Skip to content

Help centre · The safety net

Exporting your data and understanding backups

Download the shop data you can carry away, know what the archive deliberately excludes, and do not confuse that export with an off-provider disaster-recovery backup.

For owner, manager · checked against the product on 2026-09-14

The shop's export is the self-service way to take business records out of Torqix. It downloads a zip of portable files and a manifest. There is no plan or subscription check on that route, so export remains available during the read-only period after cancellation. Nothing in the product is labelled "Full export" — the download is a link, and which words it wears depends on which of three screens you reach it from.

What the archive contains

The archive is assembled inside the current organisation boundary. It includes the shop's customers, vehicles, work, purchase orders and receipts, cycle counts, vendor returns, digital inspections and inspection-template metadata, plus the other supported records described by its manifest; it never reaches another tenant. Test data is left out, so a sample shop or receptionist test cannot inflate what an owner believes is real business history.

What a manager receives follows the same money-visibility rules as the app. A role without cost visibility does not gain it by exporting. Secrets are excluded: passwords, sealed provider credentials, API keys and other account-access material do not belong in a business-data archive.

The separate Download books export under Settings › Accounting is the accountant-and-owner extract: invoices, payments, purchase tax and the customers they belong to. Its README names the shop's ISO 4217 currency, and every CSV row with a cents column carries that same currency beside it. Amounts remain integer cents; the export labels them and never converts them.

  1. Step 1: Start the export

    The door a manager can always reach is on the settings index: open Settings and follow Your data leaves with you. An owner has two more — Download current export on Settings › Billing, and Export everything available first in the cancellation flow — and all three fetch the same archive. The current role still decides which money fields may be present.

  2. Step 2: Keep the manifest with the files

    The manifest records the export format and what was produced. Keep it beside the data rather than treating the zip as a set of unrelated spreadsheets.

  3. Step 3: Store your copy somewhere you control

    An export is useful only after it has left this deployment. Download it, protect it as customer data, and test that your chosen storage can return it to you.

The off-provider backup is a different control

The operator runbook defines a nightly encrypted database dump to separately owned Cloudflare R2 storage and a weekly copy to Backblaze B2, with 35 daily and 400 weekly recovery points. That mechanism is for recovering the service after provider loss. It is not a shop-facing download and does not replace the portable full export.

The code, encryption, retention checks and tenant-policy smoke checks are built. The provider accounts and credentials are not provisioned, so the off-provider control is not operating. It has never completed a provider upload, download or production restore. Until an owner provisions both destinations and a real restore drill succeeds, its provider-loss recovery point and recovery time are unverified.