Privacy policy
Last updated: August 8, 2026
Graftport is a store migration platform operated by Bytetide (“we”, “us”). This policy explains what data Graftport handles, why, and what your rights are. It covers the Graftport web application, the Graftport Shopify app, and this documentation site.
The two kinds of data we handle
Graftport handles data in two distinct roles:
- Your account data — information about you as a Graftport user (controller role).
- Your store data — the commerce data Graftport moves between platforms on your instructions, which can include your customers’ personal information (processor role). You remain the controller of this data; we process it only to run the migrations you configure.
Account data we collect
- Account details: name, email address, and workspace membership, collected when you sign up or accept an invitation.
- Usage data: pages visited and product events inside the app, collected via analytics cookies (see below).
- Support communication: messages you send us.
Store data we process on your behalf
When you connect a store or configure a migration, we process:
- Platform credentials: API tokens and connection details for your source platform and destination Shopify store. Tokens are stored server-side and are never sent back to your browser once saved (see Security below). For stores connected through the Graftport Shopify app, uninstalling the app invalidates the token at Shopify and we delete the stored connection as soon as Shopify tells us the app was removed.
- Commerce records: the resource types you choose to migrate — products, customers, orders, collections, discounts, gift cards, blogs, and related content. Customer and order records can include names, email addresses, physical addresses, phone numbers, and order history of your store’s customers.
We use store data solely to perform the migration work you configure: extracting it from the source, transforming it to the destination format, loading it into your Shopify store, and showing you progress and results. We do not sell it, use it for advertising, or use it to train machine-learning models.
Shopify app and protected customer data
The Graftport Shopify app requests the access scopes needed to read a source store and write a destination store, including order history where Shopify has granted that access. In line with Shopify’s protected customer data requirements, we act on Shopify’s mandatory privacy webhooks:
-
Customer data requests are recorded and answered by hand: we compile what Graftport holds about that customer and return it to the store owner, who passes it on. We aim to do that inside Shopify’s 30-day window — if you have not heard from us, chase us at the address at the bottom of this page.
-
Customer redaction requests delete that customer’s extracted records, and the orders Shopify lists alongside the request, from migrations that read from your store — and delete the customer records Graftport prepared for stores it writes to. We accept the request the moment it arrives and carry out the deletion immediately afterwards; on a large store the deletion itself can take a few minutes to finish. A request Shopify sends twice is only acted on once.
-
Shop redaction is what Shopify sends 48 hours after the Graftport app is uninstalled from a store. It removes that store’s Graftport app connection and the credentials held with it, and it erases the store data held by every workspace that had connected that store through the Graftport app: everything the workspace imported from the store, and the content of every record it had prepared for the store.
It is scoped to the relationship the uninstall ends. If a workspace connected the store through the Graftport app at any point, all of that workspace’s data for the store is erased — including anything it imported using a token entered by hand. If a workspace never used the Graftport app for that store, and worked only with its own app or a token it entered itself, nothing of that workspace’s is erased: the connection it relies on is still standing and is its own to revoke. Connections made with your own app are left alone for the same reason.
Reconnecting cancels it. If the store is reconnected through the Graftport app before the request reaches us, we carry out no erasure at all and record the request as received and deliberately not acted on, together with the reason. Reconnecting with your own app instead does not cancel it — the request follows the Graftport app, so only reconnecting through the Graftport app stops the erasure.
We do not let this happen quietly. When Shopify tells us the app was uninstalled, we email everyone in each workspace in scope that holds data for the store, naming the date the erasure falls due and what will go. Once it has run, everyone in a workspace it actually took something from gets a second email saying what was erased.
What shop redaction deliberately leaves behind is a bare cross-reference list: one line per migrated item, linking it to the matching item in your own Shopify store. It holds identifiers only — no names, addresses, or order contents — and exists so that a later migration does not duplicate what is already there.
We also keep a record of each privacy request Shopify sends us, as our evidence that we acted: the request type, the store it concerns, when it arrived, and when we completed it. Kept with it are only the identifiers needed to act on the request and to say which request it was — the store id, the customer id, the request id, and the ids of any orders in scope. Everything else Shopify sends is discarded before the record is written: email addresses, phone numbers, names, postal addresses, and — when you uninstall the app — your own store contact and billing details. So honouring an erasure request never leaves us a second copy of the data we were asked to erase.
Retention
Extracted and prepared store data exists to support your migration — re-runs, dry runs, and troubleshooting. Deleting a migration removes it, and everything it holds, from your workspace. The extracted copy behind it is erased when the workspace itself is deleted, on a redaction request as described above, or whenever you ask us to erase it. Account data is retained while your account is active and deleted when you close it, except where we must keep records to meet legal obligations — invoices, for example, are kept, detached from your workspace.
Four things deliberately outlive a redaction. None of them holds any of the data that was erased:
- The record of the privacy request itself, described above, which we keep as compliance evidence. We delete it automatically a year after the request arrived, once the request has been carried out. A request still outstanding — an export we have not yet compiled, or a deletion that did not finish — is exempt from that clean-up and kept until it is settled, so an obligation we still owe you can never quietly age out. A shop redaction that goes ahead clears the identifiers out of the request records still held for that store, leaving each one as nothing more than the fact that the request arrived and was honoured; one cancelled by a reconnection leaves them as they are.
- The cross-reference list linking migrated items to the matching items in your Shopify store, which carries identifiers but none of the underlying record content. It does not expire automatically. Ask us and we will delete it.
- The record of what the erasure removed: which workspace and which migrations it touched, how many imported and prepared records went, and when — or, where we cancelled it, the fact that we did and why. Counts and identifiers only, never any of the erased content. This is our evidence that a mandatory request was honoured, so it is not deleted on request and does not currently expire.
- The record that a workspace connected a store through the Graftport app: the workspace, the store address, which app was used, and when it was first and last connected. It holds no store data. We keep it because it is what tells us, when an erasure request arrives up to days after a connection is gone, whose data that request covers. Deleting your workspace deletes it.
Security
Store credentials and migrated data are stored in access-controlled databases, encrypted in transit and at rest. Once a credential is saved, its secret part — an API token, a password, an API secret — is never sent back to your browser again, and nobody in your workspace can read it through Graftport: the app can tell you that a token is set, never what it is. Only the non-secret connection details saved beside it stay visible, so you can still see what a migration points at — a store address, a username, the identifying half of an API key pair. This covers the access tokens issued when you connect a store through the Graftport Shopify app the same way: they are never returned to the browser at all, and are used only by the servers running the migration you configured. Internal access to customer data is restricted to operating and supporting the service.
Subprocessors
We rely on a small set of providers to run Graftport: cloud hosting and managed databases for the application and its data, an email provider for account and migration notifications, a payment processor (Stripe) for the services you buy from us, application monitoring, and analytics providers (PostHog and Google Analytics) for product usage measurement. Analytics never receive your store’s commerce data or credentials.
Cookies
The application uses cookies for sign-in sessions (essential) and product analytics (measurement). Installing the Graftport app from Shopify sets one more essential cookie, which carries the new connection across to your workspace while you sign in; it lasts an hour at most and cannot be read by scripts in the page. The documentation site does not require an account.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict processing. For your account data, contact us and we will respond within the legally required time frame. If you are a customer of a store that used Graftport, the store owner is the controller of your data — direct requests to them, and we will act on the requests they relay (for Shopify stores, automatically via the redaction webhooks above).
Changes
We will update this page when our practices change and revise the date above. Material changes are announced to account holders by email.
Contact
Bytetide — privacy questions and data requests: hc@bytetide.io