Restora Privacy Policy
Last updated: [date]
Restora is run by Declan Lohan, trading as B-Side Apps, in Ireland ("we", "us"). This policy explains what information Restora collects, why, who it's shared with, and how long it's kept.
Contact: [email protected]
Address: 124 Churchfields, Ashbourne, Co. Meath, A84 AX77, Ireland
1. Who this applies to
Restora is a service for businesses that use Square. This policy covers the business owners and staff who connect Restora to a Square account, use the Restora dashboard, or get emails from us.
2. What we collect
From your Square account, when you connect Restora: - Your business name, Square merchant ID, country, currency, timezone and location logo - Your item library: items, sizes and variations, prices, categories, option lists and modifiers, taxes, discounts, pricing rules, item photos, and the settings attached to them - An access token that lets Restora read and restore your item library
We ask Square for three permissions only: reading items, writing items (used only when you click Restore), and reading your merchant profile. We don't access your customers, sales, payments, staff, timecards or stock counts.
From you: - The email address you give us for alerts and summaries - Whether you want product update emails
From Stripe, when you subscribe: - Your Stripe customer and subscription IDs, plan, billing status, trial and renewal dates
Your card details go directly to Stripe. We never see or store them.
Created when you use Restora: - A history of every change to your item library, and nightly full copies - A record of restores you make and alert emails we send - Error logs, used to find and fix problems
3. Why we use it
| What | Why | Legal basis |
|---|---|---|
| Square data and item library | To back up your items, show their history, and restore them when you ask | Contract |
| Your alert email | To send bulk-delete alerts, summaries, trial and billing emails | Contract |
| Billing details | To charge for the service and keep accounting records | Contract; legal obligation |
| Product update emails | To tell you about new features | Legitimate interests (you can opt out at any time) |
| Error logs | To keep Restora working and secure | Legitimate interests |
| Subscription revenue per shop | To report and pay Square's revenue share | Contract with Square; legitimate interests |
We don't sell your data, use it for advertising, or use it to train any AI model.
4. Who we share it with
We use these providers to run Restora:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage and server functions | EU (Ireland) |
| Stripe | Subscriptions and payments | EU, with transfers outside the EU |
| Resend | Sending emails | EU (Ireland), with transfers to the United States |
| Cloudflare | Hosting the website and dashboard | Global network |
| Square (Block, Inc.) | The source of your data, and the revenue share report | As set out in Square's own privacy notice |
Where data leaves the EU, we rely on the provider's safeguards for international transfers, such as Standard Contractual Clauses.
We may also disclose information if the law requires it, or to protect our rights in a dispute.
5. How long we keep it
- While you're subscribed: everything in section 2, so Restora can do its job.
- If you cancel, stop paying, or disconnect Restora in Square: backups stop straight away. Your item history, nightly copies, photos, restore records and alert records are deleted 30 days later. Disconnecting in Square also deletes your access token immediately.
- What we keep after that: your merchant ID, business name, Stripe IDs and whether you've had a free trial, so billing records line up and the free trial can only be used once.
- Billing and accounting records: six years, as Irish tax law requires.
- Error logs: 30 days.
6. Security
- Square access tokens are encrypted before they're stored.
- Each shop's data is kept separate, and no shop can access another's.
- Stored files are private, and nothing is publicly accessible.
- All connections use HTTPS, and messages from Square and Stripe are checked to confirm they're genuine.
- Access to the systems is limited to B-Side Apps.
No system is completely secure. If a breach affects your data, we'll tell you without undue delay.
7. Cookies and storage
The dashboard stores your login session in your browser so you stay logged in. We don't use analytics, advertising or tracking cookies.
8. Your rights
Under GDPR you can ask to: - see the personal data we hold about you - correct it - delete it - restrict or object to how we use it - get a copy of it in a portable format
Email [email protected] and we'll respond within one month. You can also complain to Ireland's Data Protection Commission at dataprotection.ie.
9. Changes
If we change this policy in a way that matters, we'll email you before the change takes effect.