ONLLY · SHOPIFY APP
Privacy notice
Effective 24 September 2026 · Version 1.0
This notice explains how BUIDLERS LIMITED processes information through the ONLLY Partner Catalogue app. The app lets an approved Shopify merchant select ONLLY artwork, create linked Shopify products, and calculate royalties for sales of that artwork.
Who is responsible
ONLLY is operated by BUIDLERS LIMITED, Flat E, 10/F, Tower 3, The Avenue, 200 Queen's Road East, Wan Chai, Hong Kong. This is the company's registered office, not a customer-service location.
For privacy questions or requests, contact info@onlly.art.
Information the app uses
- Store and installation information: Shopify store domain and identifier, store display name and currency, granted app permissions, an encrypted Shopify access token, and the time the app was installed or uninstalled.
- Artwork and product links: selected ONLLY artwork IDs and versions, Shopify product IDs, product status, selected sizes and prices where needed to create a product, and import timestamps.
- Order and refund information: only the order, line-item and product identifiers, order reference, event time, currency, quantity, paid poster line amount after discounts, and refunded poster line amount needed to calculate and reconcile the store's royalty.
- Agreement record: the Shopify store ID, the versions of this notice and the Data Processing Addendum accepted by an authenticated store administrator, and the acceptance time. We do not collect the administrator's name or personal Shopify profile through this app.
The app does not request or use buyer names, email addresses, phone numbers, delivery addresses, payment credentials, or shipping details to calculate royalties. Shopify's mandatory customer privacy-request webhook can itself contain customer contact fields; the endpoint receives that request transiently and does not retain its body or those fields.
Why we use it
- Authenticate an approved partner store and keep its Shopify access token secure.
- Show the ONLLY catalogue and create products selected by that merchant, preserving the canonical ONLLY artwork ID.
- Identify paid sales and refunds of ONLLY-linked products, calculate the store-specific royalty using the agreed rate, and report the resulting usage event to Shopify for billing when that feature is enabled.
- Prevent duplicate webhook processing, resolve billing failures, maintain accounting records, and meet Shopify's privacy-request and app-security requirements.
We do not use order information for advertising, customer profiling, resale, or unrelated analytics. We do not make decisions about individual buyers.
How order data is handled
Shopify sends paid-order and refund events to the app. The app handles the webhook body in memory, checks its authenticity, and processes only the fields required for royalty accounting. It does not save raw order or refund webhook bodies. A keyed, non-reversible fingerprint of the delivery is retained for duplicate prevention; order-related identifiers are pseudonymised, and accounting amounts and event timestamps are encrypted at rest.
Customer data request and customer-redaction webhook bodies are not stored, including as a body digest. We retain only a keyed delivery reference and the processing status needed to respond idempotently.
Retention and deletion
- Processed or ignored webhook-delivery receipts are automatically deleted after 12 months. Failed or unresolved deliveries are kept until resolved; after resolution, the 12-month period applies.
- The minimized royalty ledger and successfully submitted Shopify billing-event records are automatically deleted after 7 years from the sale or refund event, subject to any unresolved billing event.
- When the app is uninstalled, its Shopify access token and partner session are cleared. On Shopify's
shop/redactrequest, the app deletes operational data such as credentials, sessions, selections, product links, webhook receipts, and agreement-acceptance state. Where required for BUIDLERS LIMITED's statutory accounting records, the app retains only the merchant identity and minimized royalty/billing records for up to 7 years from each event; those records are automatically deleted at the end of that period. If there are no such records, the store record is deleted on receipt of the request.
These periods describe the live app database. The seven-year period reflects Hong Kong business-record rules; see the Inland Revenue Department record-keeping guidance. Infrastructure-provider recovery copies, if enabled for the VPS, may persist until the provider's backup cycle overwrites them; they are not used as an operational data source.
Service providers and international processing
- Shopify: provides the merchant platform and app APIs, delivers order/refund events, and receives royalty usage events when Shopify app billing is enabled. Shopify's own privacy terms apply to its processing.
- Timeweb: provides the VPS infrastructure that hosts the app and its database. The current server address is part of a Timeweb network allocation registered in Russia; the IP registry does not identify the physical data-centre location. Contact us for the current provider placement details before enabling the app where a specific data-residency location is required.
BUIDLERS LIMITED is based in Hong Kong, and the app's hosting provider may process information outside the merchant's country. Where a restricted international transfer applies, the merchant-facing Data Processing Addendum sets out the transfer safeguards to be put in place before the app is enabled for that merchant.
Security
We use HTTPS for app traffic, encrypt Shopify access tokens with AES-256-GCM, encrypt stored royalty amounts and event timestamps with AES-256-GCM, and use keyed HMAC references for order, line-item, webhook and payload identifiers. Access is limited to the app's server-side functions and approved partner stores. No security measure can guarantee absolute security.
Your rights and requests
The merchant controls its Shopify store and is responsible for its customer privacy notices and decisions. If an individual asks about information used by the app, the merchant can contact us at info@onlly.art. We will assist the merchant as required by applicable law and our Data Processing Addendum. The app does not keep customer contact profiles that it could return or delete.
Shopify merchants can uninstall the app from Shopify Admin. For a privacy or data request, contact us with the store domain and a description of the request; do not email customer payment or identity documents unless we specifically request them through a secure channel.
Changes
We will update this notice when our data practices materially change. If an update changes the terms under which a partner store's information is processed, the app will require the authenticated store administrator to accept the new version before catalogue data or import functions can be used.