CaaS Privacy Policy
Effective date: 17 August 2026 · Last updated: 17 August 2026This Privacy Policy explains how CaaS Group (“CaaS”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information when you use CaaS One and other CaaS products and services that link to this policy (together, the “Services”).
We designed CaaS One as a shared identity layer for CaaS applications (for example point of sale, farm, and business management products). Please read this policy carefully. If you do not agree with it, do not use the Services.
1. Who we are
CaaS Group provides cloud software for organizations. CaaS One is our unified account platform: one sign-in for CaaS products, with organization-level administration, roles, and security controls.
For privacy questions, contact one@caas-group.com. For product support, contact one@caas-group.com.
2. Scope of this policy
This policy applies to personal information processed in connection with:
- CaaS One (accounts, authentication, MFA, profile, organization directory, and SSO handoff to connected apps)
- CaaS products that authenticate through CaaS One or otherwise link to this policy
- Related websites, invite flows, password-reset flows, and support communications
If your organization has a separate agreement with CaaS (for example a master services agreement or data processing agreement), that agreement may govern additional terms for enterprise processing. Where there is a conflict for organization-managed data, the commercial agreement controls to the extent permitted by law.
This policy does not cover third-party websites or services that we do not control, including identity providers you choose to connect (such as Google), except for the limited data those providers share with us when you authorize sign-in.
3. Information we collect
The information we collect depends on how you use the Services and how your organization configures them.
Account and identity information. Name, email address, password (stored as a one-way hash), account status, language and timezone preferences, profile photo if provided, and identifiers used to link OAuth accounts (for example a Google account ID).
Organization and access information. Company, tenant, and branch associations; user type or role; app entitlements; invite tokens and invite status; and administrator-managed directory data necessary to operate multi-tenant access.
Authentication and security information. Sign-in events; multi-factor authentication (MFA) configuration (for example authenticator secrets stored securely, or email one-time codes); login attempt counters and temporary lockout state; refresh tokens and session metadata; approximate IP address and user agent associated with login or token refresh; and audit logs of security-relevant actions.
Product and usage information. App launch and SSO handoff metadata, feature usage needed to operate and improve the platform, diagnostics, and error reports.
Communications. Messages you send to support, and transactional emails we send (invites, password resets, MFA codes, security notices).
Information from third parties. If you sign in with Google or another supported provider, we receive basic profile details authorized by that provider (typically email and name, and an account identifier) to create or link your CaaS account.
We do not ask for payment card details inside CaaS One unless a specific billing feature is enabled and disclosed separately. Organization billing may be handled under separate commercial arrangements.
4. How we use information
We use personal information to:
- Create and manage accounts, authenticate users, and provide SSO into connected CaaS apps
- Enforce organization access controls, roles, and product entitlements
- Provide security features such as MFA, password reset, lockout protection, and audit trails
- Send service emails required to operate the account (invites, codes, security alerts)
- Maintain, troubleshoot, and improve reliability, performance, and usability of the Services
- Detect, prevent, and investigate abuse, fraud, or security incidents
- Comply with law, respond to lawful requests, and enforce our terms and policies
- Communicate important product or policy changes
We do not sell your personal information. We do not use CaaS One account data to serve third-party advertising.
5. Legal bases
Where applicable data-protection law requires a legal basis (for example in the EEA/UK), we rely on one or more of the following:
- Contract / legitimate interest in providing the service — to operate accounts, SSO, and security features you or your organization request
- Legitimate interests — to secure platforms, prevent abuse, and improve reliability, balanced against your rights
- Legal obligation — where we must retain or disclose information to comply with law
- Consent — where we ask for it (for example optional marketing, if offered) and where you may withdraw it
When your organization is the controller of workplace accounts, CaaS typically acts as a processor or service provider for that organization’s instructions regarding employee or member accounts.
6. Authentication and security
We implement administrative, technical, and organizational measures designed to protect personal information, including:
- Password hashing (we do not store plaintext passwords)
- Optional or organization-required MFA (authenticator apps and/or email one-time codes)
- Ability to disable password sign-in when another linked method (such as Google) is available
- Short-lived access tokens and rotatable refresh tokens
- Transport encryption (HTTPS) for Service traffic
- Rate limiting and temporary lockouts after repeated failed sign-in attempts
- Audit logging of sensitive authentication and administration events
No method of transmission or storage is perfectly secure. You are responsible for keeping credentials and MFA devices confidential and for promptly notifying your administrator or CaaS if you suspect unauthorized access.
9. Retention
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type. For example:
- Account profile data is kept while the account remains active and for a reasonable period afterward for security and audit purposes
- One-time codes and invite/reset tokens expire automatically after a short window
- Session and refresh tokens are revoked on logout or expire by design
- Security and audit logs may be retained longer to investigate incidents and meet compliance needs
Organization administrators may request deactivation or deletion of user accounts subject to their policies and applicable law. Residual copies may remain in encrypted backups for a limited time until those backups rotate.
10. International transfers
We may process and store information in countries other than where you live, including where our cloud infrastructure or subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers (such as contractual protections).
11. Your rights and choices
Depending on your location and role, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information, and to receive a portable copy of data you provided. You may also have the right to lodge a complaint with a supervisory authority.
Practical choices inside CaaS One include updating profile details, managing MFA and sign-in methods (where permitted), signing out, and contacting support. If your account is managed by an organization, some requests must go through your administrator because they control the workplace account.
To exercise privacy rights, email one@caas-group.com or ask your organization administrator. We may need to verify your identity before fulfilling a request.
12. Children
The Services are built for business and organizational use. They are not directed to children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
13. Organization administrators
If you administer CaaS One for an organization, you are responsible for:
- Providing appropriate notices to your users about how their workplace accounts are used
- Configuring roles, app access, and security settings responsibly
- Handling end-user privacy requests that relate to organization-controlled data
- Ensuring you have a lawful basis to invite and manage users on the platform
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Effective date” / “Last updated” values above. Material changes may also be communicated through the Services or by email where appropriate. Continued use after an update constitutes acceptance of the revised policy to the extent permitted by law.
15. Contact us
For privacy inquiries or requests:
- Privacy: one@caas-group.com
- Support: one@caas-group.com
- Web: this page at /privacy (public — no sign-in required)