Privacy Policy
FraudPilot: High-risk order review for Shopify
Effective date: September 14, 2026
This Privacy Policy explains how Alpenglow Software LLC ("we," "us," "our"), operator of FraudPilot ("the App"), collects, uses, stores, and protects information when you install and use the App through the Shopify platform. FraudPilot is a human-review queue for orders that Shopify's risk engine flags as medium or high risk. It enriches each flagged order with the facts you need to make a call, lets you record your decision (approve, cancel, or tag), and keeps an immutable, append-only decision log you can export as chargeback-representment evidence. FraudPilot is read-only against your Shopify data and does not decide for you. See Section 1 for details.
1. Information We Collect
Data from Shopify APIs
The App requests the following Shopify access scopes:
read_orders: used to build and enrich the review queue. For each order Shopify flags as medium or high risk, the App reads and stores the order name/number, order total and currency, line-item count, AVS (address verification) and CVV result codes, fulfillment status, and Shopify's own risk assessment and risk signals. The App reads the network (IP) address recorded on the order, but stores it only in coarsened form (see "Protected Customer Data" below). The App does not access or store customer names, postal addresses, email addresses, phone numbers, or payment card information through this scope.read_customers: used solely to read the Shopify Customer identifier (the customer's GID) attached to an order, so the App can recognize a repeat buyer across your own prior decisions. The App reads and stores the customer identifier only. It does not read or store the customer's name, email address, phone number, or address, and it does not modify customer records.
The App requests no write scopes. It does not cancel, modify, refund, fulfill, or tag orders on your behalf, and it does not change any customer or order record in Shopify. Any action you take on an order is completed by you in the Shopify Admin.
Protected Customer Data (Level 1)
Two of the fields above are treated as Shopify Protected Customer Data at Level 1 (identifiers only, with no name, address, email, or phone):
- Coarsened network (IP) prefix and country: the App reads the client IP recorded on the order and immediately reduces it to a
/24network prefix (the final part of the address is discarded) and derives a country using a local geographic-IP database bundled with the App. The raw IP address is never stored, and no external lookup is performed for this. The coarsened prefix and country are used only to surface order velocity and geographic context for the flagged order, and to recognize whether the same network has appeared in your prior decisions. - Shopify Customer identifier (GID): used only to recognize repeat buyers across your own past decisions, as described above.
The App does not request or access any Level 2 Protected Customer Data (name, address, email, or phone). Those fields are withheld by Shopify unless an app is separately approved for them, and FraudPilot does not request that approval.
Data collected through the Shopify session
Shopify provides the following data as part of the standard app authentication process:
- Shop domain
- Staff member name, email address, and user ID
- Account role (store owner or collaborator) and email verification status
- Locale preference
- Session tokens, access tokens, and refresh tokens
This session data is managed by Shopify's official session storage library and is required for the App to function within the Shopify Admin. The App additionally stores the staff user identifier derived from the session with each recorded decision, so the decision log accurately attributes who made each call.
Data we generate and store
As you use the App, we store:
- Review queue items: the flagged orders awaiting your review, and their queue state (for example, needs decision, snoozed, decided).
- Enrichment snapshot: the order facts and risk signals described above, captured at review time so the record reflects what was known when the decision was made.
- Decision log entries (append-only): for each decision, the order identifier, the acting staff user identifier, the action taken (approve, cancel, or tag), your reason or note, a snapshot of the risk facts at decision time, the associated Shopify Customer identifier, and the coarsened
/24network prefix. - Dispute outcomes: if you record how a chargeback or dispute resolved (for example, "won in representment"), we store that outcome against the related decision.
- Store contact email: your store's contact email address, read from Shopify and stored so we can send the daily review digest (when enabled). This is your own merchant email, not customer data.
Data we do NOT collect
- Customer or shopper names, postal addresses, email addresses, or phone numbers
- Raw (full) IP addresses
- Payment card or banking information
- Product catalog, inventory, or theme/storefront code
- Storefront visitor or web-analytics behavior data
- Marketing or advertising data
We do not use artificial intelligence or machine learning to process your data, and your data is not used to train AI or machine-learning models.
2. How We Use Your Information
We use the data we collect solely to provide and improve the App's services:
- Review queue: we surface orders Shopify has flagged as medium or high risk so you can review them in one place rather than scanning the raw Orders list.
- Enrichment: we assemble the order facts, risk signals, geographic and network context, order velocity, and your own prior decisions for the same buyer or network into a single review panel.
- Decision recording: we record the decision you make (approve, cancel, or tag), together with your reason and the evidence snapshot, into the immutable decision log.
- Representment evidence: we let you export the decision log and its evidence snapshots as a CSV file you can use to contest chargebacks.
- Outcome tracking: we store dispute outcomes you record so you can see how your decisions held up.
- Subscription management: we store your current billing plan to gate features appropriately.
- App functionality: we use your shop domain and session data to authenticate requests and deliver the App within the Shopify Admin.
We do not sell your data, and we do not use it for advertising, marketing, profiling, or automated decision-making. FraudPilot makes no automated decision about any order or customer; every decision recorded in the App is one a member of your staff made.
