Legal

Privacy Policy

How onedash collects, uses and protects the data you and your team share with us.

Effective: 9 September 2026
Version: 2.0
Contact: [email protected]

01Who we are

onedash is a business-to-business operational dashboard for Shopify store operators. It centralizes profit tracking, orders, complaints, supply chain, advertising performance, product research and team management across multiple stores, for the store's own team. This policy explains what we do with the data you share with us when you use onedash.io and the onedash application.

Questions about this policy? Email [email protected].

02What data we collect

Account data

Store credentials you provide

Store data pulled via APIs

Store data we write via APIs

Operator-entered data

03Google User Data and Google Ads Integration

onedash offers an optional integration with Google Ads for merchants who want their Google Ads performance alongside their Shopify and Meta data in one dashboard. This section explains, specifically and completely, what that integration does with your Google data.

How the connection works

What we retrieve

For each Google Ads account you connect, onedash retrieves:

What this data is used for

Retrieved Google Ads information is used only to provide onedash's own advertising dashboards back to you: campaign reporting, performance analysis, and a consolidated view alongside your Shopify and Meta Ads figures.

Google Ads conversion value is not the same thing as your actual Shopify revenue. onedash treats it strictly as Google's own advertising-platform attribution figure, and keeps it conceptually and visually separate from real Shopify store revenue everywhere in the product. Your Shopify revenue is always the authoritative number for what you actually sold; Meta's and Google's own attributed/conversion values are shown alongside it, clearly labelled per platform, and are never added together into a single blended "revenue" number.

What onedash does not do

Where the credentials live

Your Google OAuth access and refresh credentials are stored and used entirely on onedash's server. They are never sent to, or exposed in, your browser or any client-side application code — the onedash frontend never has access to the raw tokens themselves.

Disconnecting and revoking access

Google API Services User Data Policy

onedash's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

04Why we process it

PurposeDataLegal basis (GDPR)
Provide the dashboard serviceAccount, store credentials, store dataContract (Art. 6(1)(b))
Provide advertising dashboards, campaign reporting and analytics for connected ad platformsMeta and Google Ads account, campaign and performance dataContract (Art. 6(1)(b))
Authenticate users and secure sessionsPasswords, session tokensContract + legitimate interest
Team management + payroll calculationsHours, rates, payment recordsContract + legitimate interest
Billing and invoicingPlan, billing status, payment records (via Mollie)Contract (Art. 6(1)(b))
Prevent abuse and diagnose errorsServer logs, IP addressesLegitimate interest (Art. 6(1)(f))
Respond to support and legal requestsContact form submissionsLegitimate interest / legal obligation

05Where your data lives

onedash runs on Railway.app infrastructure. Data is stored in persistent JSON files on a Railway-managed volume. Backups are handled by Railway. We do not sell or resell your data.

Sensitive integration credentials — Shopify, Meta and Google Ads access and refresh tokens — are additionally encrypted at rest at the application level using AES-256-GCM, independent of whatever storage-level protection Railway itself provides.

06Subprocessors and connected platforms

These are different relationships, and we keep them separate rather than listing them together as if they were the same thing.

Subprocessors

Vendors who process data on onedash's behalf, to provide the onedash service itself:

VendorPurpose
RailwayApplication hosting and persistent storage
MolliePayment processing and subscription billing
Our email delivery provider (SMTP)Transactional email: password resets, notifications, support replies

Third-party platforms you connect

Shopify, Meta and Google Ads are not onedash subprocessors. You connect your own account with each of these platforms directly, using your own credentials or your own OAuth authorization, and onedash accesses only the data you've explicitly authorized it to access on your behalf — the same way any app you grant access to would. onedash does not control, and is not responsible for, how Shopify, Meta or Google themselves handle your data under their own privacy policies.

PlatformWhat onedash accesses, and how
ShopifyStore data (orders, products, customers), accessed via a merchant-provided Admin API token
MetaAd account and campaign data, accessed via a merchant-provided System User access token
Google AdsAd account and campaign data, accessed via Google OAuth 2.0 — see §03 for full detail
PinterestNot yet available to connect through onedash's own flow; where a store owner has manually entered credentials, handled the same as Meta above

We may add or change subprocessors or connected platforms as onedash evolves; the current list will always be here.

07Data retention and deletion

Data typeRetention
Active owner accounts and their store dataDuration of the account
Deleted owner accountsCascade-deleted immediately, as part of the same request: the account, its stores, team accounts, Shopify/Meta/Google Ads credentials and synced data, orders, complaints, supply chain, COGS, hours, listings, SOPs and push-notification subscriptions
A disconnected Google Ads (or Meta) integration on an otherwise-active storeOAuth credentials and previously-synced campaign/performance data for that integration are deleted immediately as part of the disconnect action, without affecting the rest of the store's data
Contact / signup requestsKept until manually resolved by the admin
Server logsRolling (Railway default, typically 30 days)

To request deletion of your account, any specific integration's data, or data obtained through a connected third-party service such as Google Ads, email [email protected]. We may retain a minimal record where we have a legitimate legal or operational reason to (for example, billing records required for tax purposes) — we'll tell you plainly if that applies to your request rather than silently keeping more than we've said here.

08Security

09Your rights (GDPR / CCPA)

Send requests to [email protected]. We aim to respond within 30 days.

10Cookies

onedash uses browser localStorage for your session token, role and name, required for the dashboard to work. We do not use tracking or advertising cookies on onedash.io. See our Cookies page for the full list.

11Children

onedash is a B2B tool for store operators. It is not directed at anyone under 16 and we don't knowingly collect data from them.

12Breach notification

If a personal data breach is likely to affect you, we'll notify you within 72 hours in accordance with GDPR Art. 33.

13Changes to this policy

We'll update the effective date and version at the top when we change this policy. Material changes will be flagged in the app.

Get in touch

Anything about your data or this policy, [email protected].