Privacy Policy

Last updated: July 2026

Effective Date: July 1, 2026

1. Introduction

This Privacy Policy explains how ChargeGuard collects, uses, and protects data associated with your merchant account and store orders when you use the ChargeGuard service.

2. What Data We Collect

We collect the following categories of data:

  • Store name and account/contact email address
  • Order data received via Shopify webhooks (order details and customer/order metadata submitted through your connected store)
  • IP addresses associated with orders being analyzed for fraud risk scoring
  • Mobile phone numbers provided voluntarily for SMS alert delivery

3. How We Use Your Data

Your data is used to: generate fraud and chargeback risk scores for incoming orders; generate and deliver alert notifications when high-risk orders are detected; and improve and maintain the ChargeGuard service.

4. Data Sharing

ChargeGuard does not sell merchant or customer data to third parties. Data may be shared with the following service providers, solely to operate the ChargeGuard service:

  • Supabase — database and hosting infrastructure
  • Resend — email alert delivery
  • Twilio — SMS alert delivery

These providers are bound by their own confidentiality and data protection obligations.

5. SMS Communications

By providing your mobile phone number in ChargeGuard account settings, you expressly consent to receive transactional SMS fraud alert messages from ChargeGuard. Message frequency varies based on your store's order volume. Message and data rates may apply. To opt out at any time, reply STOP to any message or remove your number from account settings. Reply HELP for assistance. For privacy questions contact privacy@getchargeguard.io. View our full privacy policy at getchargeguard.io/privacy.

ChargeGuard does not sell, share, or transfer mobile phone numbers or SMS opt-in consent to third parties or affiliates for marketing or promotional purposes.

6. Data Retention

Order data is retained for 12 months from the date of collection, after which it is deleted or anonymized, unless a longer retention period is required by applicable law.

7. Your Rights

Merchants may request access to or deletion of their stored data at any time by contacting privacy@getchargeguard.io. ChargeGuard will respond within a reasonable timeframe.

8. Data Security

ChargeGuard uses reasonable administrative, technical, and organizational safeguards to protect your data. No method of transmission over the internet is 100% secure.

9. Changes to This Policy

Material changes will be communicated via email or in-app notification. Continued use of the service after changes take effect constitutes acceptance.

10. Contact

11. Data Retention

ChargeGuard retains order and customer data used for fraud scoring for a maximum of 90 days from the date of collection. After 90 days, order-level data is automatically deleted from our systems. Merchant account data is retained for the duration of the active subscription and deleted within 30 days of account cancellation. You may request early deletion of your data by contacting support@getchargeguard.io.

12. Data Loss Prevention

ChargeGuard uses Supabase as its database provider, which includes automatic daily encrypted backups, point-in-time recovery, and data redundancy across multiple availability zones. All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher. Access to production data is restricted to authorized personnel only.

13. Security Incident Response

In the event of a data breach or security incident, ChargeGuard will: (1) Identify and contain the incident within 24 hours of detection. (2) Notify affected merchants within 72 hours of confirming a breach via email to their registered address. (3) Provide a full incident report including the nature of the breach, data affected, and remediation steps taken. (4) Report the incident to relevant authorities as required by applicable law. To report a suspected security issue contact security@getchargeguard.io.