1. Purpose #
These terms set out how the Vaultify service — an online platform for backing up, restoring and migrating Shopify store data — is supplied by underscore.icu ("the Publisher").
They prevail over any other document, in particular the Subscriber's purchasing terms. Any conflicting term is unenforceable against the Publisher unless accepted in writing.
2. Definitions #
- Subscriber
- The business or professional subscribing to the Service.
- Store
- A Shopify store connected to the Service by the Subscriber, identified by its
*.myshopify.comdomain. - Store Data
- All data extracted from a Store through the Shopify API and held by the Service: products, collections, customers, orders, content, themes, metadata and associated media.
- Backup
- A timestamped copy of the Store Data at a point in time, stored in the open NDJSON format together with the media files.
- Restore
- Writing all or part of a Backup back into a Store, whether the original one (rollback) or another Store belonging to the Subscriber (migration).
- Dry-run
- A Restore executed without any write, producing a report of what would be created, updated or skipped.
3. The service #
3.1 Backup scope
The Service backs up 25 Shopify resource types: store settings, locations, policies, shipping, markets, languages, metaobject definitions and metaobjects, products, collections, inventory, customers, draft orders, inventory transfers, gift cards, orders, discounts, price rules, pages, blogs, articles, navigation, redirects, files and themes, together with the associated media.
Whether a given type is actually backed up depends on the permissions the Subscriber grants on their Store and on their selection in the interface.
3.2 Restorable scope
Not everything that is backed up can be restored. 14 types can be written back into a Store: products, collections, pages, blogs, articles, navigation, redirects, files, themes, metaobjects and their definitions, inventory, draft orders and discounts.
Orders and inventory transfers are export-only: they are backed up and downloadable, but never written back into Shopify, since re-injecting an order history would corrupt the Store's accounting. Restore reports flag them explicitly.
3.3 Frequency and retention
Backups run manually or on a schedule set by the Subscriber (daily, weekly, monthly or one-off), within the minimum frequency allowed by their plan. The Subscriber sets the retention policy per Store: how many Backups to keep and/or a maximum age. A nightly purge removes expired Backups.
3.4 Technical limits
- The quotas of the chosen plan apply: number of connected Stores, number of users, included storage, minimum frequency, retention period.
- One active Backup per Store at a time, so as not to saturate the Store's API.
- The Service is subject to Shopify's API rate limits, which may extend the duration of a Backup or a Restore, beyond the Publisher's control.
- Shopify may change, restrict or remove API endpoints: the scope of the Service may change accordingly.
4. Account and installation #
The Service is available in two modes:
- Agency mode: an account is created on the platform, and each Store is connected using a custom app the Subscriber creates in the Shopify admin, whose access token they provide.
- App Store mode: the Vaultify app is installed from the Shopify App Store, with permissions granted directly in the Store's admin.
The permissions requested cover reading the resources to be backed up and writing the restorable ones. They are listed in the privacy policy. The Subscriber may revoke them at any time by uninstalling the app or deleting the token, which stops the Service for that Store.
The Subscriber is responsible for keeping their credentials confidential and for the use made of their account. Enabling two-factor authentication is recommended.
5. Pricing, billing and trial #
Plans, prices and limits are listed on the Pricing page, which is authoritative. Prices are exclusive of tax; VAT is added as applicable.
Billing depends on how the subscription was bought:
- Direct subscription: card payment through our provider Stripe, in the currency shown on the Pricing page. No card data passes through our servers.
- Subscription through the Shopify App Store: billed through the Shopify Billing API, charged on the merchant's Shopify invoice.
The subscription is monthly and renews automatically unless terminated before the end of the term.
A free trial is offered at sign-up. When it ends without a subscription, the account becomes read-only: existing Backups remain accessible and exportable, but no new Backup runs.
If a payment fails, the account keeps working during a grace period, then becomes read-only. Existing Backups are never deleted because of a payment failure.
6. Right of withdrawal #
You have fourteen days from subscribing to withdraw from your subscription, without giving a reason and at no cost. This applies to every subscriber, whatever their size and however they subscribed.
This is a contractual commitment on our part, not a legal obligation we are bound by. The right of withdrawal under French consumer law is for consumers; its extension to businesses by article L221-3 requires three cumulative conditions — a contract concluded off-premises (doorstep selling, a face-to-face meeting), subject matter falling outside the subscriber's main field of activity, and no more than five employees — which a subscription taken out online, at a distance, does not meet. We chose to grant it anyway: it is yours for the term of your contract and we cannot withdraw it mid-subscription.
6.1 How to withdraw
Two ways, whichever suits you — the first is the fastest:
- The online withdrawal function: the "Withdraw from this contract here" button, available in your billing workspace throughout the withdrawal period. Once confirmed, we send you a timestamped acknowledgement by email without delay.
