Privacy Policy for Retrace
Effective Date: 26 August 2026
Retrace respects your privacy. This Privacy Policy details the types of information we collect, how it is used, and how it is protected when you use the Retrace Shopify Application ("the App" or "Service").
Retrace is operated by Kayease Global Solutions LLP, of 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021, and that company is the data controller for the merchant account data described below and the processor for everything we hold on your behalf.
We adhere closely to all GDPR and CCPA requirements, as well as Shopify's Partner program requirements for data protection. Merchants processing personal data through Retrace are also covered by our Data Processing Agreement.
1. Information We Collect
When you install Retrace, we collect and store:
- Shop Information: Your
.myshopify.comdomain, email address (for critical backup alerts), shop timezone, and plan tier. The email address is stored encrypted. - Store Content (Backups): To provide our backup service, we fetch and securely store representations of your Products, Collections, Metaobjects, Pages, Blogs, Menus, Themes, and Settings.
- Order Records: Order identifiers, totals, line items, financial and fulfilment status, notes, tags, shipping address, and the associated customer reference. Shopify permits Retrace to read orders placed in the last 60 days only; each backup captures orders within that window, anything older is never fetched, and the App says so wherever order backups are shown. Orders are captured for reference and export only, and are never restored — recreating a deleted order would manufacture a financial record that never happened.
- Customer Data (If Approved): Only if approved by Shopify's Protected Customer Data program, we back up customer records: customer ID, first and last name, email address, phone number, billing and shipping addresses, marketing consent state, notes, tags, account state, and customer metafields. We NEVER process payment methods or complete credit card profiles.
We process the minimum personal data required to provide backup and recovery. Retrace requests read-only access to customers and orders, and no write access to either.
2. How We Use Your Information
We use your data exclusively to operate the Retrace service:
- To maintain an encrypted history of your store's resources.
- To execute your authorized restore requests.
- To notify you of critical alerts like failing backups or account exhaustion.
We limit our use of personal data to those purposes. Specifically, we do not:
- sell, rent, share or otherwise disclose personal data to any third party for their own purposes;
- use personal data for advertising, marketing, audience building or profiling;
- use personal data for automated decision-making of any kind;
- use personal data to train machine learning models;
- write customer records back to your store — customer data is read-only in Retrace.
We do not sell, rent, or monetize your store's data in any way, shape, or form.
3. Data Protection and Encryption
- At Rest: Backups are compressed and encrypted in storage using AES-256-GCM. Each shop's data is secured by a unique Data Encryption Key (DEK), which is itself wrapped by a master key held outside the database — so a stolen copy of the database yields ciphertext only.
- In Transit: All data exchanges between Retrace and Shopify occur over HTTPS.
- Staff Access: Our staff cannot read your store's content. The internal operations dashboard exposes only counts, sizes, timestamps, statuses and store domains; there is no staff-facing path that decrypts merchant data. When support genuinely needs to see content, you export it and send it to us.
- Audit Trail: Every action Retrace takes is written to an append-only activity log. Rows are never updated or deleted.
- Incident Response: We maintain a written Security Incident Response Policy, published in full, including notification to affected merchants within 72 hours of confirming a breach.
4. Where Your Data Is Held
- The application and its database are operated on a server provided by Hostinger, located in India (Mumbai).
- Your encrypted backups — every snapshot, theme and file asset, and export archive — are held in object storage provided by MinIO, located in India (Mumbai).
- Alert email to the address on your shop record is delivered by Google (Gmail SMTP), sending from Global (Google data centres). The email carries your store's domain and the state of your backups; it never carries store content.
The complete list of sub-processors — who they are, what each one does, and the region each operates in — is in section 10 of the Data Processing Agreement, and we give notice before adding or replacing any of them.
Where personal data is transferred outside the jurisdiction in which it was collected, we rely on an appropriate transfer mechanism under applicable law, including the Standard Contractual Clauses where required.
5. Data Retention
We keep personal data only as long as it is needed to provide the service you have chosen.
Each plan carries a retention window — the age beyond which saved versions are deleted by a scheduled job that runs nightly. The windows are 7 days on the Free plan (and for a store with no plan assigned), 30 days on Starter, 90 days on Professional and 365 days on Business; a custom plan's window is whatever was agreed in writing. Your current window is shown in the app, and you can shorten it — never lengthen it — from Settings, or delete your history outright from the Retrace dashboard at any time.
Three things qualify those windows, and all three are enforced in code rather than promised in prose:
- The newest saved version of any item is never deleted, however old it is.
- If you downgrade, the previous longer window is honoured for a further 7 days after the new plan takes effect, and we email you when that clock starts.
- A failed payment never deletes anything: capture pauses 7 days after the failure and the store is marked dormant after 30, but nothing already saved is removed at either step.
The same numbers, with the effect of an uninstall, are in section 8 of the Terms of Service.
All retained data remains encrypted for its whole lifetime, and is destroyed as described in section 6.
6. Data Deletion and GDPR Rights
You have absolute control over your backup history.
- In-App Deletion: You can delete your history from the Retrace Dashboard at any time.
- App Uninstall: Uninstalling stops the service and ends your subscription, but does not itself erase anything, so a reinstall finds your history intact. Shopify then sends the mandatory
shop/redactrequest, normally about 48 hours after the uninstall. On receiving it we delete every object we hold for your store from object storage, delete the stored records, and permanently destroy your store's Data Encryption Key, so that anything that could survive those deletions is unreadable for ever. Only your store's domain and the timestamps proving the erasure happened are kept. - Customer Erasure: On
customers/redact, we delete the identified shopper's customer record and its version history, delete the stored copies of every order Shopify names in the request, rewrite every other stored order so that it no longer carries the shopper's name, address or phone number, and destroy any export archive that contained them. Because Shopify keeps the shopper on orders it did not name, a later backup of a still-installed store may capture those orders again; the erasure covers what we hold at the moment it is carried out. - Data Requests: On
customers/data_request, we work out exactly which stored records concern the shopper and pass that to the merchant, who owes the shopper an answer within 30 days. For anything those channels cannot cover, contact us and we will assist within the timeframes applicable law places on you.
7. Third-Party Services
Retrace integrates directly with:
- Shopify API: For fetching and restoring your data. Shopify is the source of this data and your own processor for it, under your agreement with them rather than ours.
- Our sub-processors: Hosting, encrypted object storage and transactional email, each named with its region in section 10 of the Data Processing Agreement.
8. Updates & Contact
We may update this Privacy Policy from time to time. You will be notified of material changes.
For any privacy or GDPR compliance question, including a request from a data subject or a supervisory authority, contact sunny@kayease.com. For anything else, write to sunny@kayease.com or use the support channel in the Retrace app. Our postal address is 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021.