Trust

Data Protection

Last updated June 2026

This page summarizes how OneExport handles personal data as a processor acting on a merchant's behalf, and the protections we apply.

Roles

For the store data OneExport processes, the merchant is the data controller and OneExport, operated by G2 Holdings LLC, is the data processor. We process personal data only on the merchant's instructions, which are given through the reports and exports the merchant runs.

What we process and why

We process store data, which can include customer name, email, phone, and address, for a single purpose: to generate the reports and exports the merchant requests on their own store's data. We do not process it for any other purpose.

Security measures

Encryption in transit (TLS 1.2 or higher) and at rest (AES-256), least-privilege and logged access, data minimization, and isolation between stores. See Security for detail.

Sub-processors

We engage a limited set of sub-processors, each bound to protect the data they handle. The current list is on our Sub-processors page.

Data subject requests

We support merchants in responding to their customers' data requests, including access and deletion, through Shopify's data request and redaction webhooks and on direct request.

Retention and deletion

We retain stored data only as long as needed to provide the service, and purge it on uninstall, on shop redaction, or on request. See Data deletion.

International transfers

Our infrastructure operates in the United States. Cross-border transfers rely on appropriate safeguards.

Contact

For a data processing agreement or any data protection question, email privacy@oneexport.app.

← Back to compliance