Privacy policy
Last updated 25 August 2026
What we store
When you install StoreVault, we store copies of the store data you ask us to back up: products, collections, pages, blogs and articles, navigation, redirects, inventory levels, themes, and - because a store archive without them is not an archive - your orders and customers. Copies are point-in-time versions of your own data, stored so that you can look at what changed and put back what was lost.
Why we store it
To provide the backup, comparison, export and restore features you installed the app for. For nothing else. We do not analyse your data, do not aggregate it with other merchants' data, do not train models on it, do not sell it and do not share it with anyone.
Emails we send you
We store one address: your store's contact email, which Shopify gives us when you install. We use it for the app itself and nothing else - no newsletters, no product announcements, no third-party senders, and it is never shared or sold.
What actually arrives: a short welcome email once, after your first backup finishes; drill receipts, which are the results of us reading your backup back on a schedule, sent whether they pass or fail; notices about your backup that you need in advance rather than after the fact, such as new snapshots being paused or version history about to be trimmed; and the confirmation link when you ask us to erase everything. Replies go to a person, not a robot.
How long
Version history is kept for the window of your plan (7, 30, 90 or 365 days). At least one copy of each record is kept while the app is installed, so nothing disappears from your backup entirely. If you uninstall, everything is erased about four weeks later - Shopify confirms the uninstall after 48 hours, and we erase 25 days after that. If you want it gone sooner, ask from inside the app and confirm by the link we email to your store contact address: we destroy your encryption key immediately, which makes every stored copy unreadable at once, and remove the data.
One honest detail about our own disaster recovery. Encrypted key-escrow copies exist so that a dead server does not make every customer's backup unreadable; they expire within 7 days, they cannot be decrypted on our servers, and keys of erased stores are excluded from any restore we perform.
How it is protected
Everything is encrypted in transit and at rest. Each store has its own encryption key; that key is stored wrapped by a master key that lives only in the running service's environment. Every read of protected data is logged. Nobody browses your data: there is no console that shows it.
This website
The public pages of this site count page views with Cloudflare Web Analytics. It sets no cookies, collects no identifiers and does not follow you between sites. The app itself - everything behind your Shopify admin - carries no analytics at all: what you do with your own backup is not something we measure.
Two pages - the home page and the how-it-works page - embed a short demo video from YouTube's privacy-enhanced player (youtube-nocookie.com). Loading the page contacts YouTube, so Google sees your IP address as it would for any request to them; the player stores nothing on your device unless you press play. Nothing about your store or your backup is sent there, and the video is the only third-party content on this site.
When you install through a partner
StoreVault runs an affiliate programme through Shoffi. When the app is opened, we send Shoffi your store domain and the IP address of that request, so that an install referred by a partner is credited to them. That is the whole purpose and the whole payload: no order data, no customer data and nothing from your backup ever goes there. Shoffi acts as a processor for us under that single, narrow purpose.
Your customers' rights
If a customer asks you to delete their data, Shopify sends us the request and we remove that person from your stored backups, not just from the live store. If a customer asks for a copy of their data, we produce it for you within the period Shopify requires.