reconstruct one.
There is more detail on the security page, including the parts we have not built yet. We would rather tell you than let you assume.
7. How long we keep it
Your association’s data is kept for as long as the account is active, because deleting a lapsed member’s history is your decision and not ours to make. When an account is closed we keep the data for 30 days so an accidental closure can be undone, then delete it. You can export the available self-service package at any time before that — see below. Where deleted data remains in provider backups, it expires under the provider retention recorded in our current backup inventory; ask us for that evidence before launch.
A workspace owner can configure per-organization minimization windows for three operational categories: old submission and delivery technical metadata, completed migration-source payloads, and content in closed or spam inbox items. The settings screen previews what is eligible, manual cleanup requires an exact-name confirmation, and the daily lifecycle sweep enforces the saved policy. These timers do not delete core membership, accounting, signed waiver, election, governance, suppression, or append-only audit records.
8. Your data is yours
An administrator can export the core organization package — including members, memberships, invoices, payments, revenue, and selected operational records — as a ZIP of CSV files without asking us. Event registrations, election results, and some other module records export separately from their own screens. If a record type is not yet covered by a self-service path, we provide a no-fee assisted export rather than representing the package as complete.
A workspace owner can erase one person’s record from that person’s profile. The screen shows exactly what will be removed, what will be de-identified, and what the association keeps — invoices, payments, ledger entries, signed agreements, the fact that a ballot was cast, and the audit trail — before an exact-name confirmation runs it, once, irreversibly. It refuses while the person still holds a role, a live membership, or an open balance, because those are ended through their own screens. The preservation rules are our documented default; if your association’s obligations differ, tell us before the first request.
If you need a specific member’s record in a particular format or a signed data-processing agreement, email hello@oneams.ai and a person will answer.
9. Changes
If we change this in a way that affects how your data is handled, we will email account administrators before it takes effect, rather than silently updating a date at the top of the page.
10. Contact
Questions about anything on this page, or about data we hold, go to hello@oneams.ai. A person reads it, and you will get an answer from one rather than a form response.