01LEGAL
Privacy Policy
Last updated · 20 August 2026
This policy explains what data Onecheckout Limited (“CODAudit”, “we”) collects when you use the CODAudit reconciliation service, how we use it, how long we keep it, and how you can exercise your rights.
1. Data we collect
Account data
Name, work email address, company or store name, store URL, courier and platform selections, monthly COD order volume, and billing details processed by our payment processor.
Uploaded files
Order exports and courier remittance reports that you upload or send to us. These files contain order-level commercial data (order IDs, AWB numbers, COD amounts, remittance amounts, dates and delivery statuses).
Technical data
IP address, browser and device information, and essential cookie identifiers. See our Cookie Policy.
2. End-customer personal data in uploaded files
Courier remittance and order files typically contain personal data relating to your end customers — including names, phone numbers, delivery addresses and, in some formats, email addresses.
You are the data controller for that personal data. We act solely as your data processor. We process it only on your documented instructions, for the purpose of producing your reconciliation report. Our Data Processing Agreement governs this relationship.
You are responsible for ensuring you have a lawful basis to share this data with us, and we ask that you remove any personal fields that are not required for reconciliation.
3. Purpose limitation
Uploaded files are processed exclusively to identify short-paid, unpaid, delayed and duplicate COD orders and to generate your reconciliation report. We do not sell, rent, share or license uploaded data. We do not use end-customer personal data for marketing, profiling, or model training.
4. Retention and deletion
Uploaded order and remittance files are deleted 30 days after the corresponding report is delivered. Generated reports and aggregate, non-personal metrics are retained for the life of your account and deleted within 30 days of account closure. Account and billing records are retained for the period required by applicable tax and accounting law in Hong Kong SAR.
You may request earlier deletion of any uploaded file at any time by writing to privacy@codaudit.com.
5. Sub-processors
- Vercel Inc. — application hosting and file storage — European Union (Frankfurt)
- Stripe — payment processing and subscription billing
- Resend — transactional email delivery
- Cloudflare, Inc. — DNS, email routing and web analytics. Our analytics are cookieless and do not track individuals across sites; aggregate analytics data is retained for 6 months.
- Lovable AI Gateway — AI inference for the support assistant chat (currently routed to Google Gemini models). It receives only the text you type into the chat widget, never uploaded files.
Each sub-processor is bound by written terms no less protective than this policy. We will give notice before adding or replacing a sub-processor that processes uploaded files.
6. International data transfers
International data transfers. Onecheckout Limited is established in Hong Kong SAR. Application hosting and file storage are provided by Vercel Inc. with processing in the European Union (Frankfurt); payment processing is handled by Stripe. Uploaded order and remittance files are deleted 30 days after processing. Data you upload, including personal data relating to your customers, is therefore processed outside the United Arab Emirates and other GCC jurisdictions. Where you are subject to UAE Federal Decree-Law No. 45 of 2021 (PDPL) or the EU/UK GDPR, you remain the data controller and we act as processor. Transfers are made on the basis of the Data Processing Agreement available at /dpa, which incorporates appropriate contractual safeguards.
7. Your rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, a portable copy, and withdrawal of consent where processing is consent-based. Send requests to privacy@codaudit.com; we respond within 30 days and may ask for information to verify your identity.
Requests from your end customers should be directed to you as controller. If we receive one directly, we will forward it to you rather than act on it ourselves.
8. Applicable law
We process personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where the processing falls within its scope, the EU General Data Protection Regulation (Regulation 2016/679). Other GCC and MENA data protection laws apply where relevant to your establishment.
9. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to uploaded files is restricted to named personnel who need it to produce a report, is logged, and is protected by multi-factor authentication and least-privilege access controls. See our Security page for detail.
10. Support access to your account
Support access is tiered, logged and time-limited. By default, our support team can see only technical diagnostics for your account — file formats, encodings, detected carriers, column mappings, row counts, skip reasons, errors and email delivery status. In that view, your end-customers' names, phone numbers, email addresses and delivery addresses are masked; order references, tracking numbers, amounts and dates remain visible because they are the commercial data needed to diagnose a settlement problem.
To let us open your account and see what you see, you grant access explicitly in Settings → Get support. Grants are view-only unless you separately allow changes on your behalf, expire automatically after 24 hours, and can be revoked by you at any time, which ends any open session immediately. Every access — what was viewed, and for changes the before and after values — is written to an immutable log that you can read in your own settings.
11. Contact
Data protection contact: privacy@codaudit.com. General enquiries: hello@codaudit.com. Registered address: No. 5, 17/F, Strand, Bonham Strand, Sheung Wan, Hong Kong.