Data Protection
This page summarizes how OneExport handles personal data as a processor acting on a merchant's behalf, and the protections we apply.
Roles
For the store data OneExport processes, the merchant is the data controller and OneExport, operated by G2 Holdings LLC, is the data processor. We process personal data only on the merchant's instructions, which are given through the reports and exports the merchant runs.
What we process and why
We process store data, which can include customer name, email, phone, and address, for a single purpose: to generate the reports and exports the merchant requests on their own store's data. We do not process it for any other purpose.
Security measures
Encryption in transit (TLS 1.2 or higher) and at rest (AES-256), least-privilege and logged access, data minimization, and isolation between stores. See Security for detail.
Sub-processors
We engage a limited set of sub-processors, each bound to protect the data they handle. The current list is on our Sub-processors page.
Data subject requests
We support merchants in responding to their customers' data requests, including access and deletion, through Shopify's data request and redaction webhooks and on direct request.
Retention and deletion
We retain stored data only as long as needed to provide the service, and purge it on uninstall, on shop redaction, or on request. See Data deletion.
International transfers
Our infrastructure operates in the United States. Cross-border transfers rely on appropriate safeguards.
Contact
For a data processing agreement or any data protection question, email privacy@oneexport.app.
← Back to compliance