1. Who we are and scope
This Privacy policy explains how 1591011 B.C. LTD, trading as OneProp (“we”, “us”), collects, uses, stores, shares, and protects personal data. It applies to https://oneprop.shop (the “Site”), enquiries you send us, and — at a high level — personal data processed in the licensed Software after you sign an Order. It does not apply to third-party websites we link to, or to a prop firm’s own trader-facing site that happens to run on our infrastructure: that firm publishes its own notice.
OneProp is a B2B technology provider. We do not sell funded accounts to retail traders and we do not operate this origin as a retail onboarding desk. “Personal data” and “personal information” mean information that identifies or can reasonably identify an individual.
We process personal data in accordance with applicable law, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and, where they apply, the California Consumer Privacy Act as amended by the CPRA (“CCPA”) and similar US state laws. We do not sell or rent personal data. We do not share personal data for cross-context behavioural advertising on this Site, because we do not run advertising or analytics pixels here.
If you need this notice in an accessible format, email admin@oneprop.shop.
2. Controller and processor roles
Marketing Site. For visitors and people who submit demo, trial, waitlist, or contact forms, OneProp is the controller of personal data we receive at admin@oneprop.shop. Submissions POST to this origin and are emailed to that inbox.
Licensed Software. For trader, applicant, affiliate, and staff records inside a production tenant, you (the operator) are the controller. We act as processor (or equivalent “service provider” under CCPA) on your documented instructions. A data-processing addendum can be executed with the Order and then governs that processing. See Data processing and deletion.
KYC, cards, and payouts. Identity documents, card data, and payout-rail data are typically collected by vendors you enable. Those vendors are usually your processors or independent controllers under their own terms — not processors of this marketing origin. Card data is not intended to sit on this marketing Site.
If we jointly determine purposes with another party, we will identify that arrangement in the Order or in an updated version of this policy.
3. Categories of personal data
Identity and contact
Full name; work email; telephone if you choose to send it in notes; firm or project name; role implied by the form; preferred meeting window.
Commercial and enquiry data
Launch focus (FX/CFD, futures, crypto, broker desk, creator firm, migration); free-text notes (rules, platforms, timeline); waitlist or trial preferences; records of emails with us; billing contacts and invoice details if you become a customer (account name, VAT number if supplied, payment references — not full card PAN on this Site).
Technical data
IP address, user agent, requested URL, approximate time, referrer if the browser sends one, and TLS metadata as seen by the host or CDN. Theme preference stored locally. We do not load Google Analytics, Meta Pixel, LinkedIn Insight Tag, X Pixel, or similar tags on this Site. See the Cookie and storage notice.
Security and abuse-prevention data
Honeypot field company_website (should be empty); rate-limit timestamps on forms; logs needed to investigate attacks or spam.
Software Client Data (controller: you)
Once a tenant exists, the Software may process operator seats; trader profiles; evaluation and risk events; payout records; affiliate records; contest entries; journal notes; API logs; and similar operational records you or integrations emit. We do not use that data to sell funded accounts or to train unrelated public generative models. We may use aggregated, de-identified operational metrics to improve reliability and capacity planning.
Data we do not seek on the Site
Government ID images, biometric templates, health data, precise geolocation, payment-card PAN/CVV, passwords to other services, or special-category data. Do not paste those into public forms. If you send them unsolicited, we will delete them where feasible and ask you to use an appropriate channel.
4. Sources
- Directly from you (forms, email, demo calls, contracts).
- Automatically from your device when you load the Site (server logs).
- From your organisation if a colleague names you as a billing or technical contact.
- From public business sources you ask us to review (for example a company registry extract you attach).
- Inside the Software, from you, your Authorised Users, End Users, and Third-Party Services you enable.
We may complete a form you abandon only if the data actually reached our systems; on the static Site, abandoned localStorage drafts never reach us.
5. Purposes of processing
- Respond to demo, trial, waitlist, and contact requests, and schedule walkthroughs.
- Prepare a relevant tenant configuration and commercial discussion.
- Perform contracts, including onboarding, billing, support, and security.
- Verify the contracting entity as described in the AML and KYC notice.
- Protect the Site and Software (abuse, fraud, unauthorised access, DDoS).
- Keep accounting and tax records.
- Improve the product using aggregated or de-identified insights and voluntary feedback.
- Send service messages about an enquiry or Order (outages, invoice, security).
