Video
Overview
24sevenCommerce - POS and eCommerce Integration
+1 408-643-0097
Live Chat
  • Home
  • Integrations
    • POS
      • Acceo SmartVendor
      • Auto-Star POS
      • Bepoz
      • Counterpoint POS
      • ClearTEQ POS
      • Dynamics GP
      • Heartland Retail
      • JCSSoft POS
      • Keystroke
      • Korona POS
      • Lightspeed (R Series)
      • Lightspeed (X-Series)
    • More POS
      • Liquor POS
      • Microsoft RMS
      • Linga POS
      • Osprey POS
      • PC America CRE
      • Quickbooks POS
      • Retail Pro 8 & 9
      • Retail Pro Prism
      • Retail Plus POS
      • RMH
      • Ranger POS
      • Realtime POS
    • More POS
      • RepairShopr
      • RDT System
      • RetailEdge
      • Storis POS
      • Smyth Retail
      • Square POS
      • Shopify POS
      • TallySales
      • The General Store
      • Vend HQ POS
      • Visual Retail Plus
      • Zedonk ERP
      • Z Software Integration
    • eCommerce
      • Bigcommerce
      • CMS Max
      • Liquor Max
      • Local Express
      • Magento
      • Shopify
      • Shopping Cart Elite
      • WooCommerce
      • Wix
    • MarketPlaces
      • Amazon
      • eBay
      • Google Shopping
      • Google Local Inventory Ads
      • Walmart
    • Other Integrations
      • B.O.P.I.S.
      • CNET Items Database
      • Electronic Shelf Label
      • Lightspeed Smart Receipts
      • OTB Planning Reports
      • Shipworks
      • Shipstation
      • Retail Advisor
      • WooCommerce B2B App
  • Product & Services
    • Octopus Bridge
    • Website Development
    • Catalog Management
    • Social Media Marketing
  • Resources
    • Octopus Channel API
    • Octopus Rest API
    • Manuals
    • Customers
    • Videos
    • Media
    • Blog
    • Customer Surveys
    • Testimonials
  • Partners
  • Company
    • About Us
    • Contact Us
    • Careers
    • Retail News
    • News
    • Octopus Survey

Privacy Policy — Harbour

Last updated: August 15, 2026 Effective date: August 15, 2026

This Privacy Policy explains how Octopus Bridge, Inc. (“Octopus Bridge,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Harbour application (“Harbour,” the “App,” or the “Service”) available through the Shopify App Store.

Harbour helps Shopify merchants back up their store data — products, variants, images, collections, and metafields — to secure cloud storage, and delivers a downloadable ZIP archive to the merchant on request.

1. Who we are (Data Controller / Processor)

For most information handled by Harbour, the merchant (you) is the “data controller” under the GDPR and comparable privacy laws, and Octopus Bridge is the “data processor.” We only process store data on the merchant’s instructions and to deliver the Service.

Legal entity: Octopus Bridge, Inc. Registered address: 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA Contact for privacy inquiries: support@octopusbridge.com

2. What we collect

2.1 Information you provide when installing the App

  • Shopify shop domain (e.g., your-shop.myshopify.com)
  • Shopify Admin API access token (issued by Shopify during OAuth install; stored encrypted at rest)
  • Contact email address for your Shopify store (retrieved via Shopify’s contactEmail field) — used only to deliver backup-ready notification emails

2.2 Store data we access to perform backups

When you trigger a backup, Harbour reads the following from your Shopify store using read-only Admin API scopes:

  • Products, variants, and inventory quantities
  • Product images and files
  • Collections (manual and automatic)
  • Product metafields
  • Store locales and publications configuration

Harbour requests the following Shopify API scopes: read_products, read_product_listings, read_inventory, read_files, read_content, read_locales, read_publications. We do not request or access customer data, orders, financial information, or any personally identifiable customer information.

