Effective 2026-08-01 · Contact: support@runbackstop.com
Backstop stores company-level business data only, scoped to your shop:
| Data | Contents | Personal data? |
|---|---|---|
| Companies | Shopify company ID, company name, credit limit, exposure, status | No, organization name only |
| Ledger & order state | Order IDs, amounts as integer cents, due dates, timestamps | No |
| Audit entries | Decision records: inputs seen, rule fired, timestamp | No |
| Settings & sessions | App settings; Shopify OAuth session for merchant staff (name/email of the staff user who installed) | Merchant staff only, never storefront customers |
We do not store customer names, emails, phone numbers, or addresses. Order webhook payloads are processed in memory and not persisted; we keep only order IDs, company IDs, money amounts, due dates, and timestamps. Backstop never touches payment card data. Shopify processes all payments; Backstop only controls which payment options appear at checkout.
Backstop reads orders, payment transactions, and refunds for a single purpose: computing each company's outstanding balance so your credit limits can be enforced. That is the app's core function; the data is used for nothing else.
When you uninstall Backstop, access tokens are deleted immediately. Business data is retained for 48 hours (so a quick reinstall keeps your limits, history, and audit trail), then Shopify sends the shop/redact signal and every row belonging to your shop is permanently deleted. GDPR data-request and redaction webhooks are honored: since we hold no customer-level data, customer data requests return an empty report and customer redactions complete trivially.
Data is stored encrypted at rest with our hosting provider. Webhooks are verified with Shopify's HMAC signatures; unverified requests are rejected.
We will update this page if our practices change and note the new effective date above. Questions: support@runbackstop.com.