Privacy Policy
Last updated 22 July 2026
This Privacy Policy explains how Leira (“Leira”, “we”, “us”), operated by Navid Asgharzadeh, 147 71 Grödinge, Sweden, processes data when you install and use the Leira backup & restore application for Shopify (the “App”) and when you visit leira.app (the “Site”). We are GDPR-first and EU-resident: your data is stored in the European Union and never follows a US data path.
1. Who is the controller
For the merchant account data and store content processed through the App, the merchant is the data controller and Leira acts as a data processor on the merchant's behalf (see our Data Processing terms). For the Site and direct communications with us (for example, an early-access signup or a support request), Leira is the controller.
2. What we process
Store configuration data (as processor)
To provide backups and restores, the App reads and stores the store resources it protects — products and variants, collections, themes and theme code, pages, blogs and articles, metafields and metaobjects, files, discounts and translations — together with your store domain and an encrypted access token.
What we deliberately do not process
The App never requests order or customer scopes and therefore does not access, store or back up orders, customers, or any other personal data of your shoppers. This keeps Leira at Protected Customer Data Level 0/1.
Site & contact data (as controller)
If you submit your email for launch access or contact support, we process the email address, any name and message you provide, and basic technical metadata (such as your IP address) to prevent abuse.
3. Lawful bases
We process store configuration data to perform our contract with the merchant (Art. 6(1)(b) GDPR). We process Site and contact data on the basis of your consent (Art. 6(1)(a)) and our legitimate interest in operating and securing the Site (Art. 6(1)(f)).
4. Where your data is stored
Metadata is held in an EU-region database and backup payloads in EU-jurisdiction object storage. Compute runs on EU edge infrastructure. There is no US data path. Our sub-processors and their locations are listed in the Data Processing terms.
5. Security
Backups and stored access tokens are encrypted at rest with AES-256-GCM. Encryption keys are managed independently of OAuth credentials. Access to production systems is restricted and least-privilege. Backups are verified by re-reading a sample after each run.
6. Retention & deletion
Backups are retained according to your plan's version-history window (7, 30 or 365 days) and then purged automatically. When the App is uninstalled, we begin deleting the store's data and, in line with Shopify's requirements, complete an irreversible purge of the store's records and backup blobs within 48 hours. We also honour Shopify's shop/redact and customers/redact compliance webhooks. Site/contact records are kept only as long as needed for the purpose collected.
7. Your rights
Subject to the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. To exercise any right, email support@leira.app. You also have the right to lodge a complaint with your local supervisory authority.
8. Cookies
The Site uses no advertising or cross-site tracking cookies. Any storage is strictly functional (for example, remembering that you dismissed a notice).
9. Changes
We may update this policy; material changes will be reflected by the “last updated” date above and, where appropriate, communicated directly.
10. Contact
Questions about this policy or your data: support@leira.app.