PRIVACY
Your address is personal.
OnceAsk is built around recipient-controlled mailing addresses and explicit permission. This policy explains what data the service processes and when an address may be shared or used for delivery.
What OnceAsk processes
Depending on how you use OnceAsk, the service may process account details, contacts you import or create, mailing addresses submitted or confirmed by recipients, permission choices, API-key and integration metadata, fulfillment records, and technical logs needed to operate and secure the service.
Recipients may also create or claim a live mailing-address profile so they can keep an address current and control future use.
How addresses are used
OnceAsk uses mailing-address data to provide the features a user or recipient requests: confirming an address, maintaining a live address, applying a permission grant, resolving an authorized delivery, and sending an authorized physical item through a fulfillment provider.
A contact record by itself is not treated as permission for private delivery. When OnceAsk requires recipient permission or a current address, the service routes the recipient through a confirmation flow before issuing a private-delivery capability.
When data is shared
If a recipient chooses to share an address directly, the authorized OnceAsk user may receive that address according to the permission selected. If a recipient chooses private delivery, OnceAsk can send the destination server-to-server to a supported fulfillment provider without returning the street address to the requesting agent or application.
OnceAsk may also use service providers that help operate the product, such as hosting, authentication, email, payment, analytics, or fulfillment services. Those providers receive information only as needed for the service they perform. Information may also be disclosed when required by law, to protect the service or its users, or as part of a business transaction subject to appropriate safeguards.
What OnceAsk does not do
OnceAsk does not make a recipient's street address public. OnceAsk does not sell mailing addresses. Private-delivery mode is designed so the requesting agent or application can complete an authorized delivery without receiving the recipient's street address.
Users who deliberately grant broader API scopes, export contacts, or choose direct address sharing can cause data to leave the private-delivery path. Those actions are separate from the default private-delivery flow.
Your choices
You can update your mailing address, review who has access from My address, and revoke future access at any time. A recipient can choose a one-time share, ongoing address sharing, or private delivery when those options are offered.
OnceAsk keeps active account, contact, permission, and address-profile data while an account or permission remains active and as needed to provide the requested service. Short-lived OAuth authorization codes expire within minutes; OAuth access tokens expire on a short schedule and refresh tokens are rotated or revoked when a connection is disconnected. Delivery and fulfillment records, security logs, and transaction records may be retained for a limited period after completion when needed for fraud prevention, support, accounting, dispute resolution, or legal compliance.
When a user requests deletion, OnceAsk will delete or de-identify personal data that is no longer required for an active service, security purpose, transaction record, dispute, or legal obligation. Backup copies may persist for a limited period before being overwritten. Requests to correct or delete personal data can be made through the public support page.
Security and changes
OnceAsk uses technical and organizational measures intended to protect account and address data. No internet service can guarantee absolute security, so users should protect account credentials and API keys and grant only the access they need.
This policy may be updated as the product changes. Material changes will be reflected on this page. Effective September 8, 2026.