GDPR Compliance
OneExport is built to support merchants and their customers in the EU and UK under the General Data Protection Regulation.
Our role
For store data, the merchant is the controller and OneExport is the processor. We process personal data only on the merchant's instructions, to build the reports they request.
Lawful basis
Processing is carried out on the merchant's instructions and lawful basis as controller. We do not determine the purposes of processing beyond delivering the requested reports.
Data subject rights
We support the rights of access, rectification, erasure, restriction, portability, and objection. Because we retain almost no personal data, most requests are met by Shopify's data request and redaction flows, which we honor, and by our deletion process.
- Access and portability: detailed personal data is not retained by us; it lives in the merchant's Shopify store and in exports the merchant holds.
- Erasure: uninstall, shop redaction, and customer redaction all trigger deletion of the relevant stored data.
- Restriction and objection: contact us and we will act on valid requests.
Security and breach notification
We apply encryption, access control, and logging, and we maintain an incident response process. Where a personal-data breach is notifiable, we notify the relevant supervisory authority within 72 hours of becoming aware of it, and affected individuals where the risk is high.
International transfers
Our infrastructure operates in the United States, and cross-border transfers rely on appropriate safeguards.
Contact
For GDPR requests, email privacy@oneexport.app.
← Back to compliance