- Send marketing about similar B2B products where law allows, with opt-out.
- Establish, exercise, or defend legal claims and comply with lawful requests.
We will not use personal data for a new purpose that is incompatible with the original purpose without a new lawful basis and, where required, notice or consent.
6. Legal bases (GDPR/UK GDPR)
Where European data-protection law applies, we rely on:
- Article 6(1)(b) contract — steps at your request toward a demo, trial, or Order, and performance of an Order (including support and billing).
- Article 6(1)(f) legitimate interests — operating a B2B website, securing it, keeping records of business enquiries, defending claims, and improving the product. We balance these interests against your rights. You may object as described below.
- Article 6(1)(a) consent — where we ask for it (certain marketing). Withdrawal does not affect prior lawful processing. You may withdraw by the unsubscribe link or by emailing us.
- Article 6(1)(c) legal obligation — tax, accounting, and responding to competent authorities where the request is binding.
We do not generally process special-category data on the Site. If an Order ever required it, we would identify an Article 9 condition in the DPA.
7. California and similar US laws
If you are a California resident, this section is a notice at collection. In the last twelve months we have collected, or may collect, the categories in section 3: identifiers (name, email, IP); commercial information (enquiry and, if you are a customer, billing); internet or electronic activity (logs, localStorage keys); and professional information (firm name, role). We collect them for the purposes in section 5. We do not collect sensitive personal information on this Site as CCPA defines it (such as government ID or precise geolocation) except if you unsolicited paste it into a form.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising on this Site. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA, because we do not collect it in the ordinary course here.
You may request to know, delete, or correct personal information, and to opt out of sale or sharing (which, for this Site, is already our practice). We will not discriminate against you for exercising rights. Submit requests to admin@oneprop.shop. We will verify you (for example by matching the email used in an enquiry). You may use an authorised agent with proof of authority. We will respond within the statutory period (generally 45 days, extendable as the statute allows).
If a similar state law applies (for example Virginia, Colorado, Connecticut, Texas), we will honour the rights that statute grants using the same contact. Appeals of a refused request may be sent to the same address with the subject “Privacy appeal”.
8. Disclosures and processors
We disclose personal data only as needed:
- Infrastructure. Static host, DNS, TLS, and CDN providers that necessarily see request logs to deliver the Site.
- Professional advisers. Counsel, accountants, and insurers under confidentiality duties.
- Authorities. When compelled by law, court order, or a valid legal process, or to protect rights, safety, or the security of the Services.
- Corporate transactions. A successor in a merger, financing, or sale, under equivalent protection, with notice where required.
- With your instruction. For example a copilot on a demo call you invite.
We do not share Site leads with other prop firms or with retail lead buyers. Form mail is written by this Site and delivered to the admin@oneprop.shop mailbox. We will name any later CRM or support tool here and in the cookie notice.
Processors we appoint for the Software are bound to follow our instructions, keep data confidential, implement appropriate security, and assist with deletion and audit rights as the DPA requires. You remain responsible for processors you contract with directly (KYC, PSP, broker, data vendor).
9. International transfers
We may process personal data outside your country, including where our hosts, contractors, or support staff operate. Those countries may not provide the same legal protections as your home country.
For personal data originating in the EEA, UK, or Switzerland, we use one or more of: an adequacy decision of the European Commission or UK Secretary of State; Standard Contractual Clauses (or the UK international data transfer addendum); and supplementary technical measures where a transfer impact assessment requires them. A copy of the relevant clauses, redacted for confidentiality, can be requested by a controller customer under a DPA.
By submitting a form you understand that your enquiry may be read by staff who are not in your country. If you do not want that, do not submit the form and contact us to arrange another channel.
10. Retention
We keep personal data only as long as needed for the purposes above, including legal, accounting, and dispute-resolution needs.
- Form submissions — emailed to admin@oneprop.shop; kept with that enquiry typically up to 12 months after last contact unless a contract or legal hold requires longer.
- Theme preference — until you change it or clear site data.
- Server logs — typically up to 90 days unless needed longer for security investigation.
- Email enquiries — while active, then typically up to 12 months after last contact, unless a contract or legal hold requires longer.
- Customer, contract, and billing records — duration of the contract plus up to 7 years (or longer if tax law requires).
- Support tickets — up to 3 years after closure.
- AML/KYC files on the contracting entity — as required by applicable record-keeping rules, often 5 years after the relationship ends.
