Privacy Policy
Lifeboat — Backup & Restore — Last updated: 2026-08-31
Summary
This policy explains how Lifeboat — Backup & Restore ("the App") accesses, stores, and
shares information when a merchant installs it on their Shopify store. The App takes periodic
snapshots of product and inventory data so that a merchant can restore that data after an
unwanted change.
Information we access
-
Product catalog data required to create and restore backups: products, variants, options,
prices, SKUs, tags, product status, and product metafields
- Inventory data: inventory items, tracked state, and inventory quantities per location
- Store metadata needed to operate the service: shop domain and shop ID
- Subscription status provided by Shopify, used to apply plan limits
We do not access customer personal data, order data, or payment details. The
App requests only the scopes it needs for product and inventory backup and restore.
Information we collect directly
-
From merchants: nothing beyond what Shopify's APIs provide, plus the settings you configure
in the App. Those settings include the email address you enter for alerts and the date and
time you consented to receive them
-
From your customers: nothing. The App runs only in the Shopify admin and does not add any
script, cookie, or tracking technology to your storefront
-
Operational logs: we generate records of backup and restore runs (timestamps, counts,
errors) to operate and troubleshoot the service
How we use information
- Create scheduled and on-demand snapshots of your products and inventory
-
Restore a product, recreate a deleted product, or roll back inventory when you ask us to
-
Detect products that appear broken (for example a price of zero, or an active product with
no image) and show them to you
- Apply the limits of your current plan
Data storage and retention
-
When you uninstall the App, Shopify sends us a shop erasure request 48 hours later. On
receiving it we permanently delete every snapshot for your store — both the stored
contents and the metadata — along with your settings and access tokens
-
Snapshot metadata is stored in an encrypted database and expires at the end of your plan's
retention window — 90 days on the free plan, 365 days on the paid plan. Once it
expires, the snapshot is no longer listed and can no longer be restored. This metadata holds
timestamps and counts, and the titles of any products flagged by the zero-price check
-
Snapshot contents are stored in encrypted cloud object storage and are permanently deleted
no later than 400 days after they are taken. This is the outer bound for every plan and is
deliberately longer than the retention windows above, so that a snapshot is never removed
while it is still restorable
-
Access tokens are encrypted with a dedicated managed encryption key and are never stored in
plain text
-
When you uninstall the App, we delete your access tokens immediately and stop all processing
Data processing location
Our infrastructure runs on Amazon Web Services in the United States (us-east-1). If you are
located in the EEA, the UK, or elsewhere, your data may be processed and stored outside your
country or region.
Data sharing
We do not sell, rent, or share your data for advertising. Data is shared only with:
- Shopify APIs, to read the data we back up and to write it back when you restore
- Amazon Web Services, as the infrastructure provider that runs the service
Security
- Access tokens are encrypted at rest using AWS KMS with a per-shop encryption context
- Snapshot storage is encrypted at rest and is not publicly accessible
- All Shopify webhooks are verified by HMAC signature before being processed
- Restore requests are checked so that a store can only ever restore its own snapshots
Your rights and choices
-
You can uninstall the App at any time. Uninstalling stops all further processing and deletes
your access tokens
-
You can request deletion of all stored snapshots at any time by contacting us, or by
requesting a store data erasure through Shopify — we honour Shopify's
shop/redact request by permanently deleting all snapshots and records for your
store
-
Because the App does not store customer personal data, a
customers/data_request or customers/redact request returns no
customer data
Changes to this policy
If we make material changes, we will update the date at the top of this page and, where
appropriate, notify merchants through the App.
Contact
For any question about this policy or your data, contact the support email listed on the
Shopify App Store listing for this app.