Merchant terms and data processing agreement
Agreement version: 1.1
Legal service provider and processor: SignalCards
Legal form: SASU
Trading/product name: SignalCards
Registered office:
14 rue Desaix
75015 Paris
France
Registered-office SIRET: 563 299 891 00135
Privacy contact: contact@getsignalcards.com
Governing law: French law
Parties and roles
The merchant is the controller or business responsible for its Shopify customer and order data. SignalCards, a SASU operating the SignalCards Chargeback Evidence service acts as the processor or service provider on the merchant’s documented instructions.
Service boundary
The app helps a merchant collect available Shopify facts and prepare a human-reviewed chargeback evidence workflow. Human review remains required. The app does not invent evidence or consent, provide legal advice, guarantee outcomes, or submit chargebacks automatically.
Processing instructions and minimization
The merchant instructs processing through installation and authenticated actions. SignalCards processes only the minimum fields needed for those actions. Customer Name, Email, Phone, billing address, shipping address, and customer IP fields are not requested. Unrestricted order tags and paymentId are not stored.
Purpose limitation
Protected data is not sold, used for advertising, used for unrelated SignalCards research, used for model training, or combined across merchants for customer profiling.
Security and confidentiality
Access is tenant-scoped. Tokens are encrypted on the server. Transport uses TLS, protected values are excluded from application logs, and data is deleted through authenticated merchant controls and verified Shopify privacy webhooks.
Privacy assistance and incidents
SignalCards supports Shopify data request and redaction workflows. SignalCards will notify the merchant without undue delay after becoming aware of a confirmed personal data breach affecting the merchant’s protected data.
Retention and termination
The published retention schedule applies. No indefinite retention is permitted. A verified shop redaction deletes the tenant, and uninstalling the app immediately removes its stored sessions and tokens.