Three things keep a business's records safe here. The database as a whole is kept by its own point-in-time recovery, which the platform runs. Every day, at the hour each business chooses, the platform also keeps a copy of everything that business holds, on its own, sealed, in a store apart from the app, with the uploaded files beside it, so one business can be put back without touching another. And every change to the records a business would want back is kept with what it was before, so one client, one price or one appointment can be put back by the owner without anyone else's help.
The nightly copies
Open Admin, Tools, Backups and exports. Nightly Copies lists each day's copy with its day, whether it is good, its size and how many records are in it. A copy is the same .zip as Download everything, with a manifest naming every table, its rows and its hash; it is sealed before it leaves the app and checked by its hash when it comes back. The platform keeps the newest 35 copies and the first copy of each month for a year.
When the copy is made chooses the hour: with the platform's nightly run (its time where you are is shown), or any hour of the day where the business is. One copy is made a day; the line beneath says when the next is due and who chose the hour. Whoever can change the business's settings can change it. Until the platform runs its hourly worker, copies are made with its nightly run whatever hour is chosen, and the screen says so.
A copy holds every kind of record the business keeps, a part of the app added later included, all read as of one moment, and the files kept with them (pictures, documents, a contract's signature, a scanned bill), copied beside it. It leaves out what would let someone in (passwords, keys, tokens, bank numbers) and the platform's own machinery, such as its logs that expire. A copy that could not take every record says why and is made again; the night before stays good.
Someone with the Download everything switch (an owner, or an admin given it) can Download any good copy from the list. A night that failed says why under its day; the night before stays good, and the platform's admins see the failure too.
Have everything sent to you
Download everything has the same records; should one kind of record be too large for a single download, or not be readable at that moment, its README says which. Have Everything Sent to You puts a copy on your own schedule: every week (Monday at 4 in the morning, where the business is) or every month (the first), as a link to the download sent to an email address, or as a file put in the business's own Dropbox or OneDrive under /BookNovi/Exports (link one under Files first). The link opens only for someone signed in with the Download everything switch. Send it now does it this minute. A copy sent to you is kept for a month. Download everything now is the same .zip, made as you ask for it.
Everything the Business Holds, under Settings, Records, is the same download for whoever has the switch: a spreadsheet for each kind of record (clients, appointments, sales, products, orders, stock, the team, marketing, the website, messages, the books and payments), with the products and the orders also in Shopify's own layouts. Passwords, keys and bank account numbers are left out, and each download is noted in the activity log.
Asking for a restore
Putting a whole business, or a kind of record, back from a copy is done by the platform's admins by hand, from the copy you name, so nothing is lost twice. Request a restore opens a message to them: pick the copy (or leave it to whichever is good) and say what should be put back and as of when, as exactly as you can. Their answer appears under Restore Requests, with who answered and when. Three requests can wait at a time.
A record's history
On a client (Details), a business in the CRM (Details) and a product (Details), the History card lists every change to the record, newest first: who made it, when, and each field as it was and as it became ("price $45.00 → $48.00"). Making the record and removing it are kept too.
An owner can Put it back as it was before any change: every field that change touched goes back to what it was, as a new change under the owner's name. Changes made since to other fields stay as they are. A record that was removed can be brought back whole with Bring it back. History is only ever added to: nothing is rewritten, so the change and its undoing both stay.
Ledgers are never edited
A client's loyalty points and store credit, a gift card's moves, an item's stock moves and the books' journal are ledgers: the balance is the sum of the entries, and no entry is ever changed or deleted. A mistake is put right by a reversing entry the other way, with the reason, which names the entry it reverses; both stay. An owner does this from a client's History card (points and store credit) or through the API's description of the ledgers; a journal entry is reversed the same way. An entry that was reversed is marked; a reversal cannot itself be reversed, and nothing can be reversed below nothing on a card or a shelf.
For the platform's admins
Admin, Platform shows every live business's last copy, the week's failures with their sentences, the restore requests to answer, retention and the log of restore drills. The runbook for a restore, one business or everything, and the quarterly drill checklist, is docs/RECOVERY.md in the repository; with no backup store set up, no nightly copies are made, and the same runbook says how to set one up.
Nightly copies kept and Monthly copies kept beyond them are the retention for every business: each keeps its newest nightly copies, then the first copy of each month for so many months, and a copy the store still locks waits for its lock. Files read back and checked each pass is how many uploaded files each pass reads back to check against what was copied. A restore request is answered with A line back to the business, then Mark it done or Decline it; the line is what the business reads under its Restore Requests. Every quarter a copy is restored into a database of its own and checked table by table against its manifest (npx tsx scripts/restore-drill.ts), and Restore Drills keeps the log of each run.
The server's secret on the same tab says whether CONNECTION_SECRET is set (never what it is), whether one is being retired, and every sealed value on the platform by the key it is under and by what it is. To change the secret, set the new one, move the old one to CONNECTION_SECRET_PREVIOUS, and watch Waiting for the clock fall to nothing (Move them now runs a pass at once) before the old one is removed; docs/RECOVERY.md, "Changing the server's secret", says each step and what else a change of secret resets.
Best practices
- Give one admin the Download everything switch and no one else; a copy holds every client's details.
- Have a copy sent to a mailbox or a Dropbox the business controls, monthly at least, so a copy exists outside the platform too.
- Before putting a version back, read the whole change: what it undoes is every field it lists, and nothing else.
- Fix a wrong points, store credit or stock entry with a reversal, never by deleting anything, so the history still explains the balance.
- Ask for a restore as exactly as you can: one record or one kind of record is put back faster, and with less touched, than everything.