Legal
Privacy policy
Counterproof, chargeback dispute evidence automation for Shopify merchants.
What we collect
Counterproof processes only the data needed to build and submit chargeback evidence for the disputes it handles. From your Shopify store, via these five OAuth scopes:
read_orders— Read order, fulfillment, and tracking data — the raw material of a dispute packet.read_all_orders— Read order history beyond the default 60-day window — the prior undisputed transactions that qualify Visa CE3.0 fraud evidence.read_shopify_payments_disputes— Read the chargeback/dispute records the app responds to.read_shopify_payments_dispute_evidences— Read the dispute evidence already on file for a case.write_shopify_payments_dispute_evidences— Save the assembled evidence packet back to Shopify so Shopify's auto-submit sends our packet.
If you connect Stripe, we read dispute and evidence data from your Stripe account using a restricted key you provide (Disputes read/write, Files write, and Radar read only). The key is stored encrypted and is never displayed again in full.
We do not currently operate a device-fingerprint or IP-capture pixel. When enabled in a future release, device-ID and IP capture at checkout will be documented here before it collects anything, and disclosed at the point of capture.
How long we keep it
Personal data attached to a dispute — the cardholder's name, email and address, the order snapshot, any conversation you paste in, and the generated evidence packet — is deleted 18 months after that dispute reaches a final outcome (won, lost, accepted, or expired). A scheduled job runs this deletion; it is not something you have to request.
The horizon is the card-network dispute window, not a round number: a cardholder can dispute a transaction up to 120 days after expected delivery and at most 540 days (about 18 months) after the transaction itself. Once that window has closed, no card network can reopen the case, so we no longer have a reason to hold the evidence and we delete it.
What remains afterwards is a stripped-down record of the dispute itself — our own reference, the payment processor's dispute reference, the amount, the dates and the outcome. It holds no name, email, address, order contents, evidence documents or correspondence; those are what the deletion above removes. We keep the remainder as an audit trail of the work we did for you.
We describe that remainder as stripped of personal details rather than fully anonymous, and the distinction is deliberate: the processor's dispute reference still points at a transaction inside your payment provider's systems, so it is not beyond all possibility of being linked back. We keep no key of our own that does so.
When a shop uninstalls, its stored dispute data and credentials are purged after the Shopify shop/redact window (below), regardless of the 18-month horizon.
GDPR / privacy webhooks we honor
Shopify sends three mandatory compliance webhooks; every request is HMAC-verified before it is trusted, recorded in our audit trail, and acknowledged:
customers/data_request— We log the request in our audit trail and acknowledge it. Counterproof stores dispute evidence keyed by order, not by customer profile, so there is no separate customer profile to export.customers/redact— We log and acknowledge the erasure request, then delete that customer's order-scoped dispute data — dispute records, assembled packets, evidence items, captured messages and stored files — rather than retaining it.shop/redact— Sent 48 hours after a shop uninstalls. We log and acknowledge it, then purge the shop’s stored dispute data and credentials.
We do not sell your data
We do not sell, rent, or share your data for advertising or any purpose beyond operating the service. Data is used only to build, review, and submit your dispute evidence.
Subprocessors
We rely on these processors to run the service:
- Cloudflare — Application hosting, database, and file storage (Workers, D1, R2).
- AI text-generation infrastructure — The language model that writes rebuttal-letter prose within a fixed evidence skeleton. It never selects evidence or asserts facts (spec §2.3).
- Stripe — Read dispute and evidence data from your connected Stripe account, via a restricted key you provide.
- Resend — Delivers the email notifications we send you (new dispute, deadline reminders). Receives your notification email address and the dispute details in the message — never cardholder data.
Contact
Questions about this policy or your data: support@counterproof.app.