OneFee privacy policy
Draft for legal review, not legal advice. Last updated: 25 September 2026.
Who we are
OneFee is a Shopify app operated by MetaOne, Leon Eikmeier, Timmerbergstraße 48, 32602 Vlotho, Germany. Contact: support@meta-one.de, phone +49 175 8790619.
What OneFee does
OneFee adds the bottle and can deposit to drinks in the checkout of Shopify stores, shows it in the storefront and reports the deposit collected. This policy explains which data OneFee processes when a merchant installs the app.
Data we process
We process data of the merchant's store only as far as needed to provide the app:
- Store: shop domain, country, currency, the deposit tax setting, the plan of the app subscription, and the access token that Shopify issues to the app (stored encrypted).
- Settings and rules: the merchant's deposit rules, deposit rates, display settings and the state of background jobs.
- Product data: product and variant IDs, titles, descriptions, handles, tags, collections, SKUs, image URLs and the deposit assignment per product, read to suggest and apply deposit rules.
- Order data for the deposit report: for each order line that contains a deposit: order ID, order number, line item ID, date, deposit rate, quantity, amounts and tax, and the product the deposit belongs to.
OneFee does not store customer data: no names, e-mail addresses, postal addresses, phone numbers or payment data of the store's customers. The order webhook is filtered to line item amounts; customer fields are not delivered to the app.
Purpose and legal basis
We process this data to provide the app to the merchant under the contract for the app (Art. 6(1)(b) GDPR). For the order data of the store's customers we act as processor on behalf of the merchant (Art. 28 GDPR), under the Shopify Partner Program terms and the Shopify API License and Terms of Use.
Where the data is stored
- Vercel Inc. runs the app servers in the Frankfurt region (EU).
- Neon Inc. runs the database in the Frankfurt region (AWS eu-central-1, EU).
- Shopify hosts the store data itself; OneFee writes the deposit product, deposit metafields and settings to the merchant's store through the Shopify Admin API.
Vercel and Neon are US companies. Transfers are covered by the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. [Check and list the current data processing agreements.]
How long we keep data
Data is kept while the app is installed. When the merchant uninstalls OneFee, all data of the store is deleted from the app database 48 hours after uninstalling, at the latest with the next daily deletion run. Shopify's compliance requests are answered: customers/data_request and customers/redact (OneFee holds no customer data) and shop/redact (all store data is deleted). Before uninstalling, merchants can remove all data OneFee wrote to their store with Settings → Remove all deposit data.
Security
Connections are encrypted (HTTPS). The Shopify access token is stored encrypted. Access to servers and database is limited to the operator.
Your rights
Merchants and, through the merchant, their customers have the right to access, rectification, erasure, restriction, data portability and objection under the GDPR, and the right to lodge a complaint with a supervisory authority. Contact us at support@meta-one.de.
Changes
We update this policy when the app changes. The current version is available at https://onefee.vercel.app/privacy.