Legal

Privacy Policy

How onedash collects, uses and protects the data you and your team share with us.

Effective: 1 January 2026
Version: 1.0
Contact: [email protected]

01Who we are

onedash is an operational dashboard for Shopify store operators. It centralizes profit tracking, orders, complaints, supply chain, product research and team management across multiple stores. This policy explains what we do with the data you share with us when you use onedash.io and the onedash application.

Questions about this policy? Email [email protected].

02What data we collect

Account data

Store credentials you provide

Store data pulled via APIs

Store data we write via APIs

Operator-entered data

03Why we process it

PurposeDataLegal basis (GDPR)
Provide the dashboard serviceAccount, store credentials, store dataContract (Art. 6(1)(b))
Authenticate users and secure sessionsPasswords, session tokensContract + legitimate interest
Team management + payroll calculationsHours, rates, payment recordsContract + legitimate interest
Prevent abuse and diagnose errorsServer logs, IP addressesLegitimate interest (Art. 6(1)(f))
Respond to support and legal requestsContact form submissionsLegitimate interest / legal obligation

04Where your data lives

onedash runs on Railway.app infrastructure. Data is stored in persistent JSON files on a Railway-managed volume, encrypted at rest. Backups are handled by Railway. We do not sell or resell your data.

05Sub-processors

VendorPurpose
RailwayApplication hosting + persistent storage
ShopifyStore data (orders, products, customers), accessed via merchant-provided token
Meta / Google / PinterestAd platform data, accessed via merchant-provided token

We may add or change sub-processors as onedash evolves; the current list will always be here.

06Data retention

Data typeRetention
Active owner accounts + their store dataDuration of the account
Deleted owner accountsImmediately cascade-deleted from Railway on request (stores, team, orders, complaints, all files)
Contact / signup requestsKept until manually resolved by the admin
Server logsRolling (Railway default, typically 30 days)

07Security

08Your rights (GDPR / CCPA)

Send requests to [email protected]. We aim to respond within 30 days.

09Cookies

onedash uses browser localStorage for your session token, role and name, required for the dashboard to work. We do not use tracking or advertising cookies on onedash.io. See our Cookies page for the full list.

10Children

onedash is a B2B tool for store operators. It is not directed at anyone under 16 and we don't knowingly collect data from them.

11Breach notification

If a personal data breach is likely to affect you, we'll notify you within 72 hours in accordance with GDPR Art. 33.

12Changes to this policy

We'll update the effective date and version at the top when we change this policy. Material changes will be flagged in the app.

Get in touch

Anything about your data or this policy, [email protected].