Imagine you’re leasing a car. If the engine has a major issue due to a manufacturing defect, the dealership or manufacturer is responsible for fixing it. However, if you spill coffee on the seats or scratch the paint, it’s on you to clean it up or get it repaired. That’s why people get insurance and take care of their cars.
Shopify works the same way.
They maintain the core infrastructure, like hosting and security, but if something goes wrong with your store’s custom features, design, or third-party integrations, it’s up to you to fix it.
How to Lose Data in 6 Ways
1. Human errors
IT professionals report that human errors are the single biggest cause for data loss. Most people who are working on a site don’t have any ill intent but human error is bound to happen, and it can sometimes be catastrophic. David Simoes, CEO of Sounds Good, UK’s leading ecommerce agency notes that human error isn’t unique to third-parties and junior employees. ”I’ve seen one big problem happening caused by the company’s CEO who tested an app on the live store and wished he had a backup solution later”.
2. Theme code edits
The easiest way to break a website is by making a small mistake in its code. If your client is making any customizations or edits to their website, they need to have an easy way to reverse any changes that don’t work out in a way they expect.
3. App integrations
Any time your client is integrating a new app in their store, they should be aware of the permissions they’re granting the app and have a backup in case the app makes any unwanted changes. Having an app play nice with a website is never guaranteed.
4. Ill-intentioned employees and contractors
A Rewind customer lost over 3,000 products – and over a year’s worth of work – when a developer maliciously deleted the data from his ecommerce store. The only thing that saved him was his backups. Read his story here or share it with your client.
5. Hackers and malware
Nearly 70% of small business websites will face some type of cyber attack. In 2019, 10% percent of small businesses hit with a cyberattack were forced to shut down as a result. While Shopify takes extensive precautions to protect their servers against any malicious attacks, hackers target individual accounts and get increasingly creative with their methods. As part of the Shared Responsibilities Model, your client should take precautions to protect their store - having secure backups in place is a must.
6. CSV imports
CSV imports can be helpful when making bulk edits to a store, but they can actually do more harm than good if even one column isn’t accurate.
Facts about Ecommerce Security
• The most vulnerable industry is ecommerce experiencing 32.4% attacks in various forms. Ecommerce sites and apps have storage and exchanges of critical data and sensitive info, so it tempts malicious elements the most. (source)
• Nearly 70% of small business websites will face some type of cyber attack. In 2019, 10% percent of small businesses hit with a cyberattack were forced to shut down as a result. (source)
• Cybercrime is now a 45 billion dollar industry worldwide (source)
• Over 90% of data breaches are caused by human error (source)
• 40% of SaaS app users have experienced data loss (source)
• Ecommerce merchants are facing new and sophisticated threats (source)
• Every minute, four companies fall victim to ransomware attacks. Over 550,000 new pieces of malware are identified daily (source)
About Rewind
Since 2015, Rewind has been on a mission to help businesses protect their SaaS and cloud data.
Over 80,000 customers in 100+ countries trust Rewind’s top-reviewed apps and support to ensure
their software-as-a-service applications run uninterrupted. The Rewind platform enables companies to back up, restore, and copy the critical data that drives their business.
• 80,000+ business owners and brands trust Rewind to safely backup over 2 petabytes of data worldwide, or 30 billion data points.
• Rewind gives companies the tools they need to ensure mistakes don’t stop them from growing.
• Rewind is the leading backup solution for businesses, backing up data that lives in the cloud.
• Rewind provides account-level/merchant-accessible backups of your Shopify/BigCommerce store.
• Rewind is trusted by the world’s fastest-growing brands including P&G, Paul Mitchell, Pampers, MVMT, and more.
• Rewind has over 1,000 5-star reviews across all platforms.
• Rewind helps retailers restore the data powering their business in case of small mistakes and big disasters.
Rewind is SOC2 compliant.
Growth Automated follows ISO 27001 principles from day 1. Certification takes time.
See our key ISO 27001 Aligned principles by design.
1. Data Integrity & Tamper-Proof Backups
💡 "Your backups are only as good as their integrity. We ensure every backup is complete, unaltered, and recoverable—guaranteed."
✅ Alignment: ISO 27001 emphasizes data integrity (A.12.3.1) and protecting data from unauthorized modification.
2. End-to-End Encryption (At Rest & In Transit)
💡 "We encrypt your data before, during, and after backup—so even if someone intercepts it, they can’t read it."
✅ Alignment: Encryption aligns with ISO 27001 Annex A.10 (Cryptographic Controls) and ensures confidentiality of sensitive store data.
3. Access Control & Least Privilege
💡 "Your backups belong to you—period. We enforce strict access controls so only authorized users can view or restore your data."
✅ Alignment: Principle of Least Privilege (A.9.1.2) ensures users can only access what they need, reducing risk.
4. Continuous Backup Monitoring & Automated Integrity Checks
💡 "We don’t just store backups—we verify them daily, ensuring they’re ready when you need them."
✅ Alignment: ISO 27001 stresses proactive monitoring (A.12.4.1) to detect issues before they become failures.
5. Business Continuity & Disaster Recovery by Design
💡 "A backup isn’t enough—you need a recovery plan. We provide built-in disaster recovery workflows so you can restore your store in minutes."
✅ Alignment: ISO 27001 focuses on business continuity (A.17.1) to ensure quick recovery from outages.
6. Zero-Knowledge Security (Merchant-Owned Backups)
💡 "We never have access to your backup data—only you do. This keeps your store safe from insider threats and unauthorized access."
✅ Alignment: ISO 27001 recommends data ownership policies (A.8.1.2) to protect customer data from third parties.