Privacy
Effective 12 September 2026. OnesShop (ones.shop) is operated by Ones Tech Limited, Hong Kong.
The short version: you can read and compare everything here without telling us who you are; an account is needed only to be paid cashback. We set a cookie when you follow a buy link and when you sign in. We do not sell personal information, we do not share it for advertising, and we run no third-party tracking scripts. The rest of this page says exactly what happens and when.
When you browse
Reading a page of the public site sets no cookie and asks for no account. Our application keeps no log of who visits: an error is logged with the page that failed, not with who asked for it. Cloudflare, which sits in front of the site, does see each request, including its IP address, under its own policy (see below). We do send our analytics service, PostHog, an identifier made from your network address and your browser, hashed together with the day, under a key only we hold, so it is a different identifier every day and cannot be turned back into an address. It sets no cookie.
A search you type goes into the page address, as a search on most sites does. We do not store it.
The operator sign-in at /admin/ is for our own staff. It sets its own
cookies and is not part of the public site. A failed staff sign-in to our back
office is recorded — the username typed, the IP address and the browser — so that
repeated guessing can be locked out; it is deleted once the lockout window passes.
When you follow a buy link
Every buy button on the site goes through our own /go/ address before
sending you on to the merchant. At that moment the site sets one cookie, named
sessionid, which expires after two weeks. It exists so that clicking the
same button twice counts as one action rather than two; it holds a random identifier
and nothing about you. The session itself is a record in our database holding only
that identifier and an expiry date.
The click itself is recorded. That record holds: which offer you followed, where on the site the button was (a recommendation, a comparison, a product page or the home page), the offer's market, currency and price at the time, and the time of the click. The click record does not hold the cookie's identifier — it is hashed into a deduplication key and cannot be recovered from it. The record contains no IP address and no browser details. If you were signed in when you clicked, it records which account the click belongs to — that is what a cashback payment is owed against.
Each click has its own random identifier. Where the offer goes through an affiliate network, we may pass that identifier to the network, so that a later commission can be matched to the click and to the page it came from. The identifier is meaningless outside our own records and carries nothing about you. Such a link may also go through the network's own redirect address on the way to the merchant; the network then sees that request, including your IP address and browser details, under its own policy. Click records are kept: they are what a commission is reconciled against.
When you have an account
Your account is held by Clerk, our sign-in provider: your email address, your password and your sign-in security live there, under Clerk's own privacy policy. Here we keep your Clerk user id, the email Clerk gives us when you sign in, and the purchase clicks you bind to the account with their cashback quotes, the cashback ledger, payouts and claims that follow from them — that is what lets us pay you. You can see them on your cashback page. To close your account, write to us; we then anonymise your clicks rather than delete them, because a commission may still be reconciled against them.
Once you are on the merchant's site
From the moment you arrive, you are under the merchant's privacy policy and any cookies it or its affiliate network sets are theirs, not ours. Where a link is one that pays us, those cookies are how the merchant credits the sale to this site; where it is not, they are simply the merchant's own. We do not receive your name, your address, your payment details or what else you bought. From a network's report we take only that a sale happened, its value and the commission on it, tied to the click identifier above.
Analytics
Our analytics service is PostHog. Nothing of theirs runs in your browser: our own server reports what happened — a link resolved, a question asked, a page read, a buy link followed — under the daily identifier described above. What you typed, the link you pasted and your address are never part of it.
When you are signed in, those events carry your account id instead of the daily identifier, so your steps join up across devices and days. For your own purchases the events also carry the commission a merchant owes us and the cashback that follows from it. PostHog holds them under that id.
Who else handles this data
- Cloudflare sits in front of the site and sees every request, including its IP address, under Cloudflare's own privacy policy.
- Clerk is our sign-in provider and holds the buyer accounts — email address, password and sign-in security — under Clerk's own privacy policy.
- PostHog is our analytics service and receives the events described above, under PostHog's own privacy policy.
- Our hosting and database provider stores the site's data on our behalf.
- Affiliate networks receive the click identifier described above and nothing more from us; where a link passes through a network's redirect, the network also sees that request itself.
We are a Hong Kong company and our providers operate worldwide, so the little data described above may be handled outside the country you are in, including outside the United States.
We do not sell personal information, do not share it for cross-context behavioural advertising, and do not give it to data brokers. We would disclose data if the law required it, and we would say so here if that ever happened.
Your choices
You can block or delete the cookies we set; buy links keep working, we just lose the ability to tell a repeat click from a new one. There is no profile beyond your email and your clicks. If you believe we hold personal information about you, write to us and we will look and answer.
California residents. We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, so there is nothing to opt out of; a Global Privacy Control signal from your browser changes nothing, because there is nothing it would need to change. You may still ask us what we hold about you and ask us to correct or delete it, by email at the address below, and we will not treat you differently for asking.
Children. The site is not directed at children under 13 and we do not knowingly collect personal information from them.
Changes
When this policy changes, the new version appears here with a new effective date. A change that alters what we collect will be described in the text, not hidden in the date.
Contact
Questions about this policy: [email protected].