Privacy statement

Privacy statement

This Privacy statement explains how OneClickRooms collects, uses, stores, and protects information processed through the platform. Data may include account details, organization setup information, booking records, invitee information, and technical logs needed to operate and secure the service.

OneClickRooms' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable.

We use this information to provide core features such as scheduling, approvals, notifications, reporting, and support. We may also use service data to monitor performance, improve reliability, and enhance user experience. We do not sell personal data. Where necessary to run the platform, data may be processed by trusted service providers under appropriate contractual and security controls.

Data is retained according to operational and legal requirements. For trial accounts that are not converted, data may be retained for a limited grace period and then removed under standard retention processes. We implement technical and organizational safeguards designed to protect data in transit and at rest, while acknowledging that no online system can guarantee absolute security.

Sales enquiries

When you submit a sales enquiry, we collect the name, institution, email address, phone number, designation and callback preference you provide, the product you are interested in, and any requirements you share. We use these details to respond to your enquiry and arrange follow-up. The lead is sent to [email protected] and [email protected]; we also send a confirmation email to the address you provide. The form uses Google reCAPTCHA to help prevent spam, which may process technical information under Google's Privacy Policy and Terms of Service. We retain enquiry details only as long as reasonably needed for follow-up, business records, and applicable legal requirements. We do not sell this information.

Payments and portal payment routing

OneClickRooms does not receive or store full credit-card numbers, security codes, or other complete card credentials on our application servers. If you choose to pay by card, Paddle collects the card and billing information required for checkout and securely processes the payment. Paddle is a third-party payment provider and Merchant of Record for the transaction; it may also handle payment-related customer support, refunds, chargebacks, taxes, and transaction records under its own policies.

When a student opens a portal-fee payment page from an institution's verified custom portal domain, the payment preparation request is securely transferred to edu.oneclickrooms.com, which is our approved payment host for Paddle Checkout. The student may therefore see the payment checkout hosted through edu.oneclickrooms.com even though they began on the institution's portal domain.

To preserve the payment flow, OneClickRooms uses a short-lived, server-side payment handoff containing only the information needed to associate the transaction with the correct institution, student, invoice, and verified return portal. We do not place full card details in this handoff or in payment URLs. After Paddle completes the checkout process, payment confirmation is reconciled with the relevant invoice and the student is returned to the institution's verified portal billing page. Payment confirmation is based on secure transaction processing and server-side confirmation; a browser redirect alone does not determine whether an invoice is paid.

Paddle's handling of payment and buyer information is governed by Paddle's own terms and privacy documentation. Customers should review Paddle's Privacy Policy and Paddle's Buyer Terms for details about the information Paddle collects directly during checkout and how Paddle retains and uses that information.

Third-party API integrations

OneClickRooms supports optional integrations with Google APIs, Microsoft Teams APIs, and Zoom Meeting APIs to enable room scheduling, meeting coordination, and calendar synchronization. These integrations are activated only by authorized users or administrators and can be disabled at any time from the relevant connection settings.

For each integration, we request only the permissions required to deliver the enabled features. OAuth access and refresh tokens are kept on the server, associated with the authorized account and institution, and used only for authenticated API operations requested by your organization, such as reading availability or creating and updating meeting events. Provider tokens are not placed in browser pages or URLs.

Custom-branded portal domains and secure workspace handoff

An institution may configure a verified custom or branded portal URL for its OneClickRooms education portal. A custom URL is an alternate, branded access address for the same institution account; it does not create a separate database, move the institution to a different tenant, change data ownership, or by itself copy, merge, overwrite, or delete the institution's academic, financial, user, or other records.

When an authorized user opens Profile icon > Settings > Connect Apps from a branded portal and chooses Google Meet, Microsoft Teams, or Zoom, the browser may temporarily move to the selected provider's consent page and then to OneClickRooms' canonical provider callback address. This is the normal OAuth authorization flow required by the provider's registered redirect-URI rules. OneClickRooms uses a short-lived, single-use, server-side handoff record bound to the authorized user, institution, provider, and verified return portal. The handoff restores the originating portal context; it is not a transfer of the institution's database and does not expose provider passwords or access tokens in the browser URL.

After the provider returns its authorization result, OneClickRooms validates the handoff, completes the authorization-code exchange on the server, stores the connection information in the relevant institution account, and redirects the user back to the verified branded portal's Connect Apps page. If the handoff is missing, expired, invalid, or the portal is no longer verified, the connection is rejected rather than saved. This redirect mechanism is a routing and authorization safeguard only: it does not give one institution access to another institution's data or alter the institution's existing data boundaries.

