Skip to content
One Step Privacy Policy

One Step Privacy Policy

One Step Online Privacy Policy
Last Updated: 1/6/2026

1. Please Read Carefully

This Online Privacy Policy describes the information One Step Software Inc. (“Company”) collects about you though our website(s), mobile application, and all other services we provide (collectively, the “Services”), how we use and share that information, and the privacy choices we offer. This policy applies to information we collect when you access or use our website(s) and mobile application (collectively, the “Site”), when you use our Services or when you otherwise interact with us. This policy applies to you if you are an owner, employee, contractor, volunteer, or other workforce member of a treatment provider, sober living operator, recovery residence, or similar organization that uses our Services, or if you visit our website. Throughout this policy we call your organization “Provider” and we call your account your “Account.”

2. Changes to this Online Privacy Policy

We may change this Online Privacy Policy from time to time. If we make changes, we will notify you by posting the updated policy on our Site and revising the “Last Updated” date above. We encourage you to review the Online Privacy Policy whenever you use our Services to stay informed about our information practices and about ways you can help protect your privacy.

3. Health Information in the Services

The Services hold health information about the residents and patients you serve.

  • Where your Provider is a covered entity under HIPAA, we hold that information as your Provider’s business associate under a Business Associate Agreement, and our use, disclosure, and retention of it are governed by that agreement and by applicable law.
  • Where your Provider is not a covered entity, we hold that information under our services agreement with your Provider.

Your access to that information is logged, as described in Section 5.3. Records you create become part of your Provider’s records, and your confidentiality obligations to your Provider — and any obligations imposed on you by HIPAA, 42 C.F.R. Part 2, or state law — continue after your Account is closed.

Retention and deletion of information we hold on behalf of a Provider are governed by our agreement with that Provider and by the Provider’s instructions, as described in Sections 9 and 11.1.

4. Use of Services

Your access to and use of our Services are subject to certain terms and conditions, which are set forth in our Terms of Use.

Your access is also governed by the agreement between One Step and your Provider. Your Provider decides whether you have an Account, what you can see in it, and when your access ends.

5. Collection of Information

5.1. Information You Provide

We collect information you provide, such as when you email us, sign up through our Site, or submit information through our Site. We may collect, but are not limited to collecting, the following information: your name, gender, email address, mailing address, phone number, date of birth, employer, among other information. For staff and operators this includes your name, work email address, work phone number, job title and role, the facilities or programs you are assigned to, your professional licenses or certifications where your Provider records them, and your account credentials and multi-factor authentication enrollment. Where you or your Provider pay us directly, it also includes billing contact and payment information.

5.2. Children

Company does not knowingly collect or maintain personally identifiable information from persons under 18 years of age without verifiable parental consent, and no part of the Services are directed at persons under 18. If you are under 18 years of age, then please do not use the Services. If Company learns that personally identifiable information of persons less than 18 years of age has been collected without verifiable parental consent, then Company will take the appropriate steps to delete this information. To make such a request, please contact us as described in Section 11.1.

5.3. Information We Collect from Your Use of the Services

We collect information about you when you use our Site, including, but not limited to the following:

  • Account Information. When you register with us using the Site to create an account and become a registered user, you will need to provide us with certain personally identifiable information to complete the registration, including information that can be used to contact or identify you and credit card or other billing information in some cases.
  • Device Information. We may automatically collect certain information about the computer or devices (including mobile devices) you use to access the Services, such as IP addresses, unique device identifiers, browser types, browser language, operating system, and the state or country from which you accessed the Services; and information related to the ways in which you interact with the Services, including pages and content viewed, time spent on particular pages, the date and time and frequency of your use, and error logs.
  • Access and Audit Records. We record your authentication events, including failed sign-in attempts; the resident and patient records you view, create, modify, export, or delete; changes to your permissions and role; and security events. Your Provider can review these records. We may be required to produce them to your Provider, to a regulator, or in response to legal process. These records are retained on the schedule in Section 9.2 and are not deleted when your Account is closed.
  • Cookies and Other Electronic Technologies. We may use cookies, web beacons, site analytics services, and mobile device identifiers to keep you signed in, to customize your experience, and for analytics and fraud prevention. For more information on cookies, visit http://www.allaboutcookies.org.
  • Facility Information. We collect the information you enter about your facility location and your usage and activity on our Site.