2.3 Operational data we generate

  • Backup job metadata: timestamps, status, byte size, product/image counts, error messages
  • Subscription and billing status (managed by Shopify Billing API; we store only the plan handle and status)
  • Application logs (for debugging and abuse prevention; retained ≤30 days)

2.4 Information we do NOT collect

  • Customer PII (names, emails, addresses, order history)
  • Payment card data
  • Store staff account credentials
  • Analytics or tracking cookies on the merchant admin experience

3. How we use the information

We use the information above only to: – Authenticate your Shopify store during installation and each backup run – Fetch your store data and package it into a downloadable ZIP archive – Store the ZIP archive in encrypted object storage until you download it – Send you a backup-ready notification email with a time-limited download link – Manage your subscription and billing (via Shopify’s managed billing) – Debug issues, respond to support requests, and prevent abuse – Comply with legal obligations

We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your store data to train machine-learning models.

4. Where your data is stored (Sub-processors)

Harbour uses the following sub-processors. Each has a data-processing agreement with us and is contractually obligated to maintain equivalent security standards.

Sub-processor Purpose Location of processing Website
Cloudflare, Inc. Object storage (R2) for backup archives United States https://www.cloudflare.com/privacypolicy/
Neon, Inc. Managed PostgreSQL database United States (AWS us-east-2) https://neon.tech/privacy
Fly.io, Inc. Application compute (VMs) & routing United States (IAD) https://fly.io/legal/privacy-policy/
Resend, Inc. Transactional email delivery United States https://resend.com/legal/privacy-policy
Shopify, Inc. Source of your store data (via Admin API) Global (per Shopify’s policy) https://www.shopify.com/legal/privacy

We may update this list as our infrastructure evolves. Material changes will be reflected in the “Last updated” date and, where required, notified to merchants at least 30 days before the change takes effect.

5. How long we keep your data

  • Backup ZIP archives: retained per your subscription plan’s retention window (Starter: 30 days, Growth: 60 days, Scale: 90 days, Enterprise: 365 days) from the date each backup was created, then automatically deleted from Cloudflare R2.
  • Download links (signed URLs): valid for 7 days from the date the backup completed. After expiry, you can generate a new link from the Harbour dashboard while the underlying archive is still within your plan’s retention window.
  • Backup job metadata: retained for the life of your subscription plus 30 days after uninstall, for billing reconciliation and support.
  • Shopify session data (encrypted access token): deleted immediately upon app uninstall via Shopify’s app/uninstalled
  • Application logs: retained for 30 days for operational debugging, then automatically purged.

You may request earlier deletion at any time using the process in Section 8.

6. Security

We take the following measures to protect your data:

  • Encryption in transit: All traffic to and from Harbour is served over HTTPS/TLS 1.2+.
  • Encryption at rest: Backup archives are encrypted at rest by Cloudflare R2. Database contents are encrypted at rest by Neon.
  • Access controls: Access to production systems is limited to authorized Octopus Bridge personnel, protected by multi-factor authentication.
  • Secrets management: Shopify access tokens and API credentials are stored as encrypted secrets and are never logged.
  • Network isolation: Application VMs and database instances are not publicly addressable except via authenticated APIs.
  • Regular security review: We monitor dependencies for known vulnerabilities and apply security patches promptly.

Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify affected merchants and, where required, regulators within 72 hours of becoming aware of a personal data breach affecting their store (in accordance with GDPR Article 33).

7. International data transfers

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data is transferred to and processed in the United States by the sub-processors listed in Section 4. Such transfers rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
  • Adequacy decisions where applicable, and/or
  • Data Privacy Framework (DPF) certifications maintained by the relevant sub-processors.

For a copy of the SCCs or additional transfer safeguards, contact us at support@octopusbridge.com.

8. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and comparable laws), you may have the right to:

  • Access the personal data we hold about your store
  • Correct inaccurate data
  • Delete your data (“right to erasure”)
  • Restrict or object to certain processing
  • Data portability — receive your data in a machine-readable format (this is, effectively, what Harbour does by design)
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

How to exercise your rights

  • Delete all your data: Uninstall the Harbour app from your Shopify admin. This triggers Shopify’s app/uninstalled and (for EU merchants) shop/redact We will delete all your data from our systems within 30 days of receiving the redact webhook.
  • Access your data: Email support@octopusbridge.com from the store owner’s email on file. We will respond within 30 days.
  • Any other request: Email support@octopusbridge.com.

