CaaS One
Sign in

CaaS Privacy Policy

Effective date: 17 August 2026 · Last updated: 17 August 2026

This Privacy Policy explains how CaaS Group (“CaaS”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information when you use CaaS One and other CaaS products and services that link to this policy (together, the “Services”).

We designed CaaS One as a shared identity layer for CaaS applications (for example point of sale, farm, and business management products). Please read this policy carefully. If you do not agree with it, do not use the Services.

1. Who we are

CaaS Group provides cloud software for organizations. CaaS One is our unified account platform: one sign-in for CaaS products, with organization-level administration, roles, and security controls.

For privacy questions, contact one@caas-group.com. For product support, contact one@caas-group.com.

2. Scope of this policy

This policy applies to personal information processed in connection with:

  • CaaS One (accounts, authentication, MFA, profile, organization directory, and SSO handoff to connected apps)
  • CaaS products that authenticate through CaaS One or otherwise link to this policy
  • Related websites, invite flows, password-reset flows, and support communications

If your organization has a separate agreement with CaaS (for example a master services agreement or data processing agreement), that agreement may govern additional terms for enterprise processing. Where there is a conflict for organization-managed data, the commercial agreement controls to the extent permitted by law.

This policy does not cover third-party websites or services that we do not control, including identity providers you choose to connect (such as Google), except for the limited data those providers share with us when you authorize sign-in.

3. Information we collect

The information we collect depends on how you use the Services and how your organization configures them.

Account and identity information. Name, email address, password (stored as a one-way hash), account status, language and timezone preferences, profile photo if provided, and identifiers used to link OAuth accounts (for example a Google account ID).

Organization and access information. Company, tenant, and branch associations; user type or role; app entitlements; invite tokens and invite status; and administrator-managed directory data necessary to operate multi-tenant access.

Authentication and security information. Sign-in events; multi-factor authentication (MFA) configuration (for example authenticator secrets stored securely, or email one-time codes); login attempt counters and temporary lockout state; refresh tokens and session metadata; approximate IP address and user agent associated with login or token refresh; and audit logs of security-relevant actions.

Product and usage information. App launch and SSO handoff metadata, feature usage needed to operate and improve the platform, diagnostics, and error reports.

Communications. Messages you send to support, and transactional emails we send (invites, password resets, MFA codes, security notices).

Information from third parties. If you sign in with Google or another supported provider, we receive basic profile details authorized by that provider (typically email and name, and an account identifier) to create or link your CaaS account.

We do not ask for payment card details inside CaaS One unless a specific billing feature is enabled and disclosed separately. Organization billing may be handled under separate commercial arrangements.

4. How we use information

We use personal information to:

  • Create and manage accounts, authenticate users, and provide SSO into connected CaaS apps
  • Enforce organization access controls, roles, and product entitlements
  • Provide security features such as MFA, password reset, lockout protection, and audit trails
  • Send service emails required to operate the account (invites, codes, security alerts)
  • Maintain, troubleshoot, and improve reliability, performance, and usability of the Services
  • Detect, prevent, and investigate abuse, fraud, or security incidents
  • Comply with law, respond to lawful requests, and enforce our terms and policies
  • Communicate important product or policy changes

We do not sell your personal information. We do not use CaaS One account data to serve third-party advertising.

6. Authentication and security

We implement administrative, technical, and organizational measures designed to protect personal information, including:

  • Password hashing (we do not store plaintext passwords)
  • Optional or organization-required MFA (authenticator apps and/or email one-time codes)
  • Ability to disable password sign-in when another linked method (such as Google) is available
  • Short-lived access tokens and rotatable refresh tokens
  • Transport encryption (HTTPS) for Service traffic
  • Rate limiting and temporary lockouts after repeated failed sign-in attempts
  • Audit logging of sensitive authentication and administration events

No method of transmission or storage is perfectly secure. You are responsible for keeping credentials and MFA devices confidential and for promptly notifying your administrator or CaaS if you suspect unauthorized access.

7. How we share information

We may share personal information with:

  • Your organization. Administrators can view and manage account, role, and access data for users in their scope.
  • Connected CaaS applications. When you launch or sign into a connected app through CaaS One, we share identity and entitlement information needed for that handoff.
  • Service providers. Vendors who process data on our behalf (for example hosting, email delivery, monitoring), under contractual confidentiality and security obligations.
  • Identity providers you choose. If you use Google sign-in, Google’s own privacy policy also applies to their processing.
  • Legal and safety. When required by law, or to protect the rights, safety, and security of CaaS, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, or asset sale, subject to appropriate confidentiality protections.

8. Cookies, sessions, and similar technologies

CaaS One uses cookies and similar technologies that are necessary to operate signed-in sessions, remember account chooser preferences on a device, and protect against certain attacks. These are primarily first-party, functional cookies — not advertising cookies.

You can control cookies through your browser settings. Disabling necessary cookies may prevent sign-in or cause the Services to malfunction.

9. Retention

We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type. For example:

  • Account profile data is kept while the account remains active and for a reasonable period afterward for security and audit purposes
  • One-time codes and invite/reset tokens expire automatically after a short window
  • Session and refresh tokens are revoked on logout or expire by design
  • Security and audit logs may be retained longer to investigate incidents and meet compliance needs

Organization administrators may request deactivation or deletion of user accounts subject to their policies and applicable law. Residual copies may remain in encrypted backups for a limited time until those backups rotate.

10. International transfers

We may process and store information in countries other than where you live, including where our cloud infrastructure or subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers (such as contractual protections).

11. Your rights and choices

Depending on your location and role, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information, and to receive a portable copy of data you provided. You may also have the right to lodge a complaint with a supervisory authority.

Practical choices inside CaaS One include updating profile details, managing MFA and sign-in methods (where permitted), signing out, and contacting support. If your account is managed by an organization, some requests must go through your administrator because they control the workplace account.

To exercise privacy rights, email one@caas-group.com or ask your organization administrator. We may need to verify your identity before fulfilling a request.

12. Children

The Services are built for business and organizational use. They are not directed to children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps.

13. Organization administrators

If you administer CaaS One for an organization, you are responsible for:

  • Providing appropriate notices to your users about how their workplace accounts are used
  • Configuring roles, app access, and security settings responsibly
  • Handling end-user privacy requests that relate to organization-controlled data
  • Ensuring you have a lawful basis to invite and manage users on the platform

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Effective date” / “Last updated” values above. Material changes may also be communicated through the Services or by email where appropriate. Continued use after an update constitutes acceptance of the revised policy to the extent permitted by law.

15. Contact us

For privacy inquiries or requests:

© 2026 CaaS GroupBack to sign in