OnceOnly

Data Processing Agreement

Version of 2 September 2026

This agreement governs the processing of personal data that OnceOnly carries out on behalf of your shop. It becomes part of the contract between you and us when you install the app; there is nothing to sign and nothing to send back.

If you need a signed copy for your records, write to us and we will send you one.

§ 1 Parties, subject matter and roles

The processor is David Diallo, trading as “Diallo Media”, Schwachhauser Heerstraße 18, 28209 Bremen, Germany (VAT ID DE366538188) (“OnceOnly”, “we”).

The controller is you, as the operator of the Shopify store in which OnceOnly is installed (“merchant”, “you”).

The subject matter is detecting repeat buyers who redeem a discount code you have marked as protected, and calculating how much discount has gone to repeat buyers in the past.

The division of roles is unambiguous: you decide the purposes and means of this processing. You mark the codes, you choose the protection level, you decide what happens on a detection. We carry it out.

One exception that expressly falls outside this agreement: for our own merchant records — your shop domain, the access token, your subscription — we are the controller ourselves. That is contract performance under Art. 6(1)(b) GDPR and is described in our privacy notice.

§ 2 Duration

The agreement begins when you install the app and ends when you uninstall it. After it ends, § 9 applies.

§ 3 Types of data, categories of data subjects

Data subjects are the visitors and buyers of your shop.

The decisive technical property: personal attributes are not stored in plain text. Email address, phone number, street with postcode and surname, IP address, device characteristics and visitor number are turned into irreversible checksums the moment they arrive (HMAC-SHA256 with a secret key that also takes in your shop identifier). From our records alone no person is identifiable, and the same person produces different values in two different shops.

One single exception: if you add a customer to the exemption list, that customer's Shopify customer number is stored in plain text — no name, no address, no email. The purpose is the opposite of recognition: nothing will be checked for that person from then on.

  • For detection: checksums of email address, phone number, street + postcode + surname, Shopify customer number, IP address, device characteristics and visitor number
  • For the check at checkout: additionally the first name – only as part of a checksum, so that two people at one address are not confused – and from the address line 2 and city only the digits (house number, postcode), so that an address is recognised even when fields are swapped; none of this is stored in plain text
  • For the audit: order number, order date, discount codes used, discount amount, currency
  • For the exemption list: Shopify customer number in plain text, if you add one yourself
  • Not processed: products, cart contents, payment data, addresses in plain text, country, date of birth

§ 4 Instructions

We process the data solely on your documented instructions. The settings you make in the app, together with this agreement, constitute those instructions.

Individual instructions go to the address below; we document them. If we consider an instruction unlawful, we will tell you and may suspend its execution.

Where Union or Member State law requires us to process data, we will inform you beforehand unless that law prohibits it.

§ 5 Confidentiality

Everyone with access to the data is bound to confidentiality. OnceOnly is currently operated by a single person; widening that circle does not change the obligation.

In normal operation nobody accesses your shop's data. Access happens only if you ask us for help or an incident requires it.

§ 6 Technical and organisational measures (Art. 32 GDPR)

We take the following measures. They may be developed further as long as the level of protection does not drop.

  • Pseudonymisation as the core principle: checksums with a secret key only, no raw data in the database (exception: the exemption list you maintain)
  • Encryption: TLS on every connection, encryption of the database at rest
  • Access control (accounts): a single administrator account, two-factor authentication, password manager
  • Access control (data): row-level authorisation in the database, no publicly reachable data API
  • Integrity: check tickets are signed and bound to the visitor number; incoming notices from Shopify are verified by their signature and processed idempotently
  • Availability: an outage on our side never blocks a checkout; your customers can always keep ordering. The last twelve months of order history can be restored from Shopify at any time
  • Separation: development and testing run exclusively on test data from Shopify development stores, never on data from live shops; checksums also differ per shop, which rules out any matching across shop boundaries
  • Data minimisation: of the address only street, postcode and surname; device characteristics limited to five values and only with the visitor's consent
  • Deletion: fixed retention periods, a daily automated deletion run with a log (§ 9)
  • Logging: application logs without personal values

§ 7 Sub-processors

You consent to the use of the following sub-processors. Agreements under Art. 28 GDPR are in place with all of them.

We will inform you in advance if one is added or replaced — by email to the address held in Shopify. You may object within 30 days. If you object, either party may terminate; there is no right to continue without the provider where that would make operation impossible.

All processing takes place in the European Union. Some of the providers named have parent companies in the United States; for any resulting administrative or support access, the European Commission's Standard Contractual Clauses or certification under the EU-US Data Privacy Framework apply.

ProviderServicePlace of processingNote
ShopifyPlatform, origin of all dataEU/globalAlready your own processor — covered by your Shopify agreement
SupabaseDatabaseFrankfurt, GermanyStores checksums and order figures only
VercelRunning the applicationFrankfurt, GermanyRegion set explicitly, not left at the default
SentryApplication error reportsFrankfurt, GermanyScrubbed error data only: no request bodies, no cookies, no IP addresses
ResendSending operational notices to the merchantEUNo customer data — only the merchant's email address from Shopify and the text of the notice

§ 8 Assistance with data subject rights

We assist you with requests for access, rectification, erasure, restriction, objection and data portability.

The path is built in: Shopify forwards requests to us as `customers/data_request` and `customers/redact` notices, and we handle them automatically. An erasure is carried out within 30 days.

One limit that follows from how the app is built, and that you need to know: because we store only checksums, we can provide information about a person only if you supply the raw data with the request. From our records alone nobody is identifiable. That limit belongs in your answer to the data subject.

§ 9 Deletion and return

A daily automated run deletes data after fixed periods. It is logged; the log contains no personal data.

After uninstallation we delete all of your shop's data as soon as Shopify notifies us (`shop/redact`, usually within 48 hours). There is no return of data, because in this form it would be worthless to you: checksums cannot be reversed. Your order data remains untouched in Shopify anyway.

Type of dataRetention
Order records24 months from the order date
Identity checksumswith the last related order
Visitor signals180 days without an update
Receipts for incoming notices30 days
Rate-limit counters2 hours
Exemption listno period — a setting of yours, not an observation
All data of your shopin full on uninstallation
Data of one data subjectwithin 30 days of the erasure request

§ 10 Evidence and audits

On request we demonstrate compliance with this agreement, in particular through the description of measures in § 6 and through the documentation of our sub-processors.

You may satisfy yourself of compliance. On-site audits are possible with reasonable notice, during normal business hours and without disrupting operations; they must not compromise confidentiality towards other merchants.

§ 11 Notification of breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and within 24 hours at the latest of becoming aware — with the information you need for your own notification under Art. 33 GDPR.

We also assist you with data protection impact assessments and with prior consultation of the supervisory authority, as far as our processing is concerned.

§ 12 Liability and final provisions

Art. 82 GDPR applies. In all other respects the terms of the Shopify App Store, through which you obtained OnceOnly, apply.

We will notify you of changes to this agreement 30 days in advance. If you do not object and continue to use the app, the new version is deemed accepted; if you object, you may uninstall the app and the agreement ends.

Should any provision be invalid, the remainder of the agreement stays in force.

German law applies. The exclusive place of jurisdiction is our registered seat, provided you are a merchant within the meaning of the German Commercial Code.

Contact for data protection matters

Send instructions, access requests and questions about this agreement to: hey@diallomedia.de