We handle Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) as required by Shopify’s Partner Program Agreement.

9. Children’s privacy

Harbour is a business-to-business tool for Shopify merchants and is not intended for use by individuals under 16. We do not knowingly collect personal information from children.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified via: – The “Last updated” date at the top of this page – A notice in the Harbour app dashboard, and/or – An email to the store contact email on file, at least 30 days before the change takes effect (for material changes affecting how we process data)

Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

11. Contact us

Questions about this Privacy Policy or how we handle your data?

Email: support@octopusbridge.com Postal: Octopus Bridge, Inc., 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA

For EU/UK data subjects, our EU Representative is: Not currently appointed.

Terms of Service — Harbour

Last updated: August 15, 2026 Effective date: August 15, 2026

These Terms of Service (“Terms”) govern your use of the Harbour application (“Harbour,” the “App,” or the “Service”) operated by Octopus Bridge, Inc. (“Octopus Bridge,” “we,” “us,” or “our”). By installing or using Harbour, you agree to these Terms.

If you do not agree, do not install or use Harbour. 

1. What Harbour does

Harbour is a Shopify application that:

  • Reads your Shopify store’s product catalog data (products, variants, images, collections, metafields)
  • Packages it into a downloadable ZIP archive
  • Stores the archive in encrypted cloud storage
  • Emails you a time-limited download link when the backup completes

Harbour is a best-effort backup tool. It does not currently provide (v0.1):

  • Automatic scheduled backups
  • One-click restore of a previous backup back into Shopify
  • Backup of orders, customers, or financial data
  • Real-time replication or high-availability guarantees

Features may evolve. Material changes will be communicated through in-app messaging and/or these Terms. 

2. Eligibility

To use Harbour, you must:

  • Operate an active Shopify store
  • Be authorized to install apps and grant API access on that store
  • Comply with Shopify’s Terms of Service and Acceptable Use Policy
  • Be at least 18 years of age (or the age of legal majority in your jurisdiction) 

3. Account and installation

You install Harbour through the Shopify App Store. During installation, Shopify’s OAuth flow grants Harbour a scoped Admin API access token. That token is stored encrypted on our systems and is deleted upon uninstallation.

You are responsible for:

  • Maintaining the security of your Shopify admin credentials
  • All activity performed through your store’s connection to Harbour
  • Notifying us promptly of any unauthorized access 

4. Subscription and billing

4.1 Plans and pricing

Harbour offers subscription plans billed monthly through Shopify’s managed billing system. Current plans and prices:

Plan Monthly price (USD) Included features
Starter $7.99 Manual + daily automated backups, up to 25,000 SKUs, 30-day storage
Growth $14.99 Manual + daily automated backups, up to 50,000 SKUs, 60-day storage
Scale $29.99 Manual + daily automated backups, up to 100,000 SKUs, 90-day storage, priority delivery

 

Prices are exclusive of applicable taxes. Shopify may add sales tax, VAT, or GST based on your billing region.

4.2 Billing mechanics

  • All payments are processed by Shopify Billing API. We do not receive or store your credit card or payment details.
  • Subscriptions renew automatically each month unless cancelled.
  • Fees are charged in advance for each billing cycle.
  • Failed payments may result in immediate suspension of the Service until payment is resolved.

4.3 Free trial

New installs are eligible for a 14-day free trial. If not cancelled before the trial ends, the subscription automatically converts to a paid plan.

4.4 Cancellation

You can cancel your subscription at any time by uninstalling Harbour from your Shopify admin. Cancellation takes effect immediately and stops future billing. You will continue to have access to any completed backups until the end of your current billing cycle (subject to Section 5.1 retention limits).

 

5. Data storage and retention

5.1 Backup retention

  • Backup ZIP archives are retained for your plan’s retention window (Starter 30 days, Growth 60 days, Scale 90 days) from creation, then automatically deleted.
  • Signed download URLs expire 7 days after issuance; new links can be regenerated for archives still within retention.
  • Full data lifecycle details are in the Privacy Policy.

5.2 Data ownership

You own your store data. Harbour is a processor acting on your instructions. We do not sell, license, or use your data for any purpose other than delivering the Service.

