Data Processing Agreement
Version of 2 September 2026
This agreement governs the processing of personal data that OnceOnly carries out on behalf of your shop. It becomes part of the contract between you and us when you install the app; there is nothing to sign and nothing to send back.
If you need a signed copy for your records, write to us and we will send you one.
§ 1 Parties, subject matter and roles
The processor is David Diallo, trading as “Diallo Media”, Schwachhauser Heerstraße 18, 28209 Bremen, Germany (VAT ID DE366538188) (“OnceOnly”, “we”).
The controller is you, as the operator of the Shopify store in which OnceOnly is installed (“merchant”, “you”).
The subject matter is detecting repeat buyers who redeem a discount code you have marked as protected, and calculating how much discount has gone to repeat buyers in the past.
The division of roles is unambiguous: you decide the purposes and means of this processing. You mark the codes, you choose the protection level, you decide what happens on a detection. We carry it out.
One exception that expressly falls outside this agreement: for our own merchant records — your shop domain, the access token, your subscription — we are the controller ourselves. That is contract performance under Art. 6(1)(b) GDPR and is described in our privacy notice.
§ 2 Duration
The agreement begins when you install the app and ends when you uninstall it. After it ends, § 9 applies.
§ 3 Types of data, categories of data subjects
Data subjects are the visitors and buyers of your shop.
The decisive technical property: personal attributes are not stored in plain text. Email address, phone number, street with postcode and surname, IP address, device characteristics and visitor number are turned into irreversible checksums the moment they arrive (HMAC-SHA256 with a secret key that also takes in your shop identifier). From our records alone no person is identifiable, and the same person produces different values in two different shops.
One single exception: if you add a customer to the exemption list, that customer's Shopify customer number is stored in plain text — no name, no address, no email. The purpose is the opposite of recognition: nothing will be checked for that person from then on.
- For detection: checksums of email address, phone number, street + postcode + surname, Shopify customer number, IP address, device characteristics and visitor number
- For the check at checkout: additionally the first name – only as part of a checksum, so that two people at one address are not confused – and from the address line 2 and city only the digits (house number, postcode), so that an address is recognised even when fields are swapped; none of this is stored in plain text
- For the audit: order number, order date, discount codes used, discount amount, currency
- For the exemption list: Shopify customer number in plain text, if you add one yourself
- Not processed: products, cart contents, payment data, addresses in plain text, country, date of birth
§ 4 Instructions
We process the data solely on your documented instructions. The settings you make in the app, together with this agreement, constitute those instructions.
Individual instructions go to the address below; we document them. If we consider an instruction unlawful, we will tell you and may suspend its execution.
Where Union or Member State law requires us to process data, we will inform you beforehand unless that law prohibits it.
§ 5 Confidentiality
Everyone with access to the data is bound to confidentiality. OnceOnly is currently operated by a single person; widening that circle does not change the obligation.
In normal operation nobody accesses your shop's data. Access happens only if you ask us for help or an incident requires it.
§ 6 Technical and organisational measures (Art. 32 GDPR)
We take the following measures. They may be developed further as long as the level of protection does not drop.
- Pseudonymisation as the core principle: checksums with a secret key only, no raw data in the database (exception: the exemption list you maintain)
- Encryption: TLS on every connection, encryption of the database at rest
- Access control (accounts): a single administrator account, two-factor authentication, password manager
- Access control (data): row-level authorisation in the database, no publicly reachable data API
- Integrity: check tickets are signed and bound to the visitor number; incoming notices from Shopify are verified by their signature and processed idempotently
- Availability: an outage on our side never blocks a checkout; your customers can always keep ordering. The last twelve months of order history can be restored from Shopify at any time
- Separation: development and testing run exclusively on test data from Shopify development stores, never on data from live shops; checksums also differ per shop, which rules out any matching across shop boundaries
- Data minimisation: of the address only street, postcode and surname; device characteristics limited to five values and only with the visitor's consent
- Deletion: fixed retention periods, a daily automated deletion run with a log (§ 9)
- Logging: application logs without personal values
§ 7 Sub-processors
You consent to the use of the following sub-processors. Agreements under Art. 28 GDPR are in place with all of them.
We will inform you in advance if one is added or replaced — by email to the address held in Shopify. You may object within 30 days. If you object, either party may terminate; there is no right to continue without the provider where that would make operation impossible.
All processing takes place in the European Union. Some of the providers named have parent companies in the United States; for any resulting administrative or support access, the European Commission's Standard Contractual Clauses or certification under the EU-US Data Privacy Framework apply.
| Provider | Service | Place of processing | Note |
|---|---|---|---|
| Shopify | Platform, origin of all data | EU/global | Already your own processor — covered by your Shopify agreement |
| Supabase | Database | Frankfurt, Germany | Stores checksums and order figures only |
| Vercel | Running the application | Frankfurt, Germany | Region set explicitly, not left at the default |
| Sentry | Application error reports | Frankfurt, Germany | Scrubbed error data only: no request bodies, no cookies, no IP addresses |
| Resend | Sending operational notices to the merchant | EU | No customer data — only the merchant's email address from Shopify and the text of the notice |
§ 8 Assistance with data subject rights
We assist you with requests for access, rectification, erasure, restriction, objection and data portability.
The path is built in: Shopify forwards requests to us as `customers/data_request` and `customers/redact` notices, and we handle them automatically. An erasure is carried out within 30 days.
One limit that follows from how the app is built, and that you need to know: because we store only checksums, we can provide information about a person only if you supply the raw data with the request. From our records alone nobody is identifiable. That limit belongs in your answer to the data subject.
§ 9 Deletion and return
A daily automated run deletes data after fixed periods. It is logged; the log contains no personal data.
After uninstallation we delete all of your shop's data as soon as Shopify notifies us (`shop/redact`, usually within 48 hours). There is no return of data, because in this form it would be worthless to you: checksums cannot be reversed. Your order data remains untouched in Shopify anyway.
| Type of data | Retention |
|---|---|
| Order records | 24 months from the order date |
| Identity checksums | with the last related order |
| Visitor signals | 180 days without an update |
| Receipts for incoming notices | 30 days |
| Rate-limit counters | 2 hours |
| Exemption list | no period — a setting of yours, not an observation |
| All data of your shop | in full on uninstallation |
| Data of one data subject | within 30 days of the erasure request |
§ 10 Evidence and audits
On request we demonstrate compliance with this agreement, in particular through the description of measures in § 6 and through the documentation of our sub-processors.
You may satisfy yourself of compliance. On-site audits are possible with reasonable notice, during normal business hours and without disrupting operations; they must not compromise confidentiality towards other merchants.
§ 11 Notification of breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and within 24 hours at the latest of becoming aware — with the information you need for your own notification under Art. 33 GDPR.
We also assist you with data protection impact assessments and with prior consultation of the supervisory authority, as far as our processing is concerned.
§ 12 Liability and final provisions
Art. 82 GDPR applies. In all other respects the terms of the Shopify App Store, through which you obtained OnceOnly, apply.
We will notify you of changes to this agreement 30 days in advance. If you do not object and continue to use the app, the new version is deemed accepted; if you object, you may uninstall the app and the agreement ends.
Should any provision be invalid, the remainder of the agreement stays in force.
German law applies. The exclusive place of jurisdiction is our registered seat, provided you are a merchant within the meaning of the German Commercial Code.
Contact for data protection matters
Send instructions, access requests and questions about this agreement to: hey@diallomedia.de