Privacy & protected customer data
How Chargeback Recovery uses merchant and customer information to identify, prepare, and manage merchant-approved chargeback recoveries.
Effective 30 August 2026 · Version 1.0
Information we process
Chargeback Recovery processes only information needed to operate the app and its recovery workflow.
- Merchant and store information, including the authenticated Shopify shop domain, app preferences, support messages, and Shopify session data.
- Chargeback, linked-order, debtor, fulfillment, tracking, and merchant-uploaded evidence used for a recovery case.
- Minimal security, audit, workflow, payment, and provider-status records needed to operate and protect the service.
Exact linked-order access
For a LOST Shopify Payments dispute, the app may read only the exact Shopify Order linked by Shopify to that dispute. The raw response is transient. Available values may prefill a merchant-reviewed RecoveryCase.
- Name, to identify the debtor or order recipient.
- Email, to provide the recovery-case contact email.
- Shipping or billing address, to identify the debtor and prepare the recovery case.
What we do not do
The protected information is limited to the recovery workflow.
- We do not request read_customers or browse Shopify Customer records or customer history.
- We do not browse unrelated orders or use the linked-order flow as a general order-history search.
- We do not use customer data for marketing, advertising, or personalization.
- We do not sell personal data.
- We do not make automated legal or similarly significant decisions about customers.
Purpose and merchant control
The information identifies the debtor and order, reduces manual entry, supports fulfillment and tracking evidence, and helps the merchant prepare a recovery case.
Finding or preparing a case does not contact the customer and does not begin recovery. Merchant-saved case values are authoritative. Recovery requires an explicit merchant action before the app can send collection emails or create a Shopify Draft Order payment request.
Storage and service providers
Application records are hosted using Vercel and Supabase. Uploaded evidence is kept in a private Supabase Storage bucket and is accessed through short-lived, case-scoped signed URLs. Application secrets remain server-side.
Shopify supports the embedded application and merchant-approved Draft Order payment requests. Resend processes controlled recovery and support emails. No debt collection agency receives RecoveryCase, customer, order, or evidence data.
Retention and deletion
Required personal data is retained while a recovery is active. Customer-identifying case data and evidence become eligible for deletion or anonymisation 24 months after a terminal case closes. Unconverted local snapshots become eligible after 24 months without relevant activity.
Shopify privacy webhooks support customer access requests, customer redaction, and shop erasure. Uninstall removes Shopify sessions; shop redaction removes the tenant’s remaining database records and private evidence objects.
Rights and requests
Merchants and data subjects may have rights to access, correct, restrict, or delete personal data under applicable law. Merchants can contact support for requests relating to Chargeback Recovery.
Customer requests initiated through Shopify are received through Shopify’s signed privacy webhooks. Data-access requests are placed in an operational queue for response to the merchant; redaction requests remove or anonymise the matching local personal data.
Security
We use authenticated Shopify sessions, tenant-scoped database access, HTTPS, server-held secrets, private object storage, short-lived signed evidence links, bounded inputs, and structured log redaction. No online service can guarantee absolute security.
Contact
Chargeback Recovery is operated by Marc Best, 58 Ramilles Close, London, SW2 5DG, United Kingdom. Questions and privacy requests can be sent to support@aithorapp.co.uk.