5.3 What happens on uninstall

When you uninstall Harbour:

  • Your Shopify access token is deleted immediately
  • Your subscription is cancelled
  • Backup metadata is retained for 30 days for billing reconciliation, then deleted
  • Backup ZIP archives are subject to your plan’s retention limit (30–90 days); you may email us to request earlier deletion 

6. Acceptable use

You agree NOT to:

  • Reverse engineer, decompile, or attempt to extract Harbour’s source code beyond what is permitted by law
  • Use Harbour to back up data you do not own or have authorization to back up
  • Interfere with, overload, or disrupt the Service (e.g., via automation abuse)
  • Resell, sublicense, or provide the Service as a hosted offering to third parties
  • Use Harbour in any way that violates Shopify’s Terms of Service or applicable law
  • Circumvent plan limits (e.g., installing across many stores to avoid pricing tiers where a single account is intended)

Violation may result in immediate suspension and termination without refund. 

7. Service availability and warranties

7.1 Availability

Harbour is provided on a best-effort basis. We do not guarantee uninterrupted or error-free operation. Scheduled maintenance and unscheduled downtime may occur.

7.2 No SLA in v0.1

We do not currently offer a formal uptime SLA or backup-delivery time guarantee. Backup runs typically complete within minutes for small stores and up to an hour for large catalogs. In rare cases, upstream failures (Shopify API rate limits, network issues) can delay or fail a specific backup run.

If a backup fails, you may retry it at no additional cost. Retries do not extend your billing cycle.

7.3 DISCLAIMER

HARBOUR IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

WE DO NOT WARRANT THAT: (a) THE SERVICE WILL MEET YOUR REQUIREMENTS; (b) BACKUPS WILL BE FREE FROM ERRORS OR OMISSIONS; (c) ANY DATA LOST DUE TO SHOPIFY, INFRASTRUCTURE, OR THIRD-PARTY FAILURES CAN BE RECOVERED; OR (d) THE SERVICE WILL BE UNINTERRUPTED OR SECURE.

Harbour is a backup tool, not a substitute for your own primary data-integrity practices. 

8. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • In no event will Octopus Bridge be liable for any indirect, incidental, special, consequential, punitive, or exemplary damages, including without limitation loss of profits, revenue, data, goodwill, or business opportunities, arising out of or in connection with your use of Harbour, even if we have been advised of the possibility of such damages.
  • Our total aggregate liability arising out of or relating to these Terms or the Service shall not exceed the amount you paid to us for the Service in the twelve (12) months preceding the event giving rise to the claim, or USD $100, whichever is greater.

Some jurisdictions do not allow the exclusion or limitation of certain damages. In those jurisdictions, our liability is limited to the greatest extent permitted by law. 

9. Refunds

We offer a 14-day money-back guarantee for new subscribers. If you are unsatisfied within the first 14 days of your initial paid subscription, email support@octopusbridge.com with your shop domain and we will process a full refund via Shopify.

Refunds outside the 14-day window are considered on a case-by-case basis (e.g., in the case of a documented, uncorrected Service defect that materially prevents you from using Harbour). We do not offer prorated refunds for cancellations made mid-billing-cycle. 

10. Indemnification

You agree to indemnify, defend, and hold harmless Octopus Bridge and its officers, directors, employees, and agents from any claim, demand, loss, or expense (including reasonable attorneys’ fees) arising out of:

  • Your use of the Service in violation of these Terms or applicable law
  • Your infringement of any third-party right, including intellectual property or privacy
  • Data you upload or instruct Harbour to process that you do not have the right to process 

11. Termination

  • By you: Uninstall Harbour from your Shopify admin at any time.
  • By us: We may suspend or terminate your access with or without notice if you violate these Terms, fail to pay fees, or use the Service in a way that risks harm to Octopus Bridge, other merchants, or third parties.
  • Effect of termination: All rights granted to you under these Terms cease. Sections 5.3 (Post-uninstall data handling), 7.3 (Disclaimers), 8 (Limitation of liability), 10 (Indemnification), and 13 (Governing law) survive termination. 

12. Changes to these Terms

We may update these Terms from time to time. Material changes will be notified via the app dashboard and/or email to your store contact address at least 30 days before the effective date. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms.

