The short version. Onefold never sees card details and never processes a payment. A shopper's email, name and address go from their browser straight to OpoShop — they are not sent to Onefold and Onefold does not store them. Onefold's own servers hold only anonymous counts of whether the one-page checkout ran or handed the shopper back to the standard checkout. Nothing is ever sold.
This policy covers Onefold, an app a merchant installs on their OpoShop store to render a one-page checkout on their own storefront. Two groups are involved and they are treated differently:
Card fields in the Onefold checkout are rendered by the merchant's payment provider, inside that provider's own secure frames. Card numbers, expiry dates and security codes travel from the shopper's browser directly to the provider. Onefold never receives, stores, logs or transmits them, and the Onefold servers hold no payment credentials of any kind.
Payments themselves are created and confirmed by OpoShop's own payment system, exactly as on the standard checkout. Onefold does not process payments, does not hold funds, and never decides that an order has been paid — OpoShop does.
A shopper's email, name, delivery address and chosen shipping method are sent from their browser straight to OpoShop, to the same OpoShop endpoints the standard checkout uses, and are attached to the order in the merchant's store. They are not sent to Onefold's servers and Onefold does not store them.
Only anonymous operational counts, so that a merchant can tell whether the one-page checkout is behaving. Each record contains:
No names, no emails, no addresses, no phone numbers, no cart contents, no card data, no keystrokes, no screen recordings, no page content.
When a merchant installs Onefold from OpoShop, they authorise it to identify their store and its owner, so the app can show them their own settings and safety readout. Onefold does not place, edit or cancel orders, and stores no orders, carts, line items or prices of its own.
Product analytics contain no personal data. The identifier is the store
(store_<uuid>), never a person.
Onefold's data lives in its own database, scoped per store — no store can read another's. Access tokens are stored securely and used only to identify the merchant's own store on their behalf.
Onefold does not sell data and does not share it with third parties for advertising. Data is shared only with the infrastructure providers needed to run the service (hosting, database, error and product analytics).
The anonymous checkout-outcome records are deleted automatically after 90 days. Merchant store records are kept while the app is installed and removed on request after uninstall.
Merchants may request a copy or deletion of their store's data at any time by emailing the address below. Because Onefold stores no shopper personal data, there is nothing shopper-specific to export or erase.
Material changes to this policy will be reflected here with an updated date.