The integration can still make the provider-side changes that the authorized user requests, such as creating or updating a meeting or calendar event and saving the resulting meeting metadata with the relevant schedule. Those provider operations are separate from the portal redirect and remain subject to the connected account's permissions, provider policies, administrator controls, availability, and subscription or usage limits. The institution is responsible for controlling its custom domain, DNS, SSL configuration, authorized users, and connected provider accounts. No online service can guarantee uninterrupted availability or absolute security, and provider, DNS, certificate, network, or account-policy issues may interrupt a connection without changing the institution's stored records.

Google APIs (including Google Workspace)

When Google integration is enabled, OneClickRooms may process Google account profile metadata, calendar resource information, event details, and attendee data needed for booking and workflow features. Data obtained through Google APIs is used to provide and improve user-facing OneClickRooms functionality for your organization and is not sold to third parties.

OneClickRooms' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable.

Protection of Google API and OAuth data

Google authorization codes are exchanged by OneClickRooms' server over HTTPS/TLS. Google access and refresh tokens are stored in server-side connection records associated with the authorized account, user, and institution; they are used by server-side services to perform the authorized Google Calendar operations needed for connected scheduling. Tokens are not included in browser pages or URLs. Google API requests are sent over HTTPS/TLS, and access to a connection is checked against the relevant user and institution context. Disconnecting Google deactivates the connection so it is no longer used for new authorized API operations; Google-derived profile and schedule data already retained with existing records remains subject to the retention and deletion practices described in this statement.

OneClickRooms does not use Google Workspace API data for advertising, profiling unrelated to service delivery, or model training that is unrelated to requested platform functionality. Access to Google API data is limited to authorized services and personnel with legitimate operational need.

Google Meet in OCR for Education

OCR for Education allows each authorized Head of Department (HOD) to connect their own Google account through the Connect Apps settings. After the HOD authorizes Google Calendar access, OCR for Education can generate a Google Meet link for a class schedule using the connected account. Campus Administration can then allocate the classroom and time; the generated meeting is associated with the published schedule without requiring the schedule to be returned to the HOD.

For a published OCR for Education schedule, the Google Meet join link may be displayed in the schedule, included in schedule notification emails, and included in the attached calendar invitation (.ics) file. When the schedule date or time changes, OCR for Education may update the associated Google Calendar event where the Google API permits it. When a schedule is cancelled, OCR for Education may cancel the associated Google Calendar event where supported.

OCR for Education does not record, transcribe, monitor, or access the audio, video, chat, or other content of Google Meet sessions. Google Meet remains a Google service, and its use is governed by Google's terms and privacy policies. Disconnecting Google Meet stops new authorized API operations for that connected account, subject to necessary disconnect processing, existing schedule records, and legal or operational retention requirements.

Microsoft Teams APIs

When Microsoft 365 or Teams integration is enabled, OneClickRooms may process tenant identifiers, user profile metadata, meeting metadata, join links, and the schedule details needed to support Teams-enabled meeting workflows. This data is used only to provide integrated scheduling and communication functionality within OneClickRooms.

Microsoft Teams in OCR for Education

OCR for Education allows each authorized Head of Department (HOD) to connect their own Microsoft 365 or Microsoft Teams workspace through Connect Apps. After the HOD gives consent, OCR for Education can request a Microsoft Teams link for a class schedule using that connected workspace account. Campus Administration can then allocate the classroom and time, and the generated meeting link remains associated with the published schedule.

For a published OCR for Education schedule, the Microsoft Teams join link may be displayed in the schedule, included in schedule notification emails, and included in the attached calendar invitation (.ics) file. OCR for Education does not access, record, transcribe, monitor, or control the audio, video, chat, teaching content, or other session content of Microsoft Teams meetings.

Microsoft Teams remains a Microsoft service and is governed by Microsoft's terms, privacy policies, availability, quotas, and technical limitations. OCR for Education does not provide the Microsoft Teams service or subscription. The organization or account owner is responsible for Microsoft 365 or Teams licences, subscription charges, administrator controls, and provider terms. Disconnecting Microsoft Teams stops new authorized API operations for that connected account, subject to necessary disconnect processing, existing schedule records, and legal or operational retention requirements.

Zoom Meeting APIs

When Zoom integration is enabled, OneClickRooms may process account metadata, user identifiers, meeting IDs, passcodes (where applicable), join links, timestamps, and participant-related meeting fields required to create, manage, or synchronize Zoom meetings linked to room bookings. Zoom API data is used solely to execute requested meeting operations and maintain booking accuracy.

Protection of Zoom authentication and meeting data

Zoom OAuth access and refresh tokens are encrypted before they are saved in the server-side connection record. Depending on the server's available cryptographic extension, OneClickRooms uses libsodium's authenticated secretbox encryption or OpenSSL's authenticated AES-256-GCM encryption. Each encryption uses a randomly generated nonce or initialization vector. The encryption key is loaded from private, environment-specific server configuration outside the public web directory and is not stored in the application source repository. When an older Zoom connection contains a legacy unencrypted token, the application migrates it to encrypted storage the next time that connection is used.

