Skip to content

Privacy & data handling

Your app can see real customer and business data the moment it’s installed. This page covers what the platform expects you to do with it.

Request only the scopes your integration actually uses, and store only what you need to function — not everything a broad scope happens to expose. A “read-only reporting dashboard” that stores full customer PII indefinitely is exactly the kind of thing review looks for.

Two events are required subscriptions for any marketplace-listed app — listing submission checks for them and rejects with MANDATORY_WEBHOOKS_MISSING if either is missing:

EventWhat your app must do on receipt
app.uninstalledStop calling this business — its tokens are already revoked, so further calls will simply fail, but stop trying and mark the connection inactive in your own system.
business.redactDelete everything you independently store for this business. OneBooks deletes your app data values for it automatically at the same moment; anything you’ve copied into your own database is your responsibility.

Also subscribe to the per-person erasure notices if you store personal data about a business’s customers or suppliers. They’re not part of the mandatory pair above, but they carry the same obligation at the level of one person rather than the whole business:

EventScopeWhat your app must do on receipt
customer.redactcustomers:readErase the personal data you hold for that one customer, in that business.
supplier.redactsuppliers:readErase the personal data you hold for that one supplier, in that business.

When a merchant erases a customer or supplier, OneBooks anonymizes the record and, in the same step, reduces the payloads of the earlier events that carried that person’s details — customer.created/customer.updated (or supplier.created/supplier.updated), in the Events API and in your webhook delivery history alike — to { "id": …, "redacted": true }. A later Events API read or a redelivery no longer carries their details; events that only mention the contact by id, such as an invoice’s customerId, are unchanged. Then it sends customer.redact or supplier.redact. What you already received is yours to erase.

business uninstalls your app
│
├─ immediately: every token/consent for your app in this business is revoked,
│ and unredeemed codes and approvals are cancelled
├─ immediately: queued deliveries of this business's events are dropped
├─ immediately: app.uninstalled fires
│
└─ +48 hours (unless reinstalled; checked hourly): business.redact fires
├─ OneBooks deletes your app data values for this business
└─ if the notice couldn't be recorded, the next hourly check retries it

If the business reinstalls within the 48-hour window, the installation simply returns to ACTIVE — redaction never happens, and there’s nothing to reverse. See Installation & lifecycle for the full state machine.

  • Events: retained 30 days in the Events API, and webhook delivery history for 30 days too — a delivery is deleted 30 days after it was created, and can’t be redelivered after that.
  • App data: kept while your app is installed, and deleted at the 48-hour redaction point after an uninstall. Deleting a field definition deletes its values in every business.
  • Hosted function logs: whatever your function logs is stored with the run, up to 16 KB — don’t log personal data you don’t need.
  • Your own copies: this platform has no authority over data you’ve exported into your own systems — that’s governed by your own privacy policy and applicable law (and by the customer.redact/supplier.redact/ business.redact obligations above).

Security — the technical checklist (signature verification, token storage, scopes) that sits alongside these data-handling obligations.