- Client Data in a tenant — as you configure; export and deletion as in the Order and data-processing notice (request within 30 days of termination unless law requires a copy).
- Marketing suppression lists — as long as needed to honour an opt-out.
When a period ends we delete or irreversibly anonymise the data, except residual copies in encrypted backups that rotate out on the backup cycle.
11. Security
The Site uses transport encryption (TLS), a strict Content-Security-Policy, referrer policy, frame denial, sanitised form fields, and a honeypot against bulk spam. The product is designed for tenant isolation, scoped API keys, MFA on operator seats, and audit logs on risk and payouts. See Security.
Access to personal data by our personnel is limited to a need-to-know basis. We review measures as threats change. No method of transmission or storage is perfectly secure. You should not send secrets through public forms. If we become aware of a personal-data breach, we will notify the competent authority and affected individuals where law requires (including, where GDPR applies, without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable breach).
12. Your rights
Depending on your location you may have some or all of the following rights:
- Information and access — a copy of personal data we hold about you, and information about processing.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion where the law provides (the “right to be forgotten”), subject to legal retention duties.
- Restriction — limitation of processing in specified cases.
- Portability — data you provided, in a structured, commonly used, machine-readable format, where processing is automated and based on consent or contract.
- Objection — to processing based on legitimate interests, and at any time to processing for direct marketing (including related profiling).
- Withdraw consent — where consent is the basis, without affecting prior processing.
- Not to be subject to a solely automated decision producing legal or similarly significant effects, except as the law allows.
- Complain — to a supervisory authority. EEA users may contact their local authority or the authority in our EU establishment if we designate one. UK users may contact the ICO. California users may contact the California Privacy Protection Agency or the Attorney General.
Email admin@oneprop.shop with the subject “Data request”. We may need to verify your identity and may request additional information if we have reasonable doubts. We will respond within one month under GDPR (extendable by two months for complex requests, with notice). We may refuse unfounded or excessive requests, or charge a reasonable fee where the law allows. If this Site is still static-only and your only copy is in localStorage, we have no server record to retrieve — clear site data for this origin in your browser.
End Users of a licensed firm must send access or deletion requests to that firm. We will assist the operator as processor when the request is properly made and we hold the data.
Rights may be limited where we must keep data for AML, tax, or litigation, or where disclosure would adversely affect the rights of others.
13. Automated decisions
The marketing Site does not make solely automated decisions that produce legal or similarly significant effects about you. Spam filtering and honeypot checks may silently drop a submission; that is abuse prevention, not a credit or hiring decision.
Inside the Software, risk and challenge rules you configure may automatically breach or pass accounts. Those decisions are your controller activity. You are responsible for meaningful human review where your law requires it. We do not use Site enquiry data for automated profiling that produces legal effects.
14. Children
The Site and Services are for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it. Operators must not submit End User data relating to minors.
15. Marketing
We may send B2B emails about OneProp products that are similar to those you enquired about, where legitimate interests or soft-opt-in rules allow. You can opt out in any message or by emailing us. Service messages about an Order or security are not marketing and may continue while needed. We do not buy retail trader lists. We do not append marketing pixels on this Site.
16. External sites
The Site may link to brokers, terminal vendors, news, or social networks. Their privacy practices are their own. We are not responsible for content or processing on those properties. Review their policies before you submit data to them.
17. Updates and contact
We may update this policy by posting a new version with a revised date. Material changes to how we handle your data will be indicated on this page and, where we have an email for you, notified by email where practicable. Continued use of the Site after an update is acknowledgement of the revised policy, except where law requires consent.
There is no named Data Protection Officer required for this marketing Site at present. Privacy and data-subject requests: admin@oneprop.shop. If we appoint an EU or UK representative, we will publish those details here.
These documents are in English only. They describe a technology provider’s website and software licence practices. They are not legal, tax, or regulatory advice, and they are not a substitute for a signed Order or data-processing addendum. The contracting entity is 1591011 B.C. LTD, a British Columbia company trading as OneProp. A registered office, if required, is stated in the Order. Notices: admin@oneprop.shop.
Related policies
- Legal centre
- Terms of use
- Privacy policy
- Cookie and storage notice
- Legal information and disclaimers
- Acceptable use policy
- AML and KYC notice
- Data processing and deletion
- Refunds and billing
- Complaints
Questions: admin@oneprop.shop.