Privacy Policy
Last updated: September 10, 2026
StoreRecover (“the app”) backs up store data and restores it when something is deleted or changed by mistake. This policy explains what the app stores, where it is stored, how long it is kept, and how it is deleted.
What the app does not access
The app does not request or receive access to customer records, orders, or payment information. These permissions are not part of the app’s access scopes, so this data is never sent to us — not stored, not logged, not processed.
Shopify sends the app mandatory privacy webhooks (customers/data_request and customers/redact). Because no customer data is held, there is nothing to return or erase in response to them; the requests are acknowledged and recorded.
What the app stores
- Store content you asked us to back up: products and variants, product images and files, collections, pages, blogs and articles, metafields and metaobjects, navigation menus, store policies, translations, shipping profile settings, and theme files.
- Store account details: your
.myshopify.comdomain, store currency and time zone, and your subscription plan. - An activity record: every change the app makes to your store, so you can see exactly what was written and when. Request values are stored as one-way hashes, not as readable content.
- Access credentials: the tokens Shopify issues so the app can back up your store on a schedule.
How it is protected
- Access tokens are encrypted before they are written to the database using envelope encryption, and are never written to logs or error reports.
- Backup data is transmitted over TLS and stored encrypted at rest.
- Error reports are filtered before they leave our infrastructure: tokens, encryption keys, connection strings and diagnostic keys are removed, and request bodies and headers are not transmitted.
Where it is stored
Backup files are stored in Cloudflare R2. The database and background job queue are hosted on Railway. Optional error reporting uses Sentry. These providers process data on our behalf as service providers; we do not sell store data or share it for advertising.
How long it is kept
We keep the most recent 5, 20, 50 or 200 stored versions of each individual item, depending on your plan. There is no time limit: a version is kept until newer versions push it past that count, however long that takes. Older versions beyond the limit are removed automatically, and the most recent version of an item is always kept.
When you uninstall the app, Shopify notifies us and all of your store’s data is deleted within 48 hours: every backup file, every version record, and the store account row itself. Deletion is permanent and cannot be undone, so export anything you want to keep before uninstalling. The app’s Export screen produces a ZIP archive of your backed-up content at any time.
Your choices
- Export: download everything the app has backed up, as a ZIP file, from the Export screen.
- Review: see every change the app made to your store on the Activity log screen.
- Delete: uninstall the app to have all stored data erased within 48 hours.
Changes to this policy
If this policy changes, the date at the top of this page is updated. If a change materially affects how store data is handled, merchants using the app will be notified.
Contact
Questions about this policy or about data handling: gencerkrky@gmail.com. Please include your store address so we can identify the account.