If you do not agree to the updated Terms, you must stop using and uninstall Harbour. 

13. Governing law and disputes

These Terms are governed by the laws of the State of California, USA, without regard to conflict-of-law principles.

Any dispute arising out of or relating to these Terms or the Service shall be resolved in the state or federal courts located in Santa Clara County, California, USA, and the parties consent to personal jurisdiction and venue in those courts.

Class action waiver: To the extent permitted by law, disputes must be resolved on an individual basis. Class actions and consolidated arbitrations are not permitted. 

14. Miscellaneous

  • Entire agreement: These Terms, together with our Privacy Policy and any Data Processing Addendum, constitute the entire agreement between you and Octopus Bridge regarding the Service.
  • Severability: If any provision of these Terms is held unenforceable, the remaining provisions remain in full effect.
  • Waiver: Our failure to enforce a provision does not waive our right to enforce it later.
  • Assignment: You may not assign these Terms without our prior written consent. We may assign these Terms to a successor entity (e.g., in connection with a merger or acquisition).
  • No agency: Nothing in these Terms creates a partnership, joint venture, employment, or agency relationship. 

15. Contact

Octopus Bridge, Inc. 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA Support: support@octopusbridge.com Legal: support@octopusbridge.com

Data Processing Addendum (DPA) — Harbour

Last updated: August 15, 2026

This Data Processing Addendum (“DPA”) supplements the Terms of Service between Octopus Bridge, Inc. (“Processor,” “Octopus Bridge,” “we”) and the Shopify merchant using Harbour (“Controller,” “Merchant,” “you”). The DPA governs the Processing of Personal Data in connection with the Harbour service.

This DPA applies only where the Processing of Personal Data is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or comparable privacy laws. For merchants located exclusively outside these jurisdictions, this DPA is provided for transparency but is not strictly required. 

1. Definitions

Terms used in this DPA have the meanings given in the GDPR unless otherwise defined here. Specifically:

  • “Personal Data,” “Processing,” “Data Subject,” “Controller,” and “Processor” have the meanings in Article 4 GDPR.
  • “Sub-processor” means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.
  • “Services” means the Harbour application described in the Terms of Service.
  • “Merchant Data” means data uploaded, transmitted, or made available by the Controller to Harbour through Shopify’s Admin API. 

2. Roles and scope

  • The Merchant is the Controller of Personal Data contained within its store data.
  • Octopus Bridge is the Processor, acting on the Merchant’s documented instructions (the primary instruction being: “back up the store data and make it available for download”).
  • This DPA applies for the duration of the Services and until all Merchant Data has been deleted or returned in accordance with Section 9.

Note on scope of Personal Data in Harbour: Harbour requests read-only Shopify scopes that exclude customer, order, and financial data. In normal operation, the volume of Personal Data processed by Harbour is limited to:

  • The Merchant’s own shop contact email (used for notifications)
  • The Merchant’s Shopify access token (a credential, not personal data of a data subject)
  • Any Personal Data the Merchant chooses to embed within product descriptions, metafields, or product image filenames (unusual, but possible) 

3. Nature and purpose of Processing

Item Description
Subject matter of Processing Backup of the Merchant’s Shopify store catalog data
Duration Life of the Merchant’s subscription + retention periods per Section 9
Nature and purpose Read store data via Shopify Admin API; package into ZIP; store; deliver
Types of Personal Data Shop contact email; access token (credential); any Personal Data incidentally present in product metadata
Categories of Data Subjects Merchant (store owner or authorized staff)

 

 

4. Merchant instructions

The Merchant instructs Octopus Bridge to Process Merchant Data:

  • To provide the Services described in the Terms of Service
  • To troubleshoot, debug, and provide support (upon Merchant request)
  • To comply with legal obligations

Octopus Bridge shall not Process Merchant Data for any purpose other than as instructed above and as required by applicable law. 

5. Confidentiality

Octopus Bridge personnel with access to Merchant Data are bound by written confidentiality obligations equivalent to those in this DPA. Access is limited to the minimum necessary to deliver the Services. 

