OneBox by Gezici Labs
Privacy Policy
Last updated 12 August 2026
OneBox is a Shopify app, published by Gezici Labs, that controls how a merchant’s orders are routed across fulfillment locations so shipments are not split unnecessarily. This page describes exactly what data the app touches, what it keeps, and for how long.
The short version: OneBox stores no buyer personal data on its servers. The app works on carts and locations, not on people. What we keep is a store credential and anonymous daily counts.
Who is responsible for what
The merchant running the store is the data controller. Gezici Labs acts as a data processor on the merchant’s behalf and only processes what is described below. If you are a shopper and want to know what a particular store holds about you, contact that store directly — we cannot identify you from anything we hold.
Buyer data the app is granted access to
- Cart contents at checkout. Shopify passes the cart lines — which products, in what quantities — to our fulfillment constraints function, which runs inside Shopify’s own sandboxed runtime. That code has no network access: it looks at the products and the merchant’s routing rules and tells Shopify which locations may fulfill them. It never sees the buyer’s name, email, or address, and nothing is sent to us or written down.
- Orders from the last 24 hours. The app scans recent orders at most once a day to count how many were split into multiple shipments. It reads only each order’s fulfillment structure — never the buyer’s identity, address, or payment details — and stores only the resulting totals.
The app never receives IP addresses, payment details, email addresses, shipping addresses, or browsing history, and it installs nothing in the storefront or checkout that tracks shoppers.
What we store, and where
- Your Shopify session. Your store domain, the access token that lets the app call Shopify on your behalf, the permissions you granted, and their expiry. The access token is a credential and is treated as one.
- Daily counters. Per store and per day: how many orders were split across multiple locations. These are plain numbers and cannot be traced to a person.
This data is held on Cloudflare Workers and Cloudflare D1, encrypted in transit and at rest.
Where your routing rules live
The rules you write — which products must ship from which locations, and whether orders may be split — are stored in your own Shopify store, as metafields under the app’s reserved namespace. They are not copied to our servers. Uninstalling the app removes those metafields along with it.
How long we keep things
- Your session is deleted as soon as we receive Shopify’s app uninstall notification.
- Everything else we hold for your store — the daily counters — is deleted when Shopify sends the shop redaction request, 48 hours after uninstall.
- Because we hold no per-shopper records, Shopify’s customer data request and customer redaction webhooks have nothing to export or erase. We acknowledge both.
Who else sees this data
Two processors, both required to run the app: Shopify, which hosts your store and delivers the app, and Cloudflare, which hosts our code and database. There is no analytics provider, no advertising network, and no third-party tracking of any kind. We do not sell or share data, and we do not use it to train models.
Your rights
Merchants can ask us at any time what we hold for their store, request a copy, or ask for deletion — uninstalling triggers deletion automatically, but you do not have to uninstall to ask. Under GDPR and similar laws you also have rights of access, correction, restriction, and objection. Email utkuorcungezici@gmail.com and we will respond within 30 days.
Changes
If this policy changes in a way that affects what we collect or how we use it, we will update the date at the top of this page and notify installed merchants by email before the change takes effect.