- By email, to , in an unambiguous statement.
We voluntarily follow the arrangements set out in article L221-21 of the French Consumer Code, created by ordinance no. 2026-2 of 5 January 2026 and its decree no. 2026-3 of the same day: a function available online throughout the withdrawal period, a confirmation step, and a timestamped acknowledgement on a durable medium.
6.2 Effects of withdrawal
We refund you within fourteen days of receiving your request, using the same means of payment you used to subscribe, unless you expressly agree to another.
One reservation, under article L221-25 of the French Consumer Code: if you asked for the Service to start before the end of the period — which is the case from the first Backup — we may retain an amount proportionate to what has already been supplied up to the date of your withdrawal. The remainder is refunded.
Where the subscription was bought through the Shopify App Store, the refund is made against the merchant's Shopify invoice; it may take the form of a credit applied to subsequent invoices, within the limits of the Shopify platform.
7. Subscriber obligations #
The Subscriber undertakes to:
- hold the necessary rights over the Store Data entrusted to the Service, and to submit only lawful data;
- inform the individuals concerned — in particular the customers of their Stores — that a backup provider is used, and to have a legal basis for that processing;
- check every Restore: run the dry-run, review the report, and prefer a trial on a staging store before writing to production;
- not circumvent plan quotas, attempt to access another subscriber's data, or disrupt the Service;
- keep the access permissions for their Stores valid.
A Subscriber managing Stores on behalf of third parties warrants that those third parties comply with the same obligations.
8. Warranties #
The Publisher supplies the Service with the care and diligence of a professional. It owes an obligation of means, not of result.
The Service depends on a third-party API outside the Publisher's control. Accordingly, the Publisher does not warrant:
- the completeness or absolute integrity of a Backup: data that the Shopify API does not expose, or restricts, cannot be captured;
- that a Restore will succeed in full: Shopify may reject resources on validation, permission or consistency grounds;
- that a migration between two Stores with differing configurations will be a perfect reproduction.
The Service does not relieve the Subscriber of their own checks. It is for them to verify periodically that Backups run, to download a copy where they see fit, and to test a Restore on a test store.
9. Liability #
The Publisher is liable for direct damage caused by a proven fault in performing the Service.
Its total liability, on any ground, is capped at the amounts actually paid by the Subscriber over the twelve months preceding the triggering event.
Indirect damage is excluded: loss of revenue, loss of customers, damage to reputation, as well as any data loss occurring within the Subscriber's Store or at Shopify and unrelated to the Service.
These limitations do not apply in cases of gross negligence or wilful misconduct, personal injury, or wherever the law forbids them. No clause of these terms may operate to exempt the Publisher from all liability under its essential obligation.
The Subscriber indemnifies the Publisher against any third-party claim, in particular from a customer or a merchant, arising from the content of the Store Data or from the Subscriber's breach of its obligations.
10. Availability and maintenance #
The Publisher endeavours to keep the Service continuously available. It may interrupt it for maintenance, giving notice where possible and favouring quieter periods.
Interruptions attributable to Shopify, to the host or to telecommunications networks cannot be attributed to the Publisher.
11. Term, termination and data #
The subscription runs for the period bought and renews automatically. The Subscriber may terminate at any time from their workspace or, in App Store mode, by uninstalling the app; termination takes effect at the end of the current period, without pro-rata refund.
The Publisher may suspend or terminate for material breach, in particular unlawful use or persistent non-payment, after a formal notice left unanswered for fifteen days, save in urgent cases involving security.
What happens to data after termination
- Before deletion, the Subscriber can export their Backups as a ZIP archive (NDJSON and media), an open format usable outside the Service.
- App Store mode: uninstalling revokes access and pauses the Store; Shopify then sends the redaction request, forty-eight hours after uninstall, and the account created by the app together with its Backups is deleted.
- Agency mode: deleting a Store or the account deletes the corresponding Backups and their files.
12. Data protection #
The parties expressly acknowledge the following split of roles:
- the Publisher is controller for the Subscriber's account data: identity, billing, logs, support;
- the Publisher is a processor within the meaning of GDPR article 28 for the Store Data, the Subscriber — or the merchant whose Store they manage — remaining the controller. The Publisher acts only on documented instructions and never uses that data for its own purposes.
The terms of that processing are set out in the data processing agreement, which forms an integral part of these terms. Details of the processing appear in the privacy policy.
13. Force majeure and general #
Neither party is liable for a failure caused by force majeure within the meaning of article 1218 of the French Civil Code, including a prolonged failure of Shopify, of the host or of telecommunications networks.
The Publisher may amend these terms; the Subscriber is notified at least thirty days before they take effect and may terminate free of charge if they refuse them.
If a provision is held void, the remainder continues to apply. Tolerating a breach is not a waiver.