SignalCards Chargeback Evidence privacy policy

Service provider and processor: SignalCards, a SASU operating the SignalCards Chargeback Evidence service.
Privacy contact: contact@getsignalcards.com

Merchant and processor roles

The merchant is the controller or business responsible for its Shopify customer and order data. The provider identified above acts as the processor or service provider and processes that data only on the merchant’s documented instructions.

Information processed

The app processes Shopify shop and installation identifiers, encrypted access tokens, and the minimum order, line-item, transaction, refund, fulfillment, tracking, and dispute facts needed for a human-reviewed chargeback evidence workflow.

The app does not request or store customer Name, Email, Phone, billing address, shipping address, or customer IP fields. It does not store unrestricted order tags, paymentId, full card numbers, or CVV.

Merchant-entered manual references, reasons, amounts, currencies, and deadlines are processed only when the merchant chooses to provide them. Merchants must not enter customer identities, payment-card data, credentials, or unrelated sensitive information in free-text fields.

Purpose limitation

Protected data is used only for merchant-authorized chargeback evidence functionality, application security, and privacy compliance. It is not sold, used for advertising, used for unrelated SignalCards research, or used for model training.

Human review and automated decisions

Human review remains required. The app does not submit chargebacks automatically and does not make automated decisions with legal or similarly significant effects.

Processors and security

Shopify supplies merchant-authorized data. Render hosts the isolated application and Supabase hosts its dedicated PostgreSQL database. Traffic is protected with TLS, database storage uses managed encryption at rest, and Shopify tokens use server-side authenticated encryption.

Incident notification

SignalCards will notify the merchant without undue delay after becoming aware of a confirmed personal data breach affecting the merchant’s protected data.

Retention and deletion

The retention schedule limits each record class and prohibits indefinite retention. Verified Shopify privacy webhooks and authenticated merchant controls support access and deletion. See the Retention page for the complete schedule.

Contact and privacy requests

Contact contact@getsignalcards.com or use the authenticated Request Data and deletion controls in App Home.