Privacy Policy
This policy explains what data OneExport accesses, how we use it, and the choices you have. In plain terms: we use your store data only to build the reports you ask for, we store almost none of it, and we never sell it.
Who we are
OneExport is operated by G2 Labs, a brand of G2 Holdings LLC ("we", "us"). You can reach us at privacy@oneexport.app.
What data we access
When you install OneExport, you grant it read access to your store data through Shopify's official API. Depending on the reports you run, this can include orders, products, inventory, customers, and related records, along with customer fields such as name, email, phone, and address where a report includes them.
How we use it
We use this data for one purpose: to build the reports and exports you request, on your own store's data. We do not use it for anything else.
What we never do
- We never sell your data.
- We never share it with advertisers or unrelated third parties.
- We never use it to train machine-learning or AI models.
What we store, and what we don't
We store as little as possible. Detailed customer fields (name, email, phone, street address, zip) are read live from Shopify the moment a report runs, written into the export you download, and not retained. The only customer data kept at rest is a customer's Shopify ID and coarse geography (country and province) on an order, used to keep aggregate reporting fast.
How we protect it
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Access tokens are stored encrypted and scoped to your store. Access to our systems is limited and logged. See our Security page for detail.
Sub-processors
We use a small set of infrastructure providers to run the service: Railway (application hosting and database), Cloudflare (DNS and inbound email routing), Resend (outbound email such as lifecycle and support messages), and Shopify (the platform). They process data only to run the service. The current list is on our Sub-processors page.
Data retention and deletion
We keep stored data only as long as needed to provide the service. When you uninstall, or on a Shopify shop-redaction request, all of your stored data is purged. You can request deletion at any time, completed within 30 days. See Data deletion.
Your rights
Depending on where you are, you may have rights to access, correct, delete, or port your data, and to object to or restrict its processing. We honor GDPR and CCPA rights. See GDPR and CCPA, or email privacy@oneexport.app.
International data
Our infrastructure is operated in the United States. Where data is transferred across borders, we rely on appropriate safeguards.
Changes
If we update this policy, we will revise the date above and, for material changes, notify merchants.
← Back to compliance