Add-on · $9 a store a month

A backup is only worth what
its restore can prove.

BulkGauge copies your catalogue data every night, encrypts it before it leaves your store, and keeps it where you choose. When you restore, you see every change first — including the ones that cannot be made, and why.

AES-256, before the file leavesYour storage or oursYou can hold the key
What is in a copy

Catalogue data. Named, not implied.

Products and variants, metafields and metaobjects, collections, pages, blogs and navigation, inventory levels, discounts and price rules, and theme settings data.

Products cannot be excluded from a copy. Every other type references them, and a copy without them cannot be restored from.

Nightly

or weekly, or manual. At an hour you choose, in your store's timezone.

30

restore points on Growth. 7 on Core, 90 on Scale and Compliance.

2 GB

of encrypted storage included per store — Core’s 7 restore points fit inside it. Then 40¢ a GB.

$0

to restore. However many times, however large the job.

The part most backup apps do not write down

Shopify has no rollback, so a restore replays changes

There is no API that returns a store to an earlier moment. BulkGauge writes your saved values back through the same API any app uses, which means a restore has four outcomes per object — and you read all four before anything is written.

Updated in place

The product still exists. Its saved values are written back, and the job can be undone from Jobs like any other.

Recreated

The product was deleted. It comes back as a new product with a new ID, which cannot be undone.

Skipped

Nothing in the backup differs from what is in your store now, so nothing is touched.

Cannot be restored

Shopify refuses the write — a gift card, a handle another product now uses, a value it rejects. Named on its row, with the reason.

The new-ID problem, stated once and plainly. A recreated product does not inherit the old product's ID, so collection memberships, metafield references and navigation links pointing at the old ID stop resolving. BulkGauge lists every one of them by name in the preview, before you approve. Afterwards it can re-add the recreated products to manual collections; references and menu links have to be repointed by hand, and the completion summary tells you which.
Not covered, and why

Four things a Shopify backup cannot give you

Orders

Never copied and never restorable. Shopify has no way to write an order back.

Customers

Not copied. Customer records and their consent state stay in Shopify only.

Theme code

Liquid and assets. Shopify's own theme versioning covers those.

Other apps' data

Anything another app keeps in its own database is outside this backup.

This is the same list you see before you configure your first backup, and it is on the Backups page afterwards. A merchant who learns it during a real emergency has been failed by the product, not by the platform.

Where it is kept

Ours, yours, or neither.

  • BulkGauge storage. Encrypted, in Canada, 2 GB included per store and 40¢ a GB above it. Nothing to connect.
  • Your Google Drive or Dropbox. The same encrypted file, in a folder you authorise. No per-GB charge from us, and you can revoke the access from your own account at any time.
  • Download only. Nothing stored anywhere. A link that expires in 24 hours, and our copy deleted once you have it.

We ask Google or Dropbox for permission to one folder. There is no field anywhere in BulkGauge for a storage password or a broad-scope API key.

Who holds the key

A trade, not an upgrade.

  • We hold it. Restore always works, from any device, with nothing to keep. Our staff cannot browse your backups, but we hold the key material and could technically decrypt a copy.
  • You hold it. We cannot read your backups, and cannot help you read them. The key is shown once and never stored by us — lose it and every copy encrypted with it is permanently unrecoverable. No reset, no support route.

Both consequences are on screen before the choice, and the second one has to be typed out rather than ticked.

Questions

Is this a full store backup?

No, and we do not call it one. It covers catalogue data — products, variants, metafields, collections, pages, navigation, inventory levels, discounts and theme settings. Orders, customers, theme code and other apps' data are not in it.

What does it cost?

$9 per store per month on any paid plan, including 2 GB of encrypted storage for that store — enough for the 7 restore points Core keeps. Above that it is 40¢ per GB, charged on the period's peak. Writing to your own Drive or Dropbox removes the per-GB part. Restores are never charged.

What happens if a backup fails?

You are emailed and the Backups page states the cause in the first sentence, the age of your newest usable restore point, and the two actions that fix it. A backup product that fails silently is worse than no backup, so nothing about a failed run is hidden behind a link.

Can I restore only part of a backup?

Yes. The preview lists every object with its outcome and exports to CSV, and you can restore a scope rather than the whole point. What you cannot do is restore selectively without seeing the list first.

If I lose my own key, can support recover it?

No. That is the point of holding it yourself: we never receive it, so there is nothing for support to look up, reset or verify. If that is a risk you would rather not carry, let us hold the key — restore then always works.

Does turning it off delete my backups?

Not immediately. Scheduled runs stop that night, your restore points stay readable and downloadable for 30 days, then they are deleted. The charge ends with the current period.

The copy is cheap. The afternoon it saves is not.