Privacy notice
OnceOnly is an app for Shopify stores. It recognises when a discount code meant to be used once per person is redeemed again by someone who has already bought — and declines it in the cart.
This notice covers two separate things: what happens when you visit this website, and what the app processes inside a merchant's store. The roles are not the same in both cases.
1. Who is responsible for what
For this website we are the controller within the meaning of Art. 4(7) GDPR. Full provider details are in the imprint.
For the data the app processes inside a merchant's store, the merchant is the controller. They decide whether to use OnceOnly and which discount codes are protected. We act as a processor under Art. 28 GDPR and only on their instructions. If you are a customer of such a store and want information about your data, please contact that store — we are not allowed to release their data on our own.
2. When you visit this website
This page sets no cookies and loads nothing from third-party servers — no fonts, no analytics, no advertising networks. There is no cookie banner because there is nothing to consent to.
Our hosting provider (see section 6) processes technically necessary connection data such as IP address, time and requested address. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in secure operation.
3. What the app processes
Data from store visitors and orders is turned into checksums; no readable data is stored. Email address, phone number, street with postcode and name, IP address and device characteristics are replaced by an irreversible value the moment they arrive (HMAC-SHA256 with a secret key kept outside the database). The original value cannot be calculated back from it.
The same person produces different checksums in two different stores. Matching across store boundaries is therefore technically impossible, not merely forbidden.
One single exception: if a merchant adds a customer to their exemption list — a wholesale buyer, a member of staff — that customer's Shopify customer number is stored in readable form. No name, no address, no email. The purpose is the opposite of recognition: nothing is checked for that person any more.
- Purpose: preventing repeated use of discount codes that are meant to work once per person.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in fraud prevention (Recital 47 names it explicitly). For reading device characteristics, additionally consent under § 25(1) TDDDG.
- No advertising, no profiling for advertising, no sharing with third parties, no sale.
- No payment data, no card details, no purchased products.
- No AI model training with this data.
4. Cookies and browser storage
The complete list. Inside a merchant's store the app sets the following; two entries for the language setting are added in our admin interface, and one on this website for the light or dark appearance:
| Name | Kind, where | Purpose | Lifetime |
|---|---|---|---|
_oo_vid | Cookie, in the store | Random visitor number. Without it the check result could not be bound to a device and could be passed on freely | 1 year |
oo_vid | Local storage, in the store | The same number, so losing the cookie does not immediately void it | until cleared |
oo_off | Local storage, in the store | A note not to ask again when the store has no paid plan. Saves requests | 1 hour |
oo_forget | Local storage, in the store | A note that a withdrawal of consent still has to be confirmed by the server. Only set when you withdraw consent — it makes sure your device characteristics are discarded even if the page reloads in the middle of it. Holds nothing but the value “1”, no identifier | until the withdrawal is confirmed |
oo_lang | Cookie, admin interface | Last language seen by the signed-in staff member | 1 year |
Language choice | Database, admin interface | The language deliberately chosen in settings, per staff member. We store Shopify's user number, never a name | until you uninstall |
oo_theme | Local storage, this website | Light or dark appearance, if you used the switch at the top. Not present unless you click it | until cleared |
_oo_token | Cart attribute, in the store | The check result itself — the signed statement of whether this cart may redeem a protected code. Contains no readable personal data | until the cart is ordered or expires |
_oo_vid | Cart attribute, in the store | The same visitor number as in the cookie. It binds the ticket to the cart so it cannot be passed on | as above |
5. How long we keep things
A daily clean-up enforces these periods automatically. They apply uniformly to every shop; individual merchants cannot extend them.
| Data | Retention |
|---|---|
Order records | 24 months from the order date |
Identity checksums | with the last order they belong to |
Visitor signals | 180 days without an update |
Receipts for processed events | 30 days |
Exemption list | until the merchant removes the entry |
All data of a store | immediately once the merchant uninstalls the app |
Data of an individual person | within 30 days of a deletion request via Shopify |
6. Who receives data
Only the providers the app cannot run without. The required processing agreements are in place with each.
The data sits on servers inside the European Union. Some of the providers themselves are based outside it. Access from a third country is therefore not ruled out, and that needs a basis under Chapter V of the GDPR. Which one applies is listed per provider below.
- Shopify (Shopify Inc., Canada) — operator of the store platform; order data comes from there. Canada is covered by an adequacy decision of the European Commission.
- Vercel (Vercel Inc., USA) — operation of this application, servers in Frankfurt. Vercel is certified under the EU-US Data Privacy Framework.
- Supabase (Supabase Inc., USA) — database, servers in Frankfurt. Supabase is not certified under the Data Privacy Framework; transfers rely on the European Commission's Standard Contractual Clauses.
- Sentry (Functional Software Inc., USA) — reporting of technical errors, so that failures surface before a merchant reports them. We use the EU data region; personal values are stripped before sending, and only what is needed for diagnosis is transmitted. Sentry is certified under the EU-US Data Privacy Framework.
- Resend (Resend Inc., USA) — delivery of our operational emails to the merchant, sent from Ireland. They contain no customer data. Resend is certified under the EU-US Data Privacy Framework.
- Resend — delivery of operational notices to merchants (for instance that protection has stopped working in their store). Only the email address from the merchant's Shopify settings and the text of the notice are transmitted; customer data never reaches this provider. The address is fetched from Shopify for the send and not stored afterwards. Merchants can turn these notices off in the app settings.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You may also complain to a supervisory authority — ours is the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen, but you may approach any authority.
If you bought from a store that uses OnceOnly, please contact that store first. They are the controller and can trigger a deletion through Shopify; we then carry it out within 30 days.
One limitation we state openly: because we store only checksums and no readable data, we cannot determine from an email enquiry alone which entries belong to you. Going through the store is therefore not convenience — it is the only way to match a request safely.
8. The automatic decline
If OnceOnly detects that a protected discount code is being used by someone who has already ordered, the code is declined and a message is shown. That decision is made automatically.
It has no legal effect and does not similarly significantly affect you within the meaning of Art. 22 GDPR: buying at the regular price remains possible at any time, no account is blocked, no order is cancelled and no payment method is refused. Only the discount is declined.
If you believe a decline is wrong, contact the store. The merchant can override it in individual cases.
9. Security
All connections are encrypted with TLS. The database and its backups are encrypted at rest as well.
The secret key used to compute the checksums lives only in the runtime environment, never in the database. That is the point that matters: anyone who got hold of the database still could not turn a checksum back into an email address.
Access to the production environment is limited to the provider and protected by two-factor authentication.
10. Changes to this notice
If what the app processes changes, we change this notice with it. It applies in the version published here at the time.
Contact
For questions about data protection: hey@diallomedia.de