5.4. Information from Third Parties

We may obtain additional information about you from third parties such as marketers, partners, researchers, and others. We may combine information that we collect from you with information about you that we obtain from such third parties and information derived from any other subscription, product, or service we provide.

5.5. Aggregate or De-identified Data

We may aggregate and/or de-identify information collected by the Services or via other means so that the information is not intended to identify you. Our use and disclosure of aggregated and/or de-identified information is not subject to any restrictions under this Online Privacy Policy, and we may disclose it to others without limitation for any purpose, in accordance with applicable laws and regulations. Where information is protected health information, we de-identify it only in accordance with the standard set forth at 45 C.F.R. § 164.514(b). We may retain and use de-identified and aggregated information after you close your account or after we delete other information about you, as described in Section 9.

6. Use of Information

We use the information that we collect for the purposes for which you provided it; to contact you; to fulfill your purchase and process payments; to send notifications, emails, and text messages; to provide, maintain, administer, improve, or expand the Services; to send you news and information about our Services; to track and analyze trends and usage; to prevent, detect, and investigate security breaches, fraud, and other potentially illegal or prohibited activities; to enforce the legal terms that govern your use of the Services; to protect our rights or property; to administer and troubleshoot the Services; and for any other purpose disclosed to you in connection with our Services.

We also use it to create and manage your Account and administer the permissions your Provider assigns you; to authenticate you and keep your Account secure; to create and maintain the access and audit records described in Section 5.3; to provide training, onboarding, and product guidance; to report to your Provider on usage of the Services within its organization, including your individual usage where your Provider requests it; and to comply with our obligations under our agreements with Providers, including Business Associate Agreements.

We may use third-party service providers to process and store personal information in the United States and other countries.

7. Sharing of Information

We may share personal information about you with third parties who provide, maintain, and improve our Services; with our affiliates and partners for the purposes described in this Online Privacy Policy; with affiliates, partners or other third parties so they may contact you about products, programs, services, and promotions (see the Opt-In Policy below); in connection with a merger, sale of company stock or assets, financing, acquisition, divestiture or dissolution, under non-disclosure and confidentiality protections; where we believe disclosure is reasonably necessary to comply with applicable law, regulation, legal process or governmental request, to enforce applicable user agreements or policies, to protect the security or integrity of our Services, and to protect us, our users or the public from harm or illegal activities; and with your consent. We may also share aggregated, non-personally identifiable information with third parties. We also share information about you with your Provider. Your Provider can see your Account information, your usage of the Services, and the access and audit records of your activity, and it can do so without notice to you. Disclosure of records subject to 42 C.F.R. Part 2 is additionally restricted by that regulation and is made only as Part 2 permits.

8. Opt-In Policy

When you supply us with personally identifiable information in connection with your use of the Services, you may be asked to indicate whether you are interested in receiving information from us about our product and service offerings and whether you would like us to share personally identifiable information about you with our affiliates, partners or other third parties for their marketing purposes. You may choose not to receive additional marketing information from us, or not to allow our sharing of your personally identifiable information, by following the link provided in our marketing-related email messages or by contacting us as described below. Please note that if you do opt out of receiving marketing-related messages from us, we may still send you important administrative messages, from which you cannot opt out.

9. Data Retention

9.1. Your Account information

We keep your Account information for as long as your Account is active. After it is deactivated or deleted — by you, by your Provider, or because your Provider’s subscription ends — we delete or de-identify it within 10 days, except for the categories described in Sections 9.2 through 9.4.

