Last updated 25 September 2026

Privacy policy

This policy explains what OneObit collects when a merchant installs the OneObit Mobile App Builder from the Shopify App Store, what the merchant's mobile app collects from shoppers, and what we do with it.

Who we are

OneObit("we", "us") builds and operates the OneObit Mobile App Builder, a Shopify app that lets a merchant design a native iOS and Android storefront and publish it under the merchant's own Apple and Google developer accounts. We are based in Noida, Uttar Pradesh, India. Contact us at [email protected].

Two kinds of people, two roles

Merchants install our app in their Shopify admin. For merchant data we are the data controller.

Shoppersuse a merchant's mobile app. For shopper data we act as a data processor on the merchant's instructions, under a data processing agreement with each merchant. The merchant is the controller of their shoppers' data.

What we collect from merchants

  • Shop identity from Shopify: shop domain, shop name, plan, and the email of the account that installed us.
  • Your app design: theme, sections, copy, images and settings you create in the editor.
  • Developer account credentials you provide for publishing: App Store Connect API keys and Google Play service account keys, encrypted at rest and used only to build and submit your app.
  • Billing status, read from Shopify. We never see card details; Shopify bills you.
  • Support conversations and emails you send us.

What the merchant's app collects from shoppers

  • Push notification tokens (APNs and FCM device tokens) when a shopper allows notifications. This is the minimum needed to deliver a push, and we store it so the merchant can send campaigns.
  • Cart and browsing events inside the app, such as products viewed and carts abandoned, so the merchant can send abandoned-cart and back-in-stock notifications and so recommendation rails can be ranked.
  • Order history, read from Shopify with the merchant's approved protected-customer-data access, to power "Buy it again" rails and AI suggestions. This data stays on Shopify; we read it when needed and cache derived rankings, not the underlying orders.

Customer accounts, addresses, payment details, checkout and orders are handled by Shopify. Checkout in the app is Shopify's own checkout. We do not process payments and we never see card numbers.

Protected customer data

Where a merchant enables push notifications, we request Shopify's protected customer data access for name, email, phone and address, with a per-field justification, so notifications can be personalised and so data-subject requests can be honoured. We apply Shopify's Level 1 and Level 2 requirements: data minimisation, purpose limitation, honouring consent and opt-outs, encryption in transit and at rest, encrypted backups, separated test and production data, staff access limits, and access logging.

AI features

When a merchant turns on OneObit AI, catalogue, collection and order-history data granted through Shopify scopes is used to generate suggestions for that merchant's app: layouts, push copy and rail rankings. Suggestions are drafts the merchant accepts or dismisses. We do not use one merchant's data to generate suggestions for another, and we do not use merchant or shopper data to train shared models. The AI can be switched off per store, after which no store data is sent to a model.

How long we keep it

  • Merchant data and app design: for as long as the app is installed, then deleted within 30 days of the shop/redact webhook.
  • Push tokens and app events: deleted when a shopper uninstalls the app or opts out, and in any case within 30 days of a customers/redact request.
  • Developer account keys: deleted immediately when you remove them in the editor or uninstall the app.
  • Access logs for protected data: 12 months, for security and compliance review.

Who we share it with

Shopify (the platform), Apple and Google (to publish and notify), our hosting and build providers under data processing terms, and nobody else. We do not sell data and we do not run advertising.

Your rights

Merchants can export or delete their data by uninstalling the app or emailing us. Shoppers should contact the merchant whose app they use; merchants can forward requests to us and we honour Shopify's customers/data_request and customers/redactwebhooks automatically. Depending on where you live you may have rights of access, correction, deletion, portability and objection under laws such as the GDPR, the UK GDPR, the CCPA and India's DPDP Act. Write to [email protected] and we reply within 30 days.

Cookies

This website sets no tracking cookies. The Shopify-embedded editor uses Shopify session tokens, not cookies, to identify the merchant.

Changes

We will update this page when the product changes what it collects, and note the date at the top. Material changes are also announced in the app.