Privacy Policy

Effective August 10, 2026 · Last updated August 10, 2026

This explains what we collect, why we have it, who else touches it, and how long we keep it. It is written to be read, not to be survived.

Who is responsible. DoneOnce is a service of IFENCEPRO LLC, a Florida limited liability company (Florida document number L24000385104), operating under the registered fictitious name “DoneOnce”. Questions about this policy go to hello@doneonce.app.

1. Two different kinds of data

This distinction runs through the whole policy, so it comes first.

Data about you, our customer. You signed up, you pay us, and we decide what we need in order to run the service for you. For this data we are the one responsible.

Data about your customers. Your client book, their addresses, their job history, what they owe. You decided to collect it and you decide what happens to it. We hold and process it on your instructions, to run the service you are paying for — nothing else. If one of your customers wants to see, correct or delete their data, the request belongs to you; write to us and we will help you carry it out.

2. What we collect

Because you gave it to us

Because the service produced it

What we do not collect

We do not ask for and do not want government identification numbers, health information, or anything about children. We never see or store card numbers — those go directly to Stripe, which is why they are not ours to lose.

3. Why we have it

We do not sell your data or your customers’ data. We do not share it with advertisers, we do not use it to build profiles, and we do not market to the people in your client book.

4. Who else touches it

Running the service means using other companies. Each is bound to handle the data only to provide their service to us. This is the complete list:

ProviderWhat it doesWhere
SupabaseDatabase, sign-in and the server functions that hold all application dataUnited States
RailwayHosting for the application and this websiteUnited States
StripeSubscription billing, and the payments your own customers make to youUnited States
ResendDelivery of transactional email — estimates, receipts, remindersUnited States
TwilioText messaging, where it is enabled for an accountUnited States
OpenStreetMap (Nominatim)Converts a service address into map coordinatesEuropean Union

We may also disclose data if the law requires it, to enforce our terms, or to protect the rights and safety of our users. If a business changes hands, data may transfer with it — we would tell you before that happened.

5. Messages to your customers

When DoneOnce emails or texts one of your customers, it does so on your behalf, as your business. The permission to contact that person is yours to obtain and yours to honor when it is withdrawn.

Today, payment reminders and autopay notices are sent by email only. Text messaging is not used for them, and will not start silently: it requires both an approved messaging registration and a recorded opt-in.

6. How long we keep it

7. Your rights

Depending on where you live, you may have the right to see the data we hold about you, correct it, delete it, take a copy elsewhere, or object to some uses of it. Florida, other US states and other countries grant different rights; we apply them where they apply to you.

To exercise any of them, write to hello@doneonce.app. We will answer within 30 days. We will not charge you for asking and we will not treat you differently for having asked.

If the request concerns data about one of your customers, it comes to you first — you are the one who decided to collect it. We will help you answer it.

8. Security

Data is encrypted in transit. Passwords are stored hashed. Access to production data is limited to the people who need it to operate the service. Every read and write passes through server-side functions that check who is asking before answering — the browser is never handed a key that can reach the database directly.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your data, we will tell you promptly and tell you what we know.

9. Children

DoneOnce is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, write to us and we will remove it.

10. Where your data lives

We operate from the United States and our providers store data primarily there, with geocoding handled in the European Union. If you use DoneOnce from outside the United States, you are sending your data to the United States, where privacy law differs from your own.

11. Changes to this policy

We may update this policy. If a change materially affects how we handle your data, we will notify you by email before it takes effect. The date at the top always reflects the current version.

12. Contact

IFENCEPRO LLC, d/b/a DoneOnce
Port Saint Lucie, Florida
United States

Email: hello@doneonce.app