OnceOnly

Privacy notice

OnceOnly is an app for Shopify stores. It recognises when a discount code meant to be used once per person is redeemed again by someone who has already bought — and declines it in the cart.

This notice covers two separate things: what happens when you visit this website, and what the app processes inside a merchant's store. The roles are not the same in both cases.

1. Who is responsible for what

For this website we are the controller within the meaning of Art. 4(7) GDPR. Full provider details are in the imprint.

For the data the app processes inside a merchant's store, the merchant is the controller. They decide whether to use OnceOnly and which discount codes are protected. We act as a processor under Art. 28 GDPR and only on their instructions. If you are a customer of such a store and want information about your data, please contact that store — we are not allowed to release their data on our own.

2. When you visit this website

This page sets no cookies and loads nothing from third-party servers — no fonts, no analytics, no advertising networks. There is no cookie banner because there is nothing to consent to.

Our hosting provider (see section 6) processes technically necessary connection data such as IP address, time and requested address. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in secure operation.

3. What the app processes

Data from store visitors and orders is turned into checksums; no readable data is stored. Email address, phone number, street with postcode and name, IP address and device characteristics are replaced by an irreversible value the moment they arrive (HMAC-SHA256 with a secret key kept outside the database). The original value cannot be calculated back from it.

The same person produces different checksums in two different stores. Matching across store boundaries is therefore technically impossible, not merely forbidden.

One single exception: if a merchant adds a customer to their exemption list — a wholesale buyer, a member of staff — that customer's Shopify customer number is stored in readable form. No name, no address, no email. The purpose is the opposite of recognition: nothing is checked for that person any more.

  • Purpose: preventing repeated use of discount codes that are meant to work once per person.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest in fraud prevention (Recital 47 names it explicitly). For reading device characteristics, additionally consent under § 25(1) TDDDG.
  • No advertising, no profiling for advertising, no sharing with third parties, no sale.
  • No payment data, no card details, no purchased products.
  • No AI model training with this data.

4. Cookies and browser storage

The complete list. Inside a merchant's store the app sets the following; two entries for the language setting are added in our admin interface, and one on this website for the light or dark appearance:

NameKind, wherePurposeLifetime
_oo_vidCookie, in the storeRandom visitor number. Without it the check result could not be bound to a device and could be passed on freely1 year
oo_vidLocal storage, in the storeThe same number, so losing the cookie does not immediately void ituntil cleared
oo_offLocal storage, in the storeA note not to ask again when the store has no paid plan. Saves requests1 hour
oo_forgetLocal storage, in the storeA note that a withdrawal of consent still has to be confirmed by the server. Only set when you withdraw consent — it makes sure your device characteristics are discarded even if the page reloads in the middle of it. Holds nothing but the value “1”, no identifieruntil the withdrawal is confirmed
oo_langCookie, admin interfaceLast language seen by the signed-in staff member1 year
Language choiceDatabase, admin interfaceThe language deliberately chosen in settings, per staff member. We store Shopify's user number, never a nameuntil you uninstall
oo_themeLocal storage, this websiteLight or dark appearance, if you used the switch at the top. Not present unless you click ituntil cleared
_oo_tokenCart attribute, in the storeThe check result itself — the signed statement of whether this cart may redeem a protected code. Contains no readable personal datauntil the cart is ordered or expires
_oo_vidCart attribute, in the storeThe same visitor number as in the cookie. It binds the ticket to the cart so it cannot be passed onas above

5. How long we keep things

A daily clean-up enforces these periods automatically. They apply uniformly to every shop; individual merchants cannot extend them.

DataRetention
Order records24 months from the order date
Identity checksumswith the last order they belong to
Visitor signals180 days without an update
Receipts for processed events30 days
Exemption listuntil the merchant removes the entry
All data of a storeimmediately once the merchant uninstalls the app
Data of an individual personwithin 30 days of a deletion request via Shopify

6. Who receives data

Only the providers the app cannot run without. The required processing agreements are in place with each.

The data sits on servers inside the European Union. Some of the providers themselves are based outside it. Access from a third country is therefore not ruled out, and that needs a basis under Chapter V of the GDPR. Which one applies is listed per provider below.

  • Shopify (Shopify Inc., Canada) — operator of the store platform; order data comes from there. Canada is covered by an adequacy decision of the European Commission.
  • Vercel (Vercel Inc., USA) — operation of this application, servers in Frankfurt. Vercel is certified under the EU-US Data Privacy Framework.
  • Supabase (Supabase Inc., USA) — database, servers in Frankfurt. Supabase is not certified under the Data Privacy Framework; transfers rely on the European Commission's Standard Contractual Clauses.
  • Sentry (Functional Software Inc., USA) — reporting of technical errors, so that failures surface before a merchant reports them. We use the EU data region; personal values are stripped before sending, and only what is needed for diagnosis is transmitted. Sentry is certified under the EU-US Data Privacy Framework.
  • Resend (Resend Inc., USA) — delivery of our operational emails to the merchant, sent from Ireland. They contain no customer data. Resend is certified under the EU-US Data Privacy Framework.
  • Resend — delivery of operational notices to merchants (for instance that protection has stopped working in their store). Only the email address from the merchant's Shopify settings and the text of the notice are transmitted; customer data never reaches this provider. The address is fetched from Shopify for the send and not stored afterwards. Merchants can turn these notices off in the app settings.

7. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You may also complain to a supervisory authority — ours is the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen, but you may approach any authority.

If you bought from a store that uses OnceOnly, please contact that store first. They are the controller and can trigger a deletion through Shopify; we then carry it out within 30 days.

One limitation we state openly: because we store only checksums and no readable data, we cannot determine from an email enquiry alone which entries belong to you. Going through the store is therefore not convenience — it is the only way to match a request safely.

8. The automatic decline

If OnceOnly detects that a protected discount code is being used by someone who has already ordered, the code is declined and a message is shown. That decision is made automatically.

It has no legal effect and does not similarly significantly affect you within the meaning of Art. 22 GDPR: buying at the regular price remains possible at any time, no account is blocked, no order is cancelled and no payment method is refused. Only the discount is declined.

If you believe a decline is wrong, contact the store. The merchant can override it in individual cases.

9. Security

All connections are encrypted with TLS. The database and its backups are encrypted at rest as well.

The secret key used to compute the checksums lives only in the runtime environment, never in the database. That is the point that matters: anyone who got hold of the database still could not turn a checksum back into an email address.

Access to the production environment is limited to the provider and protected by two-factor authentication.

10. Changes to this notice

If what the app processes changes, we change this notice with it. It applies in the version published here at the time.

Contact

For questions about data protection: hey@diallomedia.de