1. Our two roles #
Vaultify backs up the contents of Shopify stores. Those contents include personal data belonging to your own customers: names, addresses, order histories. We never process them for our own purposes.
| Data | Our role | Who decides |
|---|---|---|
| Your Vaultify account: identity, email, billing, sign-in logs, support exchanges | Controller | Vaultify (section A) |
| Content backed up from your Shopify store: customers, orders, products, content, themes, metadata | Processor (GDPR art. 28) | You, as controller (section B) |
Controller for section A: underscore.icu, [TO COMPLETE: legal name, company form, registered office, company number]. Contact: .
No data protection officer has been appointed: GDPR article 37 makes an appointment mandatory in three cases — a public authority or body, regular and systematic monitoring of individuals on a large scale, or large-scale processing of special category data under article 9 — and none of them applies here. Vaultify carries out neither profiling nor monitoring, and processes no special category data intentionally. Requests are handled by the contact above.
2. Section A — Vaultify as controller #
These processing activities concern your relationship with us, not the contents of your stores.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account creation and management | Name, email, hashed password, two-factor secret where enabled, company the account belongs to | Performance of the contract | Life of the account, then [TO COMPLETE: deletion period] |
| Billing and subscription | Billing details, payment provider customer id, subscription history. We store no card data. | Performance of the contract, statutory accounting obligation | 10 years (French accounting obligation) |
| Audit and security log | Actions performed in the application (who, what, when), IP address, sign-ins | Legitimate interest: traceability, evidence, security | [TO COMPLETE: log retention — no automatic purge is configured today] |
| Support and demo requests | Name, work email, agency, requested slot, content of the exchange | Legitimate interest: answering an enquiry | 3 years from last contact |
| Service notifications (failed backup, completed transfer) | Notification email address | Performance of the contract | Life of the account |
No profiling or automated decision-making producing legal effects is carried out. We neither sell nor rent this data.
3. Section B — Vaultify as processor #
When you connect a store, you entrust us with its contents so that we can back them up. You remain the controller; we act solely on your documented instructions, expressed through your settings in the application: the resource types you select, the schedule, the retention policy, the destination disk, and the restores you trigger.
Categories of data involved
The scope depends on the permissions you grant and the types you select. The permissions the application requests cover 25 Shopify resource types, several of which contain personal data:
- Customers: identity, postal addresses, email, phone, marketing consent status, account history.
- Orders and draft orders: line items, billing and shipping addresses, amounts, payment and fulfilment statuses, notes.
- Gift cards: recipient and balances.
- Content and metadata: pages, blog articles, files, metaobjects — which may contain personal data depending on how you use them.
- Products, collections, inventory, themes, markets, translations: normally free of personal data.
We have no access to payment data: card numbers are not exposed by the Shopify API and therefore never appear in a backup.
How long backups are kept
That is set by you, store by store, through the retention policy: how many recent backups to keep and/or a maximum age. A purge runs nightly and removes expired versions, their storage and any orphaned media. If you set no rule, backups are kept indefinitely for as long as the account exists. [TO COMPLETE: default retention to adopt, and should one be enforced?]
What happens to data when the contract ends
- Shopify app installed from the App Store: uninstalling immediately revokes our access and pauses the store. Shopify then sends us the shop redaction request (48 hours after uninstall): we delete the account created by the app, its backups and the associated files.
- Agency account: deleting a store or an account deletes the corresponding backups and their files. [TO COMPLETE: purge period after an agency subscription ends — no automatic purge is triggered by the end of a subscription alone]
- You can export your backups in the open NDJSON format, as a ZIP archive, before any deletion.
Assistance with data subject rights
We assist you in answering requests you receive from your own customers: locating a record in a backup, targeted deletion, export. The terms of that assistance are set out in our data processing agreement.
4. Hosting and data location #
The platform and backup storage are hosted with IONOS, in data centres located in the European Union.
A transfer outside the European Union does happen, and we would rather say so. Vaultify reads your store data through Shopify's Admin API, to which you already entrusted it when you opened your store. For European merchants the contracting entity is Shopify International Ltd. (Ireland); data may be transferred to its parent Shopify Inc., established in Canada — a country the European Commission recognises as providing an adequate level of protection — and to other group entities, on the basis of Shopify's Binding Corporate Rules and the standard contractual clauses of decision (EU) 2021/914 of 4 June 2021. Once retrieved, the data is stored in Europe.
No other transfer outside the EU is carried out without a valid transfer mechanism and prior notice.
5. Sub-processors #
| Provider | Role | Location | Safeguards |
|---|---|---|---|
| IONOS | Hosting of the platform and of backup storage | European Union | Processing agreement, data held within the EU |
| Shopify International Ltd. (EU contracting entity) and Shopify Inc. | Source of the data: the store's API | Ireland / Canada | Canada adequacy decision, Shopify Binding Corporate Rules, SCCs (EU) 2021/914 |
| Stripe | Payment for subscriptions bought directly (agency mode) | Ireland / United States | Standard contractual clauses; no card data passes through our servers |
| Shopify (Billing API) | Payment for subscriptions bought through the App Store, charged on the merchant's Shopify invoice | United States | See above |
| Amazon Web Services (S3) | Object storage, only if you choose that storage mode — the bucket may be your own | Region of your choosing | Optional; otherwise storage stays with IONOS |
| Axeptio | Cookie consent collection | France | See the cookie policy |
| Bunny Fonts | Serving the public site's web fonts | European Union | Cookie-free, tracking-free service |
| Transactional email | Service notifications, address verification, invitations | [TO COMPLETE: chosen SMTP provider and its location] | [TO COMPLETE] |
| Sentry | Application error tracking — disabled by default, can be enabled in production | European Union (EU region required if enabled) | No backup data is transmitted; only technical error messages are |
6. Security #
The measures in place are described in full on the Security page. In short:
- Encryption in transit: TLS on every connection, both to the platform and to the Shopify API.
- Shopify access tokens encrypted in the database, never displayed again and never logged.
- Encryption at rest for backups: provided by the underlying storage (volume encryption, or server-side encryption of the object store). [TO CONFIRM: to be enabled and documented with the host — the service adds no application-level encryption on backup files.]
- Isolation: each customer sees only their own stores and backups; isolation is enforced at the database query and authorization layers, and covered by automated tests.
- Access control: distinct roles, optional two-factor authentication, time-limited signed download links.
- Logging of sensitive actions.
In the event of a data breach, we notify the French supervisory authority (CNIL) within 72 hours where notification is required, and inform affected customers without undue delay so they can meet their own obligations.
7. Your rights #
For section A data, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions on what happens to your data after your death. Where processing relies on your consent, you may withdraw it at any time, without affecting the lawfulness of processing already carried out.
Send your request to . We reply within one month, extendable by two months for complex requests.
8. If you are a customer of a store #
You may have come across Vaultify because a shop you ordered from uses our service to back up its data.
Send your request to the merchant, not to us: they decide what is processed and they can identify your record. We have no way to verify your identity or to link a request to a person inside the data of a store we are not responsible for. We assist the merchant as soon as they ask.
If the merchant does not respond, you may still lodge a complaint with your supervisory authority.
9. Contact and complaints #
Contact: [TO COMPLETE: email and postal address].
You may lodge a complaint with the French data protection authority: www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the supervisory authority of your own country.