5 Assistant hours included freeGet started
1Thing

Legal

Privacy Policy

Last updated: May 14, 2026

Summary

This Privacy Policy explains how we collect, use, and protect your information.

1. Information We Collect: We may collect personal information such as name, email, and usage data.
2. How We Use Information: To provide, improve, and maintain our services.
3. Data Sharing: We do not sell, share, or give away your personal information or your clients’ data to any third party. Ever.
4. Security: We take reasonable measures to protect your data.
5. Your Rights: You may request access, correction, or deletion of your data.
6. Changes: We may update this policy from time to time.

See the full policy below for details.

1. Who We Are

1THING (“we”, “us”, “our”) is an AI assistant with a built-in CRM for real estate agents, operated by 1thing CRM INC., based in Ontario, Canada. Our platform is available at 1thing.ca.

This policy explains how we collect, use, and protect personal information from real estate professionals (“Users”) who sign up for our service, and from the leads and contacts that Users manage inside our platform (“Contacts”). It is written to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and equivalent privacy frameworks where applicable.

If you have any questions, contact us at privacy@1thing.ca.

2. Information We Collect

From Users (account holders)

  • Name, email address, phone number, brokerage name
  • Account credentials (passwords are hashed with bcrypt and never stored in plain text)
  • Billing information processed through Stripe. We never store card numbers.
  • Usage data: pages visited, features used, actions performed, timestamps
  • Device and browser information for security and troubleshooting
  • OAuth access and refresh tokens for any third-party integration you choose to connect (Google, Microsoft, Dialpad, RingCentral). Tokens are encrypted at rest.

From Contacts (leads and contacts Users add to the platform)

  • Name, email, phone, mailing address
  • Property interests, notes, communication history
  • Custom fields configured by the User

Contact data is entered by our Users. Users are responsible for ensuring they have the legal right to collect and store information about their Contacts under PIPEDA, CASL, or any applicable privacy law in their jurisdiction.

Usage Data

Standard server logs (IP address, browser type, pages visited, timestamps) are collected for security and performance monitoring. We do not sell this data.

3. How We Use Your Information

  • To provide, operate, and improve the 1THING platform
  • To authenticate Users and secure accounts (including two-factor authentication)
  • To process payments and manage subscriptions through Stripe
  • To sync and display your emails, calendar events, meetings, and call history inside the CRM
  • To send emails on your behalf from your connected email account, when you initiate the send
  • To create calendar events and Google Meet meeting links on your behalf, when you initiate the creation
  • To place outbound calls and handle inbound calls through your connected VoIP provider
  • To transcribe calls and voicemails via Groq, and to summarise the resulting transcript via Google (Gemini) and Anthropic (Claude), storing the transcript and summary alongside the call activity
  • To send you transactional emails (billing receipts, password resets, service notifications) and, with your opt-in, product updates
  • To detect, investigate, and prevent fraud, abuse, and security incidents
  • To comply with legal obligations

We do not sell, rent, trade, or give away your personal information or your clients' data — ever. We do not use Contact data or integration data to train machine learning models outside of your own workspace. Call audio and transcripts sent to Groq, Google and Anthropic for transcription and summarisation are not used to train those providers' models, per their respective API data-usage policies.

4. Google Integration — Specific Disclosures

If you connect a Google account, you choose which features to enable, and we request only the permissions those features need:

  • gmail.modify — read your Gmail inbox to display emails alongside CRM contacts and deals, and update message state (for example, marking a message read in the CRM marks it read in Gmail). Email metadata (sender, subject, date) and body content are stored in our database to power search and contact linking. We never permanently delete your mail.
  • gmail.send — send emails on your behalf using your Gmail account as the sender.
  • calendar.events — create, read, and update calendar events for meetings and showings scheduled in the CRM, and generate Google Meet links attached to those events.
  • contacts.readonly (optional) — read your Google address book to suggest recipients as you type. Off unless you enable it.
  • drive.file (optional) — attach Google Drive files to emails. This grants access only to the specific files you select in Google’s file picker; we cannot see or access anything else in your Drive.
  • userinfo.email — read the email address of the Google account you connect, so we can label it in the app.

We do not use Google data to serve advertisements. We do not transfer Google user data to third parties except as necessary to provide the service (our database provider). Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements.

5. Microsoft Integration — Specific Disclosures

If you connect a Microsoft account, we request equivalent permissions for Outlook email (read and send) and Outlook Calendar (create and update events). The same data handling rules as Google apply: no advertising use, no resale, no use for training machine learning models.

6. Call Recording — Built-in Calling

  • Call recordings — calls made or received through the CRM’s built-in calling feature may be recorded to create notes and summaries. Recording is chosen by the agent and can be turned off for any individual call. We do not announce the recording to the other party by default. An account owner can enable an automatic announcement, which is played to the other party before the conversation begins; agents are advised to say so themselves at the start of the call. Recordings are stored with our telephony provider (Telnyx) and referenced in the CRM for playback. Every recorded call is automatically transcribed and summarised — no agent action is required. The recording audio is sent to Groq to produce the transcript, and the resulting transcript is sent to Google (Gemini) and Anthropic (Claude) to produce the summary and suggested follow-ups. This processing occurs on servers located in the United States, so the recording audio and transcript are transferred outside Canada for this purpose. We do not create voiceprints or other biometric identifiers from call audio. Contact privacy@1thing.ca to request deletion of a recording or a transcript.

