Privacy Policy
Last updated 2 September 2026
This policy explains what personal data Kepvia collects, why, how it is protected, and what rights you have over it. It covers both the data we hold about you as a merchant and the store data we process on your behalf.
1. The data we collect
We handle two distinct kinds of data, and they are treated differently.
Account data — about you, the merchant
- your store’s myshopify domain, shop name, plan, country and currency;
- the email address on the store, used for service notices and support;
- subscription status and billing history (Shopify holds the payment details, not us);
- technical logs — IP address, timestamps, requested endpoint, error traces — retained for security and debugging.
Store data — the backups themselves
When you run a backup we copy the records you have chosen: products, collections, pages, blogs, articles, menus, themes and assets, files, metaobjects, metafield definitions, policies and shipping zones, and — on paid plans, where Shopify grants access — orders, customers and customer segments.
Order and customer records may contain your customers’ personal data: names, email and postal addresses, phone numbers and order histories. We hold this only as a processor acting on your instructions. You decide what is captured and for how long. The terms of that relationship are in the Data Processing Addendum.
We do not track visitors across other websites, and the marketing site sets no advertising cookies.
2. Why we process it, and on what basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the backup, restore, export and migration features | Performance of a contract — Art. 6(1)(b) |
| Billing, invoicing and keeping financial records | Contract and legal obligation — Art. 6(1)(b), (c) |
| Responding to support requests | Contract and legitimate interests — Art. 6(1)(b), (f) |
| Securing the service, preventing abuse, diagnosing faults | Legitimate interests — Art. 6(1)(f) |
| Service announcements about outages or material changes | Legitimate interests — Art. 6(1)(f) |
| Optional product emails | Consent — Art. 6(1)(a) |
Where processing rests on legitimate interests, we have considered the effect on you and limited the processing accordingly.
4. Your choices
Service messages — billing notices, failed backups, security alerts — are part of the product and cannot be switched off while you use it. Anything promotional is opt-in, and every such email carries an unsubscribe link. You can also email privacy@kepvia.com to opt out at any time.
5. How we protect it
- All traffic is encrypted in transit over TLS.
- Access tokens for your store, destination stores and connected cloud accounts are encrypted at rest with a key held outside the database.
- Backup storage is not publicly reachable; downloads are issued as single-use, expiring links.
- Access to production systems is limited to the personnel who need it, under confidentiality obligations.
- We never ask for your Shopify password. Access is granted through Shopify OAuth and revoked the moment you uninstall.
Servers and backup storage are located in TODO_HOSTING_PROVIDER_AND_REGION. No method of storage is perfectly secure, but we work to a standard appropriate to the sensitivity of the data.
6. Sub-processors
We use a small number of third parties to run the Service. Each is bound by contract to protect the data and to use it only as we instruct.
| Provider | Purpose | Engaged |
|---|---|---|
| TODO_HOSTING_PROVIDER | Application hosting, database and backup storage | Always |
| Shopify Inc. | The platform the data is read from and written back to; also processes subscription billing | Always |
| Google LLC (Google Drive) | Delivery of scheduled backup exports | Only if you connect it |
| Dropbox, Microsoft (OneDrive), pCloud | Delivery of backup exports to a connected cloud account | Only if you connect it |
We will give notice before adding a sub-processor that handles customer data, as described in the DPA.
7. Who we share it with
We do not sell personal data and we do not share it for advertising. Beyond the sub-processors above, we disclose data only where you direct us to (for example, exporting a backup to your Google Drive or writing it into a destination store), or to a successor entity in connection with a merger, acquisition or sale of assets — in which case this policy continues to apply until you are told otherwise.
8. Legal disclosure
We may disclose data where we are legally compelled to, or to establish or defend legal claims. Where we are permitted to tell you first, we will.
9. How long we keep it
Backups are retained for the history window of your plan. Older versions are removed automatically as that window rolls forward.
| Plan | Backup history retained |
|---|---|
| Free | 1 month |
| Starter | 6 months |
| Pro and Enterprise | 12 months |
When you uninstall, captures stop and your existing backups are held for the remainder of that window so a reinstall can still recover them, then deleted. You can ask us to delete everything sooner by emailing privacy@kepvia.com; we action such requests within 30 days. Account and billing records are kept for as long as tax and accounting law requires.
10. Shopify data requests
Kepvia implements the mandatory Shopify privacy webhooks. When a shopper asks a merchant for their data or its erasure, or when a store is redacted after uninstalling, Shopify notifies us and we respond within the periods Shopify requires — returning the data we hold on that shopper, or deleting it.
11. International transfers
Data may be processed outside the country where you or your customers are located. Where personal data protected by UK or EU law is transferred elsewhere, we rely on an adequacy decision or on Standard Contractual Clauses, as set out in the DPA.
12. Children's privacy
Kepvia is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
13. External links
Our site and app link to third-party services such as Shopify and Google Drive. Their privacy practices are their own, and we are not responsible for them.
14. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable format, to withdraw consent, and to complain to your data protection authority.
To exercise any of these, email privacy@kepvia.com. We respond within 30 days.
If your request concerns a shopper’s data held in a merchant’s backup, that merchant is the controller — we will refer you to them and assist them in responding.
15. Contact us
This policy is issued by TODO_LEGAL_ENTITY_NAME, registered at TODO_REGISTERED_ADDRESS. Privacy enquiries: privacy@kepvia.com. We may update this policy; material changes will be notified in the app or by email, and the date above will change.