Data Processing Agreement (DPA) — OneStore

Last updated: May 31, 2026

Version française →

This page summarizes OneStore's Data Processing Agreement (DPA) for enterprise customers who need a written contract under GDPR Article 28. OneStore is published by Karei Studio. For a signed PDF based on the European Commission Standard Contractual Clauses (controller → processor module), email support@onestore.so.

Data controller and processor roles

When you use OneStore to manage App Store and Google Play listings, you remain the data controller for the app metadata, review data, and any personal data contained in your store content. OneStore acts as a data processor and processes personal data only on your documented instructions — to sync listings, publish releases, store encrypted credentials, and deliver the features you enable in your workspace.

This DPA defines each party's obligations under Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. OneStore does not use customer workspace data for advertising or unrelated profiling. Where OneStore determines purposes for account sign-up, billing, or site analytics, it acts as an independent controller — see our privacy policy for those flows.

Scope of processing

Processing is limited to what is strictly necessary to operate the app store management platform. Categories typically include: account identifiers (email, name from OAuth), workspace membership and roles, App Store and Google Play listing metadata, screenshots and visual assets, release notes, review text and replies, encrypted Apple .p8 keys and Google service account credentials, temporarily stored binaries (.ipa, .aab), support messages, and technical logs (IP address, user-agent, timestamps) for security and troubleshooting.

Purposes include authentication, metadata synchronization, publication to Apple and Google APIs, subscription billing via Stripe, transactional email, error monitoring, optional AI-assisted review replies (Anthropic), and product analytics where consent or contract applies. Processing locations may include the EU and the United States; cross-border transfers rely on EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

What the full DPA includes

  • Description of processing activities and data categories listed above.
  • Technical and organizational measures (Article 32 GDPR): encryption, access control, audit logging.
  • Authorised sub-processors and a 30-day prior notice for changes.
  • Breach notification to the controller without undue delay and within 72 hours where feasible (Article 33 GDPR).
  • Assistance with data subject requests (Article 28(3)(e)) and data protection impact assessments where required.
  • Deletion or return of personal data at end of service, subject to legal retention obligations.

Data retention

Retention follows the schedules in our privacy policy and the signed DPA. In summary: account and workspace data is kept for the contract term and deleted or anonymized within 30 days after account closure. Store credentials remain until you revoke them or delete the workspace. Uploaded binaries are retained only as long as needed for delivery and troubleshooting — typically a few days. Technical logs are kept 30 to 90 days. Billing records may be retained for statutory accounting periods (typically up to 10 years where required).

Security measures

OneStore implements measures appropriate to the risk under Article 32 GDPR. Store credentials are encrypted at rest with AES-256-GCM at the application layer; credentials are decrypted only to perform actions you request. All traffic uses HTTPS (TLS 1.2+). Access within a workspace is role-based (OWNER, ADMIN, MEMBER) with least privilege. Sensitive actions are recorded in an audit log. Production infrastructure runs on Vercel and Neon; files and binaries are stored on Cloudflare R2. See our security page for encryption details and responsible disclosure via security@onestore.so.

Sub-processors

OneStore uses the following sub-processors to deliver the service. Each is bound by data processing terms consistent with Article 28 GDPR. Enterprise customers receive 30 days' notice before any new sub-processor is engaged.

ProviderPurposeLocation
VercelApplication hostingUS / EU
NeonPostgreSQL databaseEU / US
Cloudflare R2File and binary storageGlobal
StripePayments and subscriptionsUS / EU
ResendTransactional emailUS
UpstashQueues and scheduled jobsUS / EU
PostHogProduct analytics (with consent)US / EU
SentryError monitoringUS / EU
AnthropicAI text generationUS

Data subject rights

Data subjects (for example, users whose data appears in reviews you manage) may exercise GDPR rights — access, rectification, erasure, restriction, portability, and objection — against you as controller. OneStore will assist you in responding to such requests within a reasonable timeframe, as set out in the DPA and Article 28(3)(e). If a request concerns your OneStore account directly, contact support@onestore.so. We respond within 48 business hours.

Breach notification and assistance

If OneStore becomes aware of a personal data breach affecting data processed on your behalf, we will notify you without undue delay and, where feasible, within 72 hours, with information to help you meet your obligations under Articles 33 and 34 GDPR. We will cooperate with supervisory authorities and provide reasonable assistance for impact assessments where required by law.

Contact

DPA and privacy inquiries: support@onestore.so (Karei Studio, Paris, France). Security vulnerabilities: security@onestore.so. Questions about this DPA? Contact our team or visit our About page to learn more about OneStore.

Frequently asked questions

What data does OneStore process under its DPA?
OneStore processes account and workspace data, App Store and Google Play listing metadata, screenshots, release notes, review data, encrypted store credentials, and temporarily stored binaries (.ipa, .aab) strictly to deliver app store management and sync services on your instructions.
Is OneStore a data controller or processor?
For customer workspace and store content, OneStore acts as a data processor under GDPR Article 28. You, the customer, remain the data controller for the app listings and related personal data you upload or sync through OneStore.
How long does OneStore retain data processed under the DPA?
Account and workspace data is kept for the duration of the contract and deleted or anonymized within 30 days after closure. Store credentials are kept until revoked. Uploaded binaries are retained only as long as needed for delivery (typically a few days). Technical logs are kept 30 to 90 days.
How do I get a signed OneStore DPA?
Email support@onestore.so to request the full Data Processing Agreement based on the EU Standard Contractual Clauses (controller-to-processor module). We provide a PDF for enterprise customers and notify you 30 days before adding any new sub-processor.

OneStore — published by Karei Studio. About · Contact · Privacy policy · Terms