7. Dialpad and RingCentral — Specific Disclosures

If you connect a Dialpad or RingCentral account, 1THING receives call lifecycle webhooks (ringing, answered, ended) and voicemail and recording notifications. Call metadata is stored as Call Activity records. Recordings are referenced by Dialpad- or RingCentral-hosted URL and not re-hosted by 1THING. Voicemails are transcribed via Groq.

OAuth tokens for Dialpad and RingCentral are encrypted at rest and revocable at any time from Settings → Integrations in the CRM.

8. Data Storage and Security

  • Data is hosted in Supabase’s AWS infrastructure, primary region us-east-1. File attachments are stored in Supabase Storage, encrypted at rest.
  • Row-Level Security (RLS) ensures each tenant (brokerage) can only access its own data.
  • Passwords are hashed with bcrypt.
  • OAuth tokens are encrypted at rest.
  • Two-factor authentication (2FA) is available to all users via authenticator apps or email / SMS codes.
  • All data transmission uses TLS 1.2+.

9. Data Retention

We retain your account data for as long as your subscription is active. The following retention rules apply to specific data categories:

  • Account and CRM data (contacts, deals, leads, notes, activities) — retained for the life of the account. On cancellation, retained for 30 days to allow account recovery, then deleted.
  • OAuth tokens — deleted immediately on disconnect.
  • Synced email content (from Gmail or Outlook) — retained while the account is active; deleted within 30 days of integration disconnect.
  • Voicemail audio — not retained. Processed for transcription and discarded.
  • Voicemail transcripts — retained as part of the Call Activity; deleted with the activity.
  • Call recordings 12 months, then deleted. This applies to recordings made through the built-in calling feature, which are stored with Telnyx. Calls recorded through a connected third-party provider (Dialpad or RingCentral) are stored by that provider and their retention is governed by that provider's own settings. The reference to the recording is retained as part of the Call Activity.
  • Server logs — 30 days, for security and performance monitoring.
  • Audit logs and billing records — retained as long as required by law, typically seven years for financial records.

You may request deletion of your account and all associated data at any time by emailing privacy@1thing.ca or using the delete account option in Settings.

10. Third-Party Services

1THING uses the following third-party services to operate the platform. When you use these integrations, you are also subject to their respective privacy policies.

  • Supabase — database, authentication, and file storage (AWS us-east-1)
  • Vercel — application hosting, serverless function execution, and content delivery (global edge)
  • Stripe — payment processing. We never store card numbers.
  • Resend — transactional email delivery (billing receipts, password resets, notifications)
  • Twilio — SMS delivery when enabled
  • Telnyx — telephone calling and SMS through the built-in dialer, including call recording and recording storage, when enabled
  • Groq — speech-to-text for call recordings and voicemails (United States). Receives the audio.
  • Anthropic — call summaries, suggested follow-ups, and other AI writing features (United States). Receives the transcript, not the audio.
  • Google LLC — Gmail and Google Calendar integration, with your explicit OAuth consent. Google's Gemini models also generate call summaries and suggested follow-ups (United States), receiving the transcript, not the audio.
  • Microsoft Corporation — Outlook and Microsoft Calendar integration, with your explicit OAuth consent
  • Dialpad — VoIP provider, with your explicit OAuth consent
  • RingCentral — VoIP provider, with your explicit OAuth consent
  • Pusher / Supabase Realtime — real-time notifications to your browser (call banners, message delivery)

We share only the minimum data necessary for each integration to function. OAuth tokens are stored encrypted and can be revoked from your account settings at any time.

11. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and data
  • Export your data (contacts, deals, leads, activities) in a portable format
  • Object to specific processing activities
  • Revoke OAuth access to any integration at any time, either through the provider's account settings or from within 1THING Settings

To exercise any of these rights, email privacy@1thing.ca. We respond within 30 days as required by PIPEDA.

12. Cookies

We use session cookies for authentication. We do not use advertising or tracking cookies. No third-party analytics cookies are set without your consent.

13. Children's Privacy

1THING is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

14. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email or by a notice inside the platform at least 14 days before the change takes effect. Continued use of the platform after that date constitutes acceptance of the updated policy.

15. Contact

1thing CRM INC.
Ontario, Canada
Privacy requests: privacy@1thing.ca
General support: support@1thing.ca

SMS Consent — Contact Us Form: By providing a telephone number and submitting the form, you are consenting to be contacted by SMS text message and agreeing to our Privacy Policy. Message frequency may vary. Message and data rates may apply. Reply STOP to opt out of further messaging. Reply HELP for more information.