Privacy Policy
Last updated: March 28, 2025
1. Introduction
Chargeback Shield ("we", "our", or "us") is committed to protecting the privacy of merchants and their customers. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Shopify application and related services.
2. Information We Collect
Order Data
We collect Shopify order data including order IDs, purchase amounts, line items, fulfillment status, and shipping information to build dispute evidence packages.
Customer Data
We may process customer names, email addresses, and shipping/billing addresses as provided through Shopify order records. We do not directly collect customer payment card information.
IP Addresses & Device Information
We collect browser IP addresses and user-agent strings associated with orders (as provided by Shopify) for fraud risk scoring purposes.
Dispute Data
We store chargeback and dispute records including dispute IDs, reasons, amounts, and status updates to generate AI-assisted response drafts.
Merchant Account Data
We store your Shopify store domain, access tokens, and billing information to operate the service.
3. How We Use Your Information
- Fraud Prevention: Analyzing order signals to compute risk scores and flag potentially fraudulent transactions.
- Dispute Drafting: Using AI to generate evidence-backed chargeback response letters on your behalf.
- Fraud Network: Aggregating anonymized fraud signals across merchants to improve detection accuracy. No personally identifiable information is shared in this network.
- Service Operation: Processing webhooks, maintaining your account, and delivering the core functionality of Chargeback Shield.
- Communications: Sending dispute alerts and service notifications to the email address on your merchant account.
4. Data Retention
We retain order and customer data for up to 3 years from the date of collection. Data is automatically deleted after this period. Fraud signal data may be retained longer in anonymized, aggregated form. You may request deletion of your data at any time (see Section 7).
See our Security & Incident Response Policy.
5. Data Sharing & Disclosure
We do not sell your personal data. We may share data with:
- Supabase: Our database provider (data stored in US-East region).
- OpenAI: To generate dispute response drafts. Order and dispute data may be sent to OpenAI's API.
- Shopify: As required to operate within their platform.
- Legal Obligations: When required by law, court order, or government authority.
6. Data Security
We implement industry-standard security measures including TLS encryption in transit, row-level security on our database, and scoped API access tokens. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Your GDPR Rights
If you are located in the European Economic Area (EEA) or the UK, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Data Portability: Request your data in a machine-readable format.
- Right to Object: Object to processing of your personal data for certain purposes.
- Right to Restrict Processing: Request that we limit how we use your data.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Cookies
Our application uses session cookies required for authentication and security. We do not use third-party tracking or advertising cookies.
9. Children's Privacy
Chargeback Shield is a B2B service intended for merchants. We do not knowingly collect data from individuals under the age of 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the service after changes constitutes acceptance.
11. Contact Us
For privacy-related questions or to exercise your rights, contact:
Chargeback Shield Privacy Team
Email: [email protected]