6. Security measures

Octopus Bridge implements appropriate technical and organizational measures to protect Merchant Data, including:

  • Encryption in transit (TLS 1.2+) for all traffic to and from Harbour
  • Encryption at rest for backup archives (Cloudflare R2) and database contents (Neon PostgreSQL)
  • Access controls: Multi-factor authentication for production system access; role-based access limited to authorized personnel
  • Secrets management: Encrypted at rest; never written to application logs
  • Network segmentation: Application VMs and databases are not publicly addressable except via authenticated APIs
  • Vulnerability management: Dependencies are monitored; security patches applied promptly
  • Incident response: Documented process for detecting, containing, and reporting security incidents

A detailed description of technical and organizational measures is available on request. See also Annex II (“Security Measures”) of the Standard Contractual Clauses referenced in Section 8. 

7. Sub-processors

7.1 Approved sub-processors

The Merchant authorizes Octopus Bridge to engage the sub-processors listed in the Privacy Policy, including:

  • Cloudflare, Inc. — Object storage (R2)
  • Neon, Inc. — Managed PostgreSQL
  • io, Inc. — Application compute and routing
  • Resend, Inc. — Transactional email delivery
  • Shopify, Inc. — Source data provider (Admin API)

7.2 Changes to sub-processors

Octopus Bridge will provide the Merchant with at least 30 days’ advance notice of any addition or replacement of sub-processors (via app dashboard notification and/or email to the store contact email). If the Merchant reasonably objects to a proposed change on data protection grounds within 15 days of notice, the Merchant may terminate the Services without penalty by uninstalling the App; no refund is owed for the completed portion of the current billing cycle.

7.3 Sub-processor obligations

Octopus Bridge shall impose data protection obligations on each sub-processor that are no less protective than those set out in this DPA, and remains liable to the Merchant for the acts and omissions of each sub-processor. 

8. International data transfers

The Merchant acknowledges that Merchant Data may be transferred to and Processed in the United States by the sub-processors identified in Section 7. Where such transfers involve Personal Data of Data Subjects in the EEA, UK, or Switzerland, the transfer is safeguarded by:

  • The European Commission’s Standard Contractual Clauses (SCCs), Module Two (Controller to Processor), incorporated by reference; and/or
  • The UK International Data Transfer Addendum for UK transfers; and/or
  • Adequacy decisions and/or Data Privacy Framework (DPF) certifications maintained by the relevant sub-processors, where applicable.

By entering into this DPA, the parties are deemed to have executed the SCCs with the following completions:

  • Module: Two (Controller to Processor)
  • Docking clause: Applicable
  • Clause 7 (optional docking): Not selected
  • Clause 9(a) — sub-processors: Option 2 (General written authorization); notice period of 30 days
  • Clause 11 — redress: Deletion of “independent dispute resolution body” option
  • Clause 17 — governing law: Ireland
  • Clause 18 — forum and jurisdiction: Courts of Ireland
  • Annex I.A (Parties): Merchant is Data Exporter; Octopus Bridge is Data Importer
  • Annex I.B (Description of Transfer): See Section 3 of this DPA
  • Annex II (Security): See Section 6 of this DPA
  • Annex III (Sub-processors): See Section 7.1 and the Privacy Policy 

9. Data return and deletion

Upon termination of the Services or upon Merchant request, Octopus Bridge shall:

  • Immediately delete the encrypted Shopify access token (triggered by Shopify’s app/uninstalled webhook)
  • Within 30 days of receiving a shop/redact webhook from Shopify (which Shopify sends 48 hours after uninstall), delete all remaining Merchant Data including backup ZIP archives and backup job metadata
  • Provide written confirmation of deletion upon request

The Merchant may request return of Merchant Data (as a ZIP archive) at any point during the Services simply by triggering a backup and downloading the resulting archive. This is the primary functionality of Harbour.

Exceptions: Octopus Bridge may retain Merchant Data beyond the periods above only where required by applicable law, in which case it will continue to protect the data in accordance with this DPA. 

