Trust

Security at OneExport

Last updated June 2026

Your store data is yours. This page describes how we keep it private and protected, from the first install to the last export.

Data minimization

The strongest protection is holding very little. Detailed customer fields are read live when a report runs and are not retained. The only customer data stored at rest is a Shopify customer ID and coarse geography on an order. There is very little for anyone to reach, because most of it is never kept.

Encryption

All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Backups are managed by our hosting provider and inherit provider encryption. Shopify access tokens are stored encrypted and scoped to a single store.

Access control

Access to operational tools is limited to our team and protected by a secret, an expiring signed session, and rate limiting. Access to store data is least-privilege, and Shopify API scopes are limited to what the reports require.

Audit logging

Every access to protected customer data through our internal tools is recorded with the operator, the store, the action, and a reason. This log is the first place we look during any review.

Isolation

Each store is isolated. Your exports are yours, and no other merchant can reach them.

Deletion

Uninstalling, or a Shopify shop-redaction request, purges all of your stored data. Customer-redaction requests remove the customer link. You can request deletion at any time. See Data deletion.

Infrastructure

OneExport runs on Railway (hosting and database) with Cloudflare (DNS and email routing) and Resend (outbound email), and reads your store through Shopify's official API. These providers are listed on our Sub-processors page.

Incident response

We maintain a written incident response process: detect, contain, assess, notify, and review. Where a personal-data breach is notifiable, we follow the required timelines, including notifying the relevant authority within 72 hours under GDPR.

Reporting a concern

If you believe you have found a security issue, email privacy@oneexport.app and we will respond promptly.

← Back to compliance