SignalCards Chargeback Evidence privacy policy
Service provider and processor: SignalCards, a SASU operating the SignalCards Chargeback Evidence service.
Privacy contact: contact@getsignalcards.com
Merchant and processor roles
The merchant is the controller or business responsible for its Shopify customer and order data. The provider identified above acts as the processor or service provider and processes that data only on the merchant’s documented instructions.
Information processed
The app processes Shopify shop and installation identifiers, encrypted access tokens, and the minimum order, line-item, transaction, refund, fulfillment, tracking, and dispute facts needed for a human-reviewed chargeback evidence workflow.
The app does not request or store customer Name, Email, Phone, billing address, shipping address, or customer IP fields. It does not store unrestricted order tags, paymentId, full card numbers, or CVV.
Merchant-entered manual references, reasons, amounts, currencies, and deadlines are processed only when the merchant chooses to provide them. Merchants must not enter customer identities, payment-card data, credentials, or unrelated sensitive information in free-text fields.
Purpose limitation
Protected data is used only for merchant-authorized chargeback evidence functionality, application security, and privacy compliance. It is not sold, used for advertising, used for unrelated SignalCards research, or used for model training.
Human review and automated decisions
Human review remains required. The app does not submit chargebacks automatically and does not make automated decisions with legal or similarly significant effects.
Processors and security
Shopify supplies merchant-authorized data. Render hosts the isolated application and Supabase hosts its dedicated PostgreSQL database. Traffic is protected with TLS, database storage uses managed encryption at rest, and Shopify tokens use server-side authenticated encryption.
Incident notification
SignalCards will notify the merchant without undue delay after becoming aware of a confirmed personal data breach affecting the merchant’s protected data.
Retention and deletion
The retention schedule limits each record class and prohibits indefinite retention. Verified Shopify privacy webhooks and authenticated merchant controls support access and deletion. See the Retention page for the complete schedule.
Contact and privacy requests
Contact contact@getsignalcards.com or use the authenticated Request Data and deletion controls in App Home.