10. Data Subject rights

Given the limited categories of Personal Data Processed by Harbour (see Section 2), most Data Subject requests will be handled directly by the Merchant. Where a Data Subject sends a request directly to Octopus Bridge concerning Merchant Data, Octopus Bridge will:

  • Promptly forward the request to the Merchant, and
  • Provide reasonable assistance to the Merchant in responding to the request

Octopus Bridge will not respond directly to the Data Subject except to acknowledge receipt and redirect to the Merchant. 

11. Personal data breach notification

Octopus Bridge shall notify the Merchant without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Merchant Data. The notification will include, to the extent known:

  • Nature of the breach and categories/approximate number of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate adverse effects
  • Contact point for further information

Octopus Bridge will provide reasonable assistance to the Merchant in fulfilling the Merchant’s own notification obligations to supervisory authorities and Data Subjects. 

12. Audits

The Merchant may audit Octopus Bridge’s compliance with this DPA once per calendar year, upon 30 days’ written notice, provided that:

  • The audit is conducted during normal business hours
  • The audit does not unreasonably interfere with the operation of the Services
  • The Merchant bears its own audit costs and, if the audit is conducted onsite, reimburses reasonable costs incurred by Octopus Bridge
  • Any auditor is bound by confidentiality obligations at least as strict as those in this DPA
  • The Merchant will not access or attempt to access data belonging to any other merchant

In lieu of an onsite audit, Octopus Bridge may provide written responses to a reasonable data-protection questionnaire and/or a third-party audit report (e.g., SOC 2, ISO 27001) if available. 

13. Miscellaneous

  • Conflict: If there is a conflict between this DPA and the Terms of Service, this DPA governs to the extent of the conflict for matters concerning Personal Data protection.
  • Amendments: Octopus Bridge may amend this DPA where necessary to comply with applicable law or where the amendment does not materially reduce the Merchant’s rights. Other amendments require the Merchant’s consent.
  • Termination: This DPA terminates automatically upon termination of the Services, except for those obligations that by their nature survive (e.g., deletion confirmation, breach notification for events during the term). 

14. Contact

Data protection inquiries: support@octopusbridge.com Postal: Octopus Bridge, Inc., 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA

EU Representative (if applicable — required under GDPR Article 27 if you have EU merchants and are not established in the EU): Not currently appointed.

Refund Policy — Harbour

Last updated: August 15, 2026

We stand behind Harbour. If it doesn’t work for you, we’ll refund your money. 

14-Day money-back guarantee

New subscribers are eligible for a full refund if the request is made within 14 days of the initial paid subscription starting.

To request a refund

  1. Email us at support@octopusbridge.com from the store owner’s email address
  2. Include your Shopify shop domain (e.g., your-shop.myshopify.com)
  3. Optionally: tell us what wasn’t working — we use every reply to make Harbour better

We will process the refund via Shopify within 5 business days of receiving your request. The refunded amount will appear on your Shopify invoice within 1-2 billing cycles depending on your payment method. 

Cancellation without refund

If you cancel outside the 14-day window:

  • You retain access through the end of your current billing cycle
  • Any completed backups remain downloadable subject to your plan’s retention window (30–90 days)
  • No prorated refund is issued for mid-cycle cancellations 

Extenuating circumstances

If Harbour experiences a documented, uncorrected defect that materially prevents you from completing a backup for more than 7 consecutive days, we will consider refunds beyond the 14-day window. Email support@octopusbridge.com with details and we’ll work with you individually. 

What isn’t refundable

  • Fees paid to third parties (e.g., Shopify, Stripe, Cloudflare) are not within our control and not refundable through us
  • Storage overages or add-ons (currently none in v0.1; will be listed here if introduced) 

Questions

Email support@octopusbridge.com. We reply within one business day, usually sooner.

Octopus Bridge, Inc. 5655 Silver Creek Valley Road, STE 436, San Jose, CA 95138, USA 

Company

  • About Us
  • Pricing
  • POS Partners
  • Customers
  • Contact us

Services & Resources

  • Why Octopus API
  • Case Studies
  • Videos
  • Blog
  • Shop

Connect With Us

Facebook
X
LinkedIn
YouTube
  • Service Agreement
  • Terms & Conditions
  • GDPR Compliance

Copyright © 2026 Octopus Bridge, Inc. dba 24Seven Commerce | All Rights Reserved

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT