Privacy Policy
How onedash collects, uses and protects the data you and your team share with us.
01Who we are
onedash is an operational dashboard for Shopify store operators. It centralizes profit tracking, orders, complaints, supply chain, product research and team management across multiple stores. This policy explains what we do with the data you share with us when you use onedash.io and the onedash application.
Questions about this policy? Email [email protected].
02What data we collect
Account data
- Username, email, password (stored hashed for authentication; also stored in plain text for the super-admin to display and edit, see §07)
- Role assignments (CEO, Owner, Manager, Media Buyer, Product Lister, Customer Service)
- Session tokens (browser-side, with 2h idle or 30d "remember me" lifetime)
Store credentials you provide
- Shopify shop domain, Admin API client ID and secret
- Meta System User access token and ad account IDs
- Google Ads access token and customer IDs (stored, integration pending)
- Pinterest Ads access token and ad account ID (stored, integration pending)
Store data pulled via APIs
- Orders, refunds, fulfillment status, line items, product titles
- Customer names and emails (only when the read_customers scope is granted)
- Ad spend, campaigns and insights from Meta Marketing API
Store data we write via APIs
- Products and product details, when a merchant lists or imports products through onedash
- Product metafields, to attach a size chart the merchant built in onedash to a product
Operator-entered data
- COGS per product, notes on orders, complaint entries, supply-chain issues
- Clock-in / clock-out records, hourly rates and payment history for team members
- Product listings, SOPs and size charts
03Why we process it
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the dashboard service | Account, store credentials, store data | Contract (Art. 6(1)(b)) |
| Authenticate users and secure sessions | Passwords, session tokens | Contract + legitimate interest |
| Team management + payroll calculations | Hours, rates, payment records | Contract + legitimate interest |
| Prevent abuse and diagnose errors | Server logs, IP addresses | Legitimate interest (Art. 6(1)(f)) |
| Respond to support and legal requests | Contact form submissions | Legitimate interest / legal obligation |
04Where your data lives
onedash runs on Railway.app infrastructure. Data is stored in persistent JSON files on a Railway-managed volume, encrypted at rest. Backups are handled by Railway. We do not sell or resell your data.
05Sub-processors
| Vendor | Purpose |
|---|---|
| Railway | Application hosting + persistent storage |
| Shopify | Store data (orders, products, customers), accessed via merchant-provided token |
| Meta / Google / Pinterest | Ad platform data, accessed via merchant-provided token |
We may add or change sub-processors as onedash evolves; the current list will always be here.
06Data retention
| Data type | Retention |
|---|---|
| Active owner accounts + their store data | Duration of the account |
| Deleted owner accounts | Immediately cascade-deleted from Railway on request (stores, team, orders, complaints, all files) |
| Contact / signup requests | Kept until manually resolved by the admin |
| Server logs | Rolling (Railway default, typically 30 days) |
07Security
- Passwords hashed with SHA-256 (plus salt). New passwords are additionally stored plain-text for admin display, this trades some security for operational convenience and is documented here for full transparency.
- All traffic over HTTPS (Railway automatic TLS)
- Session tokens are 32-byte random values, expire after inactivity, and are stored server-side
- Tenant isolation: every store and user record is tagged with a hub owner ID; API queries filter on it
- The super-admin panel is unlisted and gated by a long random secret in the URL
08Your rights (GDPR / CCPA)
- Access, request a copy of the data we hold about you
- Correction, ask us to fix inaccurate data
- Erasure, ask us to delete your account and all associated data
- Portability, request your data in a machine-readable format
- Objection, object to processing based on legitimate interest
Send requests to [email protected]. We aim to respond within 30 days.
09Cookies
onedash uses browser localStorage for your session token, role and name, required for the dashboard to work. We do not use tracking or advertising cookies on onedash.io. See our Cookies page for the full list.
10Children
onedash is a B2B tool for store operators. It is not directed at anyone under 16 and we don't knowingly collect data from them.
11Breach notification
If a personal data breach is likely to affect you, we'll notify you within 72 hours in accordance with GDPR Art. 33.
12Changes to this policy
We'll update the effective date and version at the top when we change this policy. Material changes will be flagged in the app.
Get in touch
Anything about your data or this policy, [email protected].