BackNest ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that keeps restorable versions of a merchant's own store data, products, collections, pages, blog articles and inventory quantities, and restores them on the merchant's instruction. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
Contact / Data Protection: support@appnest.studio
1. Who the data belongs to
The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's store data solely to provide backup and restore.
2. What we access and why
| Scope | Why |
|---|---|
read_products, write_products |
Version products and collections; restore or recreate them |
read_content, write_content |
Version pages and blog articles; restore or recreate them |
read_inventory, write_inventory, read_locations |
Version inventory quantities per location; restore them |
The App does not request access to orders, customers, payments or themes. It never receives customer personal data.
3. What we store
| Data | Stored? | Notes |
|---|---|---|
| Shopify session / access token | Yes | Required to call the Admin API |
| Versions of products, collections, pages, articles, inventory levels (compressed) | Yes | For your plan's history period (7 / 90 / 365 days); the latest version of each item is always kept |
| Restore runs and their per-item results | Yes | 90 days |
| Alert email / Slack webhook URL | Yes | Where to notify you |
| Orders, customers, payment or theme data | No | Never requested |
4. Data retention & deletion
- Versions are retained for your plan's history period and pruned automatically.
- On app uninstall and on the Shopify
shop/redactcompliance webhook, we delete all data for that store. - We honour
customers/redactandcustomers/data_request. Because we hold no customer data, there is nothing to return or erase.
5. Subprocessors / third parties
| Provider | Purpose | Data shared |
|---|---|---|
| Hosting (Railway) + Postgres/Redis | Run the App | Stored data listed in §3 |
| Resend | Alert emails (if configured) | Your alert email + alert summary |
| Slack | Alert messages (if configured) | Your webhook + alert summary |
| Sentry | Error tracking (if configured) | Diagnostic error data |
We do not sell personal data or use it for advertising.
6. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
7. Security
- All API traffic is over HTTPS; snapshots are stored compressed in an encrypted-at-rest database.
- Restores write only the fields you selected; inventory restores are guarded so a value changed since the snapshot is never overwritten blindly.
8. Your rights
Merchants can export or delete their data by uninstalling the App (triggers full deletion) or by contacting us at the address above. Data subjects should contact the merchant (controller) for GDPR/CCPA requests; we assist the merchant in fulfilling them.
9. Changes
We will update this policy as the App evolves and revise the "Last updated" date above.
BackNest by AppNest Studio · support@appnest.studio