One Life mobile app privacy
Last updated: July 25, 2026
This notice explains how the One Life mobile app (package za.co.onelife.app) handles information. The app is provided by One Life Health SA and Edcocube (Pty) Ltd. It supplements the One Life store privacy policy and applies specifically to the Android and iOS app.
Guest-first shopping
You can browse, search, build a basket, and continue to checkout without creating or signing in to an account. Customer account sign-in is optional and is enabled in internal or preview builds before any production release.
Information kept on your device
Your selected life stage, wellness goals, dietary preferences, supplement rhythm, private ritual schedule and check-ins, saved items, basket, usuals, watch shelf, and last-order note are stored locally on your device. The recent-search list is held only for the current app session.
You can remove this local app data from the You screen by choosing Clear local app data, or by clearing the app's data in your device settings. Uninstalling may not remove every Keychain item on iOS, so use the in-app clear action when you want a stored account sign-in removed.
Search, catalogue, and reviews
When you type two or more characters into search, the words you type are sent to Shopify so the app can return suggestions and matching products. The same happens when you submit a search. The request does not include the app's local intake answers, account access token, advertising identifier, or precise location.
The app connects securely to Shopify to retrieve catalogue information, prices, availability, product details, and basket data. It retrieves public product-review content from Judge.me. The app does not submit a new review or an app account token to Judge.me.
Checkout, consent, pixels, and tracking
If you continue to checkout, Shopify's hosted checkout opens in a native checkout sheet or secure browser page. Shopify collects the contact, delivery, and payment information you choose to enter there. One Life does not receive or store full card details in the app.
The One Life store uses Shopify Customer Events and configured analytics or advertising services, including Google/GA4 and other connected pixels. Those services can process product, basket, checkout, purchase, device, cookie, and attribution information according to Shopify's consent controls and their own privacy responsibilities. The mobile app does not access the advertising identifier and does not request Apple's App Tracking Transparency permission. We do not describe the embedded checkout as "No tracking" without final binary and network verification.
Account-enabled internal builds create checkout URLs with Shopify's optional analytics, preferences, marketing, and sale-or-sharing visitor-consent purposes set to false. Any future change that offers optional tracking consent must add an in-app consent choice, apply Apple's ATT result on iOS where required, update this notice, and update both app-store declarations before release.
Optional customer accounts
Where an internal or preview build shows the counter ledger, sign-in happens on Shopify's secure page using a one-time code sent to the email address you enter there. The app receives OAuth access, refresh, and ID tokens, and uses Shopify's Customer Account API to show the signed-in email address, customer/account identifier, order history, order lines, totals, fulfillment status, and available delivery tracking.
Tokens are stored in device-only secure storage and are removed when you sign out or clear local app data. The app does not send the account token with catalogue or search requests and does not store the fetched order ledger in ordinary app storage.
Account and data deletion
To start deletion of a One Life customer account and associated personal data, use the public Delete your One Life account form. The same direct link is available from the signed-in ledger in account-enabled builds. We verify the request through the account email before deleting or anonymising data that we are permitted to remove.
Some transaction, invoice, tax, fraud-prevention, security, chargeback, or legal records may need to be retained for the period required by law. Where retention is required, the data is restricted to those purposes. Account deletion is separate from clearing local app data on a phone.
Other access
The current app does not request access to your precise or approximate location, camera, microphone, contacts, photos, files, health sensors, or advertising identifier. Ritual notifications remain disabled in the production build configuration until their separate device checklist is approved.
Health information
One Life is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Product information is for shopping and educational purposes and does not replace the label or advice from a qualified healthcare professional. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
Contact
Privacy questions about the app can be sent to info@onelife.co.za.