Privacy Policy
How onedash collects, uses and protects the data you and your team share with us.
01Who we are
onedash is a business-to-business operational dashboard for Shopify store operators. It centralizes profit tracking, orders, complaints, supply chain, advertising performance, product research and team management across multiple stores, for the store's own team. This policy explains what we do with the data you share with us when you use onedash.io and the onedash application.
Questions about this policy? Email [email protected].
02What data we collect
Account data
- Username, email, password — passwords are hashed with scrypt, a memory-hard hashing algorithm designed to resist offline cracking. Accounts created before scrypt was introduced are transparently upgraded to it the next time they sign in. onedash does not store your password in plain text, and no one at onedash, including super-admins, can view it.
- Role assignments (CEO, Owner, Manager, Media Buyer, Product Lister, Customer Service)
- Session tokens (browser-side, with a 2-hour idle or 30-day "remember me" lifetime)
Store credentials you provide
- Shopify shop domain, Admin API client ID and secret
- Meta System User access token and ad account IDs
- Google Ads OAuth authorization credentials, including access and refresh credentials as applicable, and Google Ads customer/account identifiers for accounts you explicitly connect — see §03 for the full detail on how this works
- Pinterest Ads access token and ad account ID, where a store owner has entered one; this integration is not yet available to select from onedash's connection flow
Store data pulled via APIs
- Orders, refunds, fulfillment status, line items, product titles
- Customer names and emails (only when the read_customers scope is granted)
- Ad spend, campaigns and insights from the Meta Marketing API
- Ad spend, campaign details and performance metrics from the Google Ads API, for accounts you explicitly connect — see §03
Store data we write via APIs
- Products and product details, when a merchant lists or imports products through onedash
- Product metafields, to attach a size chart the merchant built in onedash to a product
Operator-entered data
- COGS per product, notes on orders, complaint entries, supply-chain issues
- Clock-in / clock-out records, hourly rates and payment history for team members
- Product listings, SOPs and size charts
03Google User Data and Google Ads Integration
onedash offers an optional integration with Google Ads for merchants who want their Google Ads performance alongside their Shopify and Meta data in one dashboard. This section explains, specifically and completely, what that integration does with your Google data.
How the connection works
- Connecting Google Ads is entirely voluntary. onedash never requests or accesses any Google account or Google Ads data unless you explicitly start the connection yourself, from Store Management.
- The connection uses Google's own OAuth 2.0 sign-in flow. You authenticate directly with Google, on Google's own sign-in page, and Google shows you exactly what access onedash is requesting before you approve anything.
- Once you approve, onedash retrieves the list of Google Ads accounts (customer IDs) that your Google login can access, and shows that list to you so you can choose which specific accounts to link to which onedash store. onedash only syncs data for accounts you explicitly select, never every account your login could technically reach.
What we retrieve
For each Google Ads account you connect, onedash retrieves:
- Account information: customer/account ID, account name, currency and time zone
- Campaign information: campaign name, status, type (Search, Shopping, Performance Max, Display, Video and any other type Google Ads reports), and budget
- Daily performance metrics: advertising spend/cost, impressions, clicks, conversions and conversion value
What this data is used for
Retrieved Google Ads information is used only to provide onedash's own advertising dashboards back to you: campaign reporting, performance analysis, and a consolidated view alongside your Shopify and Meta Ads figures.
Google Ads conversion value is not the same thing as your actual Shopify revenue. onedash treats it strictly as Google's own advertising-platform attribution figure, and keeps it conceptually and visually separate from real Shopify store revenue everywhere in the product. Your Shopify revenue is always the authoritative number for what you actually sold; Meta's and Google's own attributed/conversion values are shown alongside it, clearly labelled per platform, and are never added together into a single blended "revenue" number.
What onedash does not do
- The Google Ads integration is reporting-only. onedash does not use the Google Ads API to create, edit, enable, pause or delete campaigns, ads, keywords, budgets, billing settings or Google Ads users.
- onedash does not sell Google user data, to anyone, under any circumstances.
- onedash does not use Google user data for advertising — including advertising onedash itself — unrelated to providing you the onedash service.
- onedash does not transfer Google user data to third parties, except: the subprocessors necessary to run the onedash service itself (§06), where required by law, or with your explicit direction or consent.
Where the credentials live
Your Google OAuth access and refresh credentials are stored and used entirely on onedash's server. They are never sent to, or exposed in, your browser or any client-side application code — the onedash frontend never has access to the raw tokens themselves.
Disconnecting and revoking access
- You can disconnect a Google Ads integration from onedash at any time, from Store Management. Disconnecting immediately removes onedash's stored OAuth credentials for that store and deletes the campaign and performance data onedash had already synced for it — this is not a scheduled or delayed cleanup, it happens as part of the same request.
- Disconnecting in onedash stops onedash's own access to your Google Ads data going forward. To fully revoke the authorization on Google's side as well, remove onedash from the third-party access list in your Google Account at myaccount.google.com/permissions.
- You can also email [email protected] at any time to request deletion of any Google-derived data associated with your onedash account, including if you'd like it removed without disconnecting through the app yourself.
