Privacy Policy
This policy explains what data Paidback collects, why, where it goes, and what you can do about it. It's written to be read, not skimmed past.
Paidback Technologies, LLC ("Paidback," "we," "us") operates the Paidback Shopify application and paidback.io.
Our Role: Controller and Processor
We handle two different kinds of data in two different legal capacities:
As a data controller, we handle information about you and your business — your store domain, contact email, account settings, and billing records. We decide how that data is used.
As a data processor, we handle personal data belonging to your customers — names, addresses, email addresses, IP addresses, and order details — solely to build and submit chargeback dispute evidence on your behalf. You are the controller of that data. We act only on your instructions and do not use it for our own purposes.
Where we act as your processor, our Data Processing Addendum governs the relationship and forms part of our agreement with you.
What We Collect
Merchant and store data
- Store domain, store name, and Shopify shop ID
- Your name and email address
- Shopify OAuth access tokens
- App configuration and preferences
- Billing records and fee history
- Support correspondence
Customer data accessed for dispute defense
When a chargeback is opened against your store, we access the data required to build a defense:
- Customer name, email address, and billing address
- Shipping address and delivery confirmation data
- IP address and device information associated with the order
- Order contents, amounts, timestamps, and currency
- Fulfillment and tracking information
- Refund and communication history related to the order
We access this data only for orders that are the subject of an active or historical dispute. We do not access or store data for your general order book.
Website data
paidback.io uses Cloudflare Web Analytics, which is cookieless and does not track individuals across sites. We do not use advertising cookies or third-party trackers on our marketing site.
How We Use Data
- To detect chargebacks and disputes on your store
- To assemble, generate, and submit dispute evidence
- To notify you about dispute activity and outcomes
- To calculate and bill success fees through Shopify
- To provide support
- To maintain security, prevent abuse, and meet legal obligations
We also use aggregated and anonymized data — win rates by dispute reason code, evidence patterns that correlate with outcomes — to improve our dispute strategies. This data cannot identify you, your store, or any customer.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use your data or your customers' data to train AI models.
Artificial Intelligence
Paidback uses AI to generate dispute rebuttal letters. Here is exactly what that means.
What we send. When building evidence for a dispute, we transmit order and customer information to Anthropic's Claude API. This includes the customer's name, billing and shipping address, order contents and amounts, fulfillment and tracking data, IP address, and the dispute reason code. A rebuttal letter cannot be written without these facts, so we do not pretend otherwise.
What we do not send. We do not transmit payment card numbers, bank account details, or authentication credentials. We never have access to full card data — Shopify does not expose it to apps.
How it is handled. Anthropic processes API inputs to return a response and does not use data submitted through its API to train its models. Anthropic acts as our subprocessor under a data processing agreement.
Your review rights. Generated evidence is available for you to review before submission. AI-generated content can contain errors. You remain responsible for the accuracy of the underlying facts about your store and orders.
Subprocessors
We use the third-party services listed at paidback.io/subprocessors to operate Paidback. That page names each provider, the data it receives, its purpose, and its processing region.
We maintain a written data processing agreement with every subprocessor that handles personal data. We will provide at least 30 days' notice before adding a new subprocessor that processes customer personal data, giving you the opportunity to object.
International Data Transfers
Paidback is operated from the United States, and our infrastructure and subprocessors are located primarily in the United States. If you or your customers are in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred outside those regions.
We rely on the European Commission's Standard Contractual Clauses (Module Two and Module Three, as applicable) for these transfers, supplemented by the UK International Data Transfer Addendum for UK data and the Swiss addendum for Swiss data. These clauses are incorporated into our Data Processing Addendum.
We apply technical measures to protect transferred data, including encryption in transit and at rest, and we will challenge any government request for data that we believe to be unlawful.
EU and UK Contact
Paidback has no establishment in the European Union or United Kingdom. Data subjects and supervisory authorities in the EEA, UK, or Switzerland may contact us directly at support@paidback.io. We monitor this address and respond to data protection inquiries within 30 days.
Data Retention
| Data | Retention |
|---|---|
| Customer personal data (name, address, email, IP) | Deleted or anonymized within 30 days of dispute resolution |
| Dispute records (reason code, amount, outcome, evidence metadata) | 12 months after resolution, in anonymized form, for accounting and win-rate analysis |
| Merchant account and store data | Duration of installation, then deleted within 30 days of uninstall |
| Billing records | 7 years, as required for tax and financial reporting |
| Support correspondence | 24 months |
Once a dispute closes, we strip the personal data from our records and keep only the anonymized outcome. We do not need your customers' names to know that we won a fraud-reason dispute in March.
Deletion and Data Requests
On uninstall. When you uninstall Paidback, Shopify sends us a shop/redact webhook. We delete your store data and all associated customer personal data within 30 days, retaining only anonymized billing records as required by law.
Customer data requests. Shopify sends us a customers/data_request webhook when one of your customers requests their data. We provide the relevant records to you, as the controller, within 30 days.
Customer deletion requests. Shopify sends us a customers/redact webhook when one of your customers requests erasure. We delete that customer's personal data within 30 days, whether or not the app is still installed.
Direct requests. If a customer contacts us directly, we will refer them to you as the controller and assist you in responding. You can request deletion or a copy of your own store data at any time by emailing support@paidback.io.
Your Rights
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your supervisory authority
We respond to requests within 30 days. We do not charge for these requests and we will not discriminate against you for making one.
United States State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of sale or sharing.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months.
The categories of personal information we collect are described above under "What We Collect." We collect them for the business purposes described under "How We Use Data," and we disclose them only to the subprocessors listed on our subprocessors page.
To exercise any of these rights, email support@paidback.io. We will verify your request through the email address associated with your Shopify store.
Security
- All data is encrypted in transit using TLS 1.2 or higher
- All stored data, including backups, is encrypted at rest by our managed database provider
- Access to production systems is restricted, authenticated, and logged
- Shopify access tokens are held only in session records and are never exposed to third parties
- Error monitoring is configured to filter personal data before transmission
- We follow the principle of least privilege for all data access
- We maintain a written information security policy and incident response plan
- We conduct dependency and vulnerability scanning on our codebase
Breach Notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. Our notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures we have taken.
Where we act as your processor, you remain responsible for notifying your customers and supervisory authorities as required. We will provide the information you need to do so.
Shopify Protected Customer Data
Paidback processes protected customer data under Shopify's Protected Customer Data requirements. We limit our access to the minimum data necessary for dispute defense, encrypt data in transit and at rest, apply the retention limits described above, restrict staff access, maintain a written security policy and incident response plan, and complete Shopify's annual data protection attestation.
Children's Data
Paidback is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
Changes to This Policy
We may update this policy. Material changes will be communicated by email to the address on your Shopify account at least 14 days before taking effect. The "Last updated" date at the top always reflects the current version.
Contact
Paidback Technologies, LLC
A limited liability company organized under the laws of the State of Delaware
Email: support@paidback.io
Privacy inquiries: support@paidback.io
Not affiliated with Shopify Inc.