9.2. Security, access, and audit records

How long we keep records of your authentication events, your access to resident and patient records, and your administrative actions depends on your Provider:

  • Where your Provider is a covered entity under HIPAA, we keep these records for at least six years, consistent with the documentation retention requirement at 45 C.F.R. § 164.316(b)(2)(i) and the audit control requirement at 45 C.F.R. § 164.312(b), and for longer where your Provider’s own obligations, a legal hold, or state law require it.
  • Where your Provider is not a covered entity, no federal retention period applies to these records. We keep them for such period as our services agreement with your Provider, your Provider’s own licensing or certification obligations, and applicable state law require.

9.3. Records we hold for your Provider

Where your Provider is a covered entity, retention is governed by our Business Associate Agreement with it; on termination of that agreement we return or destroy that protected health information as the agreement requires, and where return or destruction is not feasible we extend the protections of that agreement to the information for so long as we retain it. Where your Provider is not a covered entity, we hold those records under our services agreement with it and act on its instructions.

9.4. De-identified information and legal holds

We may retain, use, and disclose de-identified and aggregated information indefinitely and without restriction, subject to Section 5.5. Where information is subject to a litigation hold, a regulatory investigation, a subpoena, or other legal process, we retain it until the hold is lifted, notwithstanding any period in this Section and notwithstanding any deletion request.

10. Security

We take reasonable measures, including administrative, technical, and physical safeguards, to help protect personal information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. Unfortunately, no data transmission over the Internet can be guaranteed to be 100% secure. As a result, while we strive to protect your information, Company cannot ensure or warrant the security of any information you transmit to us or from our online products or services, and you do so at your own risk.

11. Your Privacy Choices

11.1. How You Can Delete or Close Your Account

Your Provider’s administrator can deactivate or delete your Account from the administration settings in the Services, or by emailing help@onestepsoftware.com.

When you request deletion, we verify the request, notify your Provider, and end your access to the Services. We then delete the information we hold about you for our own purposes, subject to the exceptions in Section 9.

Verification. We will not act on a deletion request unless we are able to verify, to our satisfaction, that the request was submitted by you or by an agent you have authorized in a manner we accept. We may require additional information for this purpose, and we may decline any request we are unable to verify. Because your Provider controls your access, we may also confirm the request with your Provider before acting on it.

Timing. We will acknowledge a deletion request within 10 business days and complete it within 90 days of verifying it, or within any shorter period required by applicable law. Information held in backups is deleted on the schedule in Section 9.4.

Effect. Closing your Account is permanent and cannot be reversed. You will lose access to the Services and we will have no obligation to restore it. Residual copies may remain as described in Section 9.4. Closing your Account does not end your confidentiality obligations to your Provider or under HIPAA, 42 C.F.R. Part 2, or state law, as described in Section 3.

If your Provider’s subscription ends. We deactivate the Accounts associated with it and handle your Provider’s records as Section 9.3 describes. Your Account information is then deleted on the schedule in Section 9.1.

11.2. Cookies

Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove or reject cookies; however, our Services may not function properly if you do so.

11.3. Options for Opting out of Cookies and Mobile Device Identifiers

If you are interested in more information about interest-based advertising and how you can generally control cookies from being put on your computer to deliver tailored advertising, you may visit the Network Advertising Initiative’s Consumer Opt-Out link, the Digital Advertising Alliance’s Consumer Opt-Out link or TRUSTe’s Advertising Choices Page to opt out of receiving tailored advertising from companies that participate in those programs.

11.4. How Company Responds to Browser “Do Not Track” Signals

We do not recognize or respond to browser-initiated Do Not Track signals. For more information about DNT signals, visit http://allaboutdnt.com.

11.5. Links to Other Websites

Our Services may contain links to other websites and those websites may not follow the same privacy practices as Company. We are not responsible for the privacy practices of third party websites. We encourage you to read the privacy policies of such third parties to learn more about their privacy practices.

11.6. Your California Privacy Rights

California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of personal information disclosed to those parties. If you are a California resident and would like to request this information, please submit your request in an email to info@onestepsoftware.com.

11.7. No Rights of Third Parties

This Online Privacy Policy does not create rights enforceable by third parties.

12. How to Contact Us

Please contact us with any questions or concerns regarding this Online Privacy Policy at:

One Step Software Inc.

Email: info@onestepsoftware.com