Google API Services User Data Policy
onedash's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
04Why we process it
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the dashboard service | Account, store credentials, store data | Contract (Art. 6(1)(b)) |
| Provide advertising dashboards, campaign reporting and analytics for connected ad platforms | Meta and Google Ads account, campaign and performance data | Contract (Art. 6(1)(b)) |
| Authenticate users and secure sessions | Passwords, session tokens | Contract + legitimate interest |
| Team management + payroll calculations | Hours, rates, payment records | Contract + legitimate interest |
| Billing and invoicing | Plan, billing status, payment records (via Mollie) | Contract (Art. 6(1)(b)) |
| Prevent abuse and diagnose errors | Server logs, IP addresses | Legitimate interest (Art. 6(1)(f)) |
| Respond to support and legal requests | Contact form submissions | Legitimate interest / legal obligation |
05Where your data lives
onedash runs on Railway.app infrastructure. Data is stored in persistent JSON files on a Railway-managed volume. Backups are handled by Railway. We do not sell or resell your data.
Sensitive integration credentials — Shopify, Meta and Google Ads access and refresh tokens — are additionally encrypted at rest at the application level using AES-256-GCM, independent of whatever storage-level protection Railway itself provides.
06Subprocessors and connected platforms
These are different relationships, and we keep them separate rather than listing them together as if they were the same thing.
Subprocessors
Vendors who process data on onedash's behalf, to provide the onedash service itself:
| Vendor | Purpose |
|---|---|
| Railway | Application hosting and persistent storage |
| Mollie | Payment processing and subscription billing |
| Our email delivery provider (SMTP) | Transactional email: password resets, notifications, support replies |
Third-party platforms you connect
Shopify, Meta and Google Ads are not onedash subprocessors. You connect your own account with each of these platforms directly, using your own credentials or your own OAuth authorization, and onedash accesses only the data you've explicitly authorized it to access on your behalf — the same way any app you grant access to would. onedash does not control, and is not responsible for, how Shopify, Meta or Google themselves handle your data under their own privacy policies.
| Platform | What onedash accesses, and how |
|---|---|
| Shopify | Store data (orders, products, customers), accessed via a merchant-provided Admin API token |
| Meta | Ad account and campaign data, accessed via a merchant-provided System User access token |
| Google Ads | Ad account and campaign data, accessed via Google OAuth 2.0 — see §03 for full detail |
| Not yet available to connect through onedash's own flow; where a store owner has manually entered credentials, handled the same as Meta above |
We may add or change subprocessors or connected platforms as onedash evolves; the current list will always be here.
07Data retention and deletion
| Data type | Retention |
|---|---|
| Active owner accounts and their store data | Duration of the account |
| Deleted owner accounts | Cascade-deleted immediately, as part of the same request: the account, its stores, team accounts, Shopify/Meta/Google Ads credentials and synced data, orders, complaints, supply chain, COGS, hours, listings, SOPs and push-notification subscriptions |
| A disconnected Google Ads (or Meta) integration on an otherwise-active store | OAuth credentials and previously-synced campaign/performance data for that integration are deleted immediately as part of the disconnect action, without affecting the rest of the store's data |
| Contact / signup requests | Kept until manually resolved by the admin |
| Server logs | Rolling (Railway default, typically 30 days) |
To request deletion of your account, any specific integration's data, or data obtained through a connected third-party service such as Google Ads, email [email protected]. We may retain a minimal record where we have a legitimate legal or operational reason to (for example, billing records required for tax purposes) — we'll tell you plainly if that applies to your request rather than silently keeping more than we've said here.
08Security
- Passwords are hashed with scrypt (memory-hard, salted); onedash never stores your password in plain text and no one, including super-admins, can view it — see §02
- All traffic over HTTPS (Railway automatic TLS)
- Session tokens are 32-byte random values, expire after inactivity, and are stored server-side
- Tenant isolation: every store and user record is tagged with a hub owner ID; API queries filter on it
- Shopify, Meta and Google Ads OAuth tokens are encrypted at rest (AES-256-GCM) and are only ever decrypted server-side, on demand, to make the specific API call that needs them
- Administrative access to the internal super-admin panel requires both a private access credential and a real, authenticated onedash login belonging to an explicitly authorized onedash staff account — a leaked or guessed link alone is not sufficient to reach any account data
09Your rights (GDPR / CCPA)
- Access, request a copy of the data we hold about you
- Correction, ask us to fix inaccurate data
- Erasure, ask us to delete your account and all associated data, including data obtained through connected third-party services such as Google Ads, subject to any legitimate legal or operational retention requirement described in §07
- Portability, request your data in a machine-readable format
- Objection, object to processing based on legitimate interest
Send requests to [email protected]. We aim to respond within 30 days.
10Cookies
onedash uses browser localStorage for your session token, role and name, required for the dashboard to work. We do not use tracking or advertising cookies on onedash.io. See our Cookies page for the full list.
11Children
onedash is a B2B tool for store operators. It is not directed at anyone under 16 and we don't knowingly collect data from them.
12Breach notification
If a personal data breach is likely to affect you, we'll notify you within 72 hours in accordance with GDPR Art. 33.
13Changes to this policy
We'll update the effective date and version at the top when we change this policy. Material changes will be flagged in the app.
Get in touch
Anything about your data or this policy, [email protected].