Bracket
How it works Features Privacy
Request access
Legal

Privacy policy

Last updated: 13 September 2026

Who we are

Bracket (“we”, “us”) provides a Shopify app for theme analysis, supported changes on unpublished drafts, and storefront checks.

This policy explains what data the app accesses and stores, how it is used, and how deletion works. It applies to merchants using Bracket, including testing access, and to visitors of this website. If anything here is unclear, email us at hello@bracket.tools.

What we access

When you install Bracket, Shopify asks you to approve a small set of permissions. Under those permissions we access:

  • Theme files: the code and settings of your themes, so we can scan them, stage supported changes on an unpublished draft copy, and retain scan and pre-change snapshots. We never modify or publish your live theme; changes are only ever written to drafts, and you publish them.
  • Shop domain and basic store details: to identify your store, run storefront checks against your public storefront, and show results in the app.
  • Store owner email: to send service messages and, if you opt in, product emails.
  • Subscription plan state: via Shopify’s billing system, to know which plan your store is on.

What we store

  • Encrypted access credentials: Shopify access and refresh tokens and, if you provide one, your storefront password. These are encrypted at rest.
  • Theme snapshots: copies of theme files used for analysis and pre-change integrity checks. Bracket does not provide a merchant restore or undo action.
  • Verification evidence: screenshots, differences, checks and technical results for staged changes.
  • Scan findings and recommendations: the results of theme scans, storefront checks, and the status of changes you have requested or approved.
  • Operational records: service-email records, consent and unsubscribe preferences, webhook identifiers, request counters and app performance telemetry.
  • Support correspondence: emails you send us, so we can respond and keep context.

We use this data to authenticate the app, analyse themes, build and verify requested changes, operate the service and communicate with you. We do not sell merchant data or share it for advertising.

Customer and order access

Bracket does not request Shopify API permissions to read customer records, orders or payment information. Customer data request and redaction webhooks are recorded as compliance events; the app has no Shopify customer record to return or erase.

Theme files and public storefront pages can contain information you place there. That content may appear in theme snapshots or verification evidence.

Data retention and deletion

Theme snapshots, build evidence, billing records and your decisions are retained for the active installation so the service and its audit history work. Operational records are subject to scheduled retention limits.

When a valid uninstall notification is processed, Bracket revokes its stored connection and removes Shopify sessions. When Shopify sends a shop-redaction request, we remove the store’s relational data and queue unreferenced theme and verification files for deletion. Failed file deletions are retried until removal is confirmed.

Deletion from our live systems is separate from backup expiry. Production database recovery is configured to retain point-in-time history for 7 days and create daily snapshots retained for 14 days. These copies may retain data after it has been removed from live systems.

Manual exports used to validate a release or recovery procedure are held separately with restricted access during validation. We remove these exports once validation is complete.

You can also request deletion at any time by emailing hello@bracket.tools.

Service providers

We use a small number of service providers (subprocessors) to run Bracket. Each processes data only as needed to provide its function:

ProviderPurpose
ShopifyApp installation, authentication, theme access and billing
NeonDatabase hosting (app data, scan findings, encrypted tokens)
Cloudflare R2File storage for theme snapshots and verification evidence
VercelApplication hosting
Trigger.devBackground job processing (scans, builds, checks)
BrowserbaseBrowser sessions for live and draft storefront verification
ResendService and opt-in product email
Cloudflare Email RoutingForwarding email sent to our support address
Google WorkspaceSupport mailbox and correspondence

Providers process the data needed for their role, such as theme files, verification pages or the email address used for service messages.

Security

Data is encrypted in transit, API access tokens are encrypted at rest, and the app requests only the permissions it needs to operate. Access to production systems is restricted to the people who operate the service.

This website

This website does not add analytics or advertising trackers. It is hosted on GitHub Pages and loads fonts from Google Fonts, so your browser sends network requests to those providers. See GitHub’s privacy statement and Google Fonts’ FAQ for their data practices. If you email us, we keep the correspondence to respond to you.

Changes to this policy

If we change this policy, we will update this page and the date at the top. You can contact us with questions about any update.

Contact

For any question about this policy or your data, including access or deletion requests, contact hello@bracket.tools.

Bracket

Theme analysis, supported draft changes and storefront checks.

Product
How it works Features Request testing access
Support
hello@bracket.tools
Legal
Privacy policy
© 2026 Bracket