Encrypted tokens are decrypted only on the server, when needed to make an authorized Zoom API request. OAuth token exchange and Zoom API communication use HTTPS/TLS. Zoom account identifiers, account email/profile details, meeting identifiers, join links, passcodes, and schedule metadata are kept server-side and access is checked through the relevant account, user, and institution context. These details are used only for the connected scheduling features and are shared with authorized users or participants when needed to manage or attend the associated meeting. OneClickRooms does not expose OAuth tokens in browser responses or URLs.

Zoom in OCR for Education

OCR for Education allows each authorized Head of Department (HOD) to connect their own Zoom account through Profile icon > Settings > Connect Apps. After the HOD gives consent, OCR for Education can create a Zoom meeting link using that connected account for a class schedule. The generated link is associated with the relevant academic schedule and can be used by the faculty and students invited to that virtual class.

For a published OCR for Education schedule, the Zoom join link may be displayed in the schedule, included in schedule notification emails, and included in the attached calendar invitation (.ics) file. OCR for Education may process only the Zoom metadata required for the requested meeting operation, such as the meeting identifier, join URL, passcode where returned, and start or end timing.

OCR for Education does not provide Zoom hosting, does not join, record, transcribe, monitor, or control the audio, video, chat, screen sharing, or other content of Zoom meetings. Zoom remains a Zoom service governed by its terms, privacy policies, availability, quotas, subscription charges, and technical limitations. The connected account owner or organization is responsible for the Zoom plan, licences, billing, administrator settings, attendee permissions, and meeting security.

When a user selects Disconnect for Zoom in Profile icon > Settings > Connect Apps, OCR deletes the saved Zoom connection record, including its OAuth access and refresh tokens, Zoom account identifiers, account email, and profile details. This prevents OCR from making further authorized Zoom API calls, but it does not revoke OneClickRooms authorization in the Zoom account. To revoke that authorization, the user must sign in to the Zoom App Marketplace, open Manage > Added Apps, find OneClickRooms, and select Remove. If Zoom later sends a deauthorization notice, OCR deletes any matching connection information that remains.

Disconnecting Zoom or removing OneClickRooms does not delete meeting links already generated and saved with classroom or exam schedules or bookings. The schedule-linked meeting records, including the join link, meeting identifier, and related metadata kept with that schedule or booking, remain associated with those records under the applicable schedule-retention practices. Emails and calendar invitations that have already been sent cannot be recalled. Because the Zoom connection information has been deleted, OCR cannot use Zoom APIs to update, reschedule, or cancel those meetings; users must manage the meetings directly in Zoom. Removing OneClickRooms does not itself delete Zoom-hosted meetings.

Retention, sharing, and user control for API data

API-sourced data is retained only as long as necessary for active booking, auditing, troubleshooting, contractual obligations, and legal compliance. When an integration is disconnected or permissions are revoked, OneClickRooms stops new API calls for that account except where needed for secure disconnect processing or required compliance actions.

We do not sell API-sourced personal data. We share such data only with subprocessors and infrastructure providers that support OneClickRooms operations under confidentiality and data protection obligations. Organization administrators may request access, correction, export, or deletion of eligible data by contacting [email protected].

User rights and request process

Subject to applicable law and organizational controls, users and organization administrators may request: (1) access to eligible personal data, (2) correction of inaccurate or incomplete data, (3) deletion of eligible data, and (4) revocation or disconnection of connected account access for integrated services such as Google, Microsoft Teams, and Zoom.

Requests can be submitted by an authorized organization administrator to [email protected]. For security, we may verify requester identity and account authority before processing. Where legal or contractual obligations apply, we will explain any limits to deletion or timing.

If your company wants data removed, contact us at [email protected] or submit a request in the portal (Support section). After a verified account-closure request, we delete the company account and associated company data from our production systems within 30 days. If immediate deletion is not possible due to legal, security, fraud-prevention, or billing obligations, we retain only the minimum required data for the required period and then delete it. For deletion-status questions, contact [email protected].

OneClickRooms uses cookies and similar session technologies in plain categories: essential session cookies (to keep users signed in and maintain secure login sessions), security cookies (to help detect abuse and protect accounts), preference cookies (to remember settings such as language or interface choices), and limited performance/analytics technologies (to understand uptime, page performance, and reliability trends). We do not use these technologies to sell personal data. Depending on applicable law and your role, you may request correction or deletion of certain data through your organization administrator or by contacting our team.

We may update this statement from time to time to reflect legal, operational, or product changes. For privacy-related requests, contact [email protected].