Privacy Policy — Harbour
Last updated: August 15, 2026 Effective date: August 15, 2026
This Privacy Policy explains how Octopus Bridge, Inc. (“Octopus Bridge,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Harbour application (“Harbour,” the “App,” or the “Service”) available through the Shopify App Store.
Harbour helps Shopify merchants back up their store data — products, variants, images, collections, and metafields — to secure cloud storage, and delivers a downloadable ZIP archive to the merchant on request.
1. Who we are (Data Controller / Processor)
For most information handled by Harbour, the merchant (you) is the “data controller” under the GDPR and comparable privacy laws, and Octopus Bridge is the “data processor.” We only process store data on the merchant’s instructions and to deliver the Service.
Legal entity: Octopus Bridge, Inc. Registered address: 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA Contact for privacy inquiries: support@octopusbridge.com
2. What we collect
2.1 Information you provide when installing the App
- Shopify shop domain (e.g., your-shop.myshopify.com)
- Shopify Admin API access token (issued by Shopify during OAuth install; stored encrypted at rest)
- Contact email address for your Shopify store (retrieved via Shopify’s contactEmail field) — used only to deliver backup-ready notification emails
2.2 Store data we access to perform backups
When you trigger a backup, Harbour reads the following from your Shopify store using read-only Admin API scopes:
- Products, variants, and inventory quantities
- Product images and files
- Collections (manual and automatic)
- Product metafields
- Store locales and publications configuration
Harbour requests the following Shopify API scopes: read_products, read_product_listings, read_inventory, read_files, read_content, read_locales, read_publications. We do not request or access customer data, orders, financial information, or any personally identifiable customer information.
2.3 Operational data we generate
- Backup job metadata: timestamps, status, byte size, product/image counts, error messages
- Subscription and billing status (managed by Shopify Billing API; we store only the plan handle and status)
- Application logs (for debugging and abuse prevention; retained ≤30 days)
2.4 Information we do NOT collect
- Customer PII (names, emails, addresses, order history)
- Payment card data
- Store staff account credentials
- Analytics or tracking cookies on the merchant admin experience
3. How we use the information
We use the information above only to: – Authenticate your Shopify store during installation and each backup run – Fetch your store data and package it into a downloadable ZIP archive – Store the ZIP archive in encrypted object storage until you download it – Send you a backup-ready notification email with a time-limited download link – Manage your subscription and billing (via Shopify’s managed billing) – Debug issues, respond to support requests, and prevent abuse – Comply with legal obligations
We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your store data to train machine-learning models.
4. Where your data is stored (Sub-processors)
Harbour uses the following sub-processors. Each has a data-processing agreement with us and is contractually obligated to maintain equivalent security standards.
| Sub-processor | Purpose | Location of processing | Website |
| Cloudflare, Inc. | Object storage (R2) for backup archives | United States | https://www.cloudflare.com/privacypolicy/ |
| Neon, Inc. | Managed PostgreSQL database | United States (AWS us-east-2) | https://neon.tech/privacy |
| Fly.io, Inc. | Application compute (VMs) & routing | United States (IAD) | https://fly.io/legal/privacy-policy/ |
| Resend, Inc. | Transactional email delivery | United States | https://resend.com/legal/privacy-policy |
| Shopify, Inc. | Source of your store data (via Admin API) | Global (per Shopify’s policy) | https://www.shopify.com/legal/privacy |
We may update this list as our infrastructure evolves. Material changes will be reflected in the “Last updated” date and, where required, notified to merchants at least 30 days before the change takes effect.
5. How long we keep your data
- Backup ZIP archives: retained per your subscription plan’s retention window (Starter: 30 days, Growth: 60 days, Scale: 90 days, Enterprise: 365 days) from the date each backup was created, then automatically deleted from Cloudflare R2.
- Download links (signed URLs): valid for 7 days from the date the backup completed. After expiry, you can generate a new link from the Harbour dashboard while the underlying archive is still within your plan’s retention window.
- Backup job metadata: retained for the life of your subscription plus 30 days after uninstall, for billing reconciliation and support.
- Shopify session data (encrypted access token): deleted immediately upon app uninstall via Shopify’s app/uninstalled
- Application logs: retained for 30 days for operational debugging, then automatically purged.
You may request earlier deletion at any time using the process in Section 8.
6. Security
We take the following measures to protect your data:
- Encryption in transit: All traffic to and from Harbour is served over HTTPS/TLS 1.2+.
- Encryption at rest: Backup archives are encrypted at rest by Cloudflare R2. Database contents are encrypted at rest by Neon.
- Access controls: Access to production systems is limited to authorized Octopus Bridge personnel, protected by multi-factor authentication.
- Secrets management: Shopify access tokens and API credentials are stored as encrypted secrets and are never logged.
- Network isolation: Application VMs and database instances are not publicly addressable except via authenticated APIs.
- Regular security review: We monitor dependencies for known vulnerabilities and apply security patches promptly.
Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify affected merchants and, where required, regulators within 72 hours of becoming aware of a personal data breach affecting their store (in accordance with GDPR Article 33).
7. International data transfers
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data is transferred to and processed in the United States by the sub-processors listed in Section 4. Such transfers rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
- Adequacy decisions where applicable, and/or
- Data Privacy Framework (DPF) certifications maintained by the relevant sub-processors.
For a copy of the SCCs or additional transfer safeguards, contact us at support@octopusbridge.com.
8. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and comparable laws), you may have the right to:
- Access the personal data we hold about your store
- Correct inaccurate data
- Delete your data (“right to erasure”)
- Restrict or object to certain processing
- Data portability — receive your data in a machine-readable format (this is, effectively, what Harbour does by design)
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
How to exercise your rights
- Delete all your data: Uninstall the Harbour app from your Shopify admin. This triggers Shopify’s app/uninstalled and (for EU merchants) shop/redact We will delete all your data from our systems within 30 days of receiving the redact webhook.
- Access your data: Email support@octopusbridge.com from the store owner’s email on file. We will respond within 30 days.
- Any other request: Email support@octopusbridge.com.
We handle Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) as required by Shopify’s Partner Program Agreement.
9. Children’s privacy
Harbour is a business-to-business tool for Shopify merchants and is not intended for use by individuals under 16. We do not knowingly collect personal information from children.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified via: – The “Last updated” date at the top of this page – A notice in the Harbour app dashboard, and/or – An email to the store contact email on file, at least 30 days before the change takes effect (for material changes affecting how we process data)
Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
11. Contact us
Questions about this Privacy Policy or how we handle your data?
Email: support@octopusbridge.com Postal: Octopus Bridge, Inc., 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA
For EU/UK data subjects, our EU Representative is: Not currently appointed.
