Privacy Policy

Last updated: March 24, 2026

1. Introduction

ChargeGuard ("we", "our", "us") provides AI-powered fraud detection and chargeback prevention services for Shopify merchants. This Privacy Policy explains how we collect, use, store, and protect data when you install and use the ChargeGuard application.

By installing ChargeGuard, you agree to the data practices described in this policy.

2. Data We Collect

When you install ChargeGuard, we access and process the following data through Shopify's API:

Order Data

  • Order details (amounts, currency, line items, timestamps)
  • Shipping and billing addresses
  • Payment status and gateway information
  • Order tags and notes

Customer Data

  • Customer name and email address
  • Purchase history and order count
  • Account creation date

Dispute Data

  • Chargeback and inquiry details
  • Dispute reasons and status

Technical Data

  • IP addresses associated with orders
  • Device fingerprints and browser information (when available from Shopify)
  • Geolocation data derived from IP addresses

Data We Do NOT Collect

  • Credit card numbers, CVVs, or full payment card details (PCI data)
  • Social security numbers or government IDs
  • Customer passwords

3. How We Use Your Data

We use the data we collect for the following purposes:

  • Fraud risk analysis: We analyze order and customer data using 34 detection signals to generate fraud risk scores for each order.
  • AI-powered explanations: We use AI to provide plain-English explanations of why an order was flagged as risky.
  • Chargeback prevention: We monitor disputes and generate AI-assisted response letters to help you fight chargebacks.
  • Pattern detection: We identify suspicious patterns across orders, including velocity checks, address mismatches, and device anomalies.
  • Merchant dashboard: We display analytics and risk summaries to help you make informed decisions about your orders.

We do not use your data for advertising, marketing to your customers, or any purpose unrelated to the functionality of the App.

4. Third-Party Services

We do not sell, rent, or trade your data. We share data only with the following third-party service providers as necessary to operate the App:

Provider Purpose Data Shared
Anthropic (Claude AI) AI-powered fraud analysis and dispute letter generation Order amounts, addresses, customer behavior patterns
Vercel Application hosting and data storage Application logs, request data
Shopify Platform integration Order and customer data (via Shopify Admin API)

No data sent to Anthropic is used to train their models. Each third-party provider processes data in accordance with their own privacy policies and is contractually obligated to protect your data.

5. Data Retention

Data Type Retention Period
Order risk scores and analysis 365 days
Dispute records and response letters 365 days
Analytics and aggregated data 180 days
IP addresses and device fingerprints 90 days
Session and authentication data 30 days

When you uninstall ChargeGuard, all associated data is deleted within 30 days. You may request immediate deletion at any time by contacting us.

Shopify Mandatory Compliance Webhooks

We comply with all Shopify mandatory GDPR/privacy webhooks:

  • Customer data request (customers/data_request): We acknowledge the request and provide any customer-related data we hold (order risk scores, fraud analysis associated with that customer).
  • Customer data erasure (customers/redact): Upon receiving this request, all data associated with the specified customer is permanently deleted.
  • Shop data erasure (shop/redact): Upon receiving this request, all data associated with your store is permanently deleted, including risk scores, dispute records, analytics, and any related data.

6. Your Rights (GDPR & CCPA)

As a merchant using the App, you have the right to:

  • Access: Request a copy of the data we hold about your store and customers.
  • Deletion: Request deletion of all stored data.
  • Portability: Receive your data in a machine-readable format.
  • Correction: Request correction of inaccurate data.
  • Objection: Object to specific data processing activities.

We respond to all data requests within 30 days.

For EU/EEA Merchants (GDPR)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority.

For California Merchants (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

7. Data Security

  • All data is transmitted over HTTPS/TLS encryption.
  • Data at rest is encrypted in our storage systems.
  • We follow the principle of least privilege for API access scopes.
  • No PCI-regulated payment card data is stored.
  • Access to merchant data is restricted to authorized systems only.
  • All incoming Shopify webhook requests are verified using HMAC signature validation to prevent unauthorized access.

8. Children's Privacy

ChargeGuard is a business-to-business service for Shopify merchants. We do not knowingly collect data from children under 13 (or under 16 in the EU). If you believe we have inadvertently collected such data, contact us and we will delete it promptly.

9. International Data Transfers

Your data may be processed and stored in locations outside your country of residence, including the United States, where our hosting and AI providers operate. By using the App, you consent to the transfer of your data to these locations. We ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes:

  • We will update the "Last updated" date at the top of this page.
  • We will notify merchants of material changes through the App or via email.

Continued use of ChargeGuard after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions, data requests, or concerns, please contact us:

Email: info@pixlerlab.com

We aim to respond to all inquiries within 48 hours and resolve data requests within 30 days.