Privacy policy
Last updated: 14 July 2026
Who we are
Bracket (“we”, “us”) provides a Shopify app that keeps a merchant’s existing theme current, fresh and safe: it scans for deprecated code and breakage risks, builds approved changes on an unpublished draft theme, tests them, and keeps automatic backups.
This policy explains what data the app touches, what it stores, what it never touches, and how data is deleted. It applies to merchants who install Bracket from the Shopify App Store and to visitors of this website. If anything here is unclear, email us at support@bracket.tools.
What we access
When you install Bracket, Shopify asks you to approve a small set of permissions. Under those permissions we access:
- Theme files: the code and settings of your themes, so we can scan them, stage changes on an unpublished draft copy, and take backups. We never modify or publish your live theme; changes are only ever written to drafts, and you publish them.
- Shop domain and basic store details: to identify your store, run storefront checks against your public storefront, and show results in the app.
- Subscription plan state: via Shopify’s billing system, to know which plan your store is on.
What we store
- An encrypted API access token: required to talk to Shopify on your store’s behalf. Stored encrypted at rest.
- Theme snapshots: copies of your theme files kept as backups and restore points.
- Scan findings and recommendations: the results of theme scans, storefront checks, and the status of changes you have requested or approved.
- Support correspondence: emails you send us, so we can respond and keep context.
We use this data solely to provide the service. We do not sell it, share it for advertising, or use it for any purpose beyond operating Bracket for your store.
What we never access
Bracket does not request permission to read your customers or orders, so we cannot and do not access:
- Customer personal information: names, emails, addresses, or any other customer data.
- Orders and payment details: order history, transactions, or checkout data.
Because we hold no customer data, requests made through Shopify’s customer data request and customer redact processes are answered by confirming that no data is held.
Data retention and deletion
Your data is retained only while the app is installed and as long as it is needed to provide the service (for example, backup snapshots are kept so you can restore earlier versions of your theme).
When you uninstall Bracket, your access token stops working immediately. When Shopify sends us its shop redact notification after uninstall, we permanently delete the store’s data, including the stored access token, theme snapshots and backup files, and scan findings.
You can also request deletion at any time by emailing support@bracket.tools.
Service providers
We use a small number of service providers (subprocessors) to run Bracket. Each processes data only as needed to provide its function:
No customer personal information is passed to any of these providers, because we never hold it.
Security
Data is encrypted in transit, API access tokens are encrypted at rest, and the app requests only the permissions it needs to operate. Access to production systems is restricted to the people who operate the service.
This website
This website does not set tracking cookies and does not collect personal information. If you email us, we keep the correspondence to respond to you.
Changes to this policy
If we change this policy, we will update this page and the date at the top. Material changes affecting installed stores will be communicated by email.
Contact
For any question about this policy or your data, including access or deletion requests, contact support@bracket.tools.