For the purposes of applicable data protection laws, you (the merchant) are the data controller for the order and customer data made available through the App. Alpenglow Software LLC acts as a data processor, processing that data solely on your behalf and as described in this policy. For any data we collect directly from you (such as support communications), we act as an independent data controller.
3. How We Process Order Data
Order and risk data flows through the App as follows:
- When Shopify flags an order as medium or high risk (or when the App reads a flagged order via the Admin API), the App fetches the order facts and risk signals over the
read_ordersscope and the customer identifier over theread_customersscope. - The client IP on the order is reduced to a
/24network prefix and resolved to a country using a local geographic-IP database in the same step. The raw IP is discarded and never written to storage. - The App assembles an enrichment snapshot from these facts, adds order-velocity and prior-decision context drawn only from your own store's records, and places the order in your review queue.
- When you make a decision, the App writes an append-only decision-log entry capturing the action, your reason, and the evidence snapshot as it stood at that moment.
- Enrichment and decision records are displayed to you in the App and can be exported for representment.
The decision log is append-only: the App exposes no path to edit or delete a logged decision through normal use. This is what makes the log usable as tamper-resistant evidence. The only paths that remove decision-log rows are the data-deletion obligations described in Section 6 (customer redaction, shop redaction, or a deletion request you make).
4. Data Storage and Security
- All data is stored in a PostgreSQL database hosted on Railway (United States).
- Shopify access tokens are encrypted at rest using AES-256-GCM encryption.
- All connections use HTTPS/TLS encryption in transit.
- We store the client IP only in coarsened
/24form; the raw IP is never persisted. - We do not sell your data. We do not share your data with third parties for marketing, advertising, or profiling purposes.
- In the event of a data breach affecting your data, we will notify you and Shopify within 24 hours of discovery, in accordance with Shopify's Partner Program Agreement and applicable law.
5. Third-Party Services
The App uses the following third-party services to operate:
| Service | Purpose | Data shared |
|---|---|---|
| Shopify Admin API | Authentication, order and risk-assessment data, customer identifier | Session tokens, GraphQL order and customer queries |
| Railway | Application and database hosting | All stored data (encrypted in transit; access tokens encrypted at rest) |
| Resend | Transactional email: a daily review digest to Paid-plan stores (contact us to stop receiving it), and operator alerts | Recipient email address and message content (queue counts and notifications). No customer identifiers or order-level personal data are sent. |
| Inngest | Background job scheduling | Shop ID and job parameters only. No customer personal data is placed in job payloads. |
The App also uses geoip-lite, an open-source geographic-IP database that runs entirely on our server. No data is sent to any external service for IP-to-country resolution.
If we add or replace a sub-processor in a way that materially affects how your data is processed, we will update this Privacy Policy and notify you through the App.
6. Data Retention
- While installed: review queue items, enrichment snapshots, decision-log entries, and dispute outcomes are retained for as long as the App is installed on your store. The decision log is retained deliberately, because it is your representment evidence.
- On uninstall: when you uninstall the App, Shopify sends a shop-redact request (typically 48 hours after uninstall). On receiving it, all data associated with your shop is permanently deleted, including sessions, queue items, enrichment snapshots, decision-log entries, dispute outcomes, and your shop record. Deletion is completed within the timeframe below.
- GDPR / privacy shop-redact: if Shopify sends a shop data erasure request, all shop data is deleted within 30 days (and in practice promptly on receipt).
- Customer redaction: on a customer redaction request (see Section 7), the review artifacts, decision-log rows, and dispute outcomes tied to the affected order(s) are deleted within 30 days.
7. Your Rights
You have the right to:
- Access: view your review queue, enrichment snapshots, and full decision history in the App, and export the decision log as CSV.
- Deletion: uninstalling the App deletes all your data (see Section 6). You may also contact us to request deletion without uninstalling.
- Data portability: export your decision log from the App, or contact us to request an export of your stored data in a machine-readable format.
- Correction: contact us if you believe any stored data is inaccurate. Note that the decision log is append-only by design; corrections are made by recording a new decision rather than altering a historical entry.
Regarding your customers. FraudPilot does not collect customer names, addresses, email addresses, or phone numbers. It does store two Level 1 identifiers tied to a flagged order: the Shopify Customer identifier and the coarsened /24 network prefix. Because these identifiers can be associated with an order, and through your Shopify records with an identifiable customer, we treat the order-linked review artifacts and decision-log rows as personal data rather than as anonymous data. FraudPilot honors Shopify's customer privacy webhooks for this data:
- A
customers/data_requestsurfaces the review artifacts and decision-log rows we hold for the requested customer's orders. - A
customers/redactrequest deletes the order-linked review artifacts, decision-log rows, and dispute outcomes for the specified orders. - A
shop/redactrequest deletes all data for your shop.
If a customer contacts you with a data request, you may contact us and we will assist. We respond to all data requests within 30 days.
8. International Data Transfers
Your data is processed and stored on servers located in the United States. By using the App, you consent to the transfer of your data to the United States for processing.
9. Cookies and Tracking
The App does not use cookies, tracking pixels, or any analytics or advertising technologies, and it does not track your behavior within the Shopify Admin. FraudPilot has no storefront component and collects nothing from your store's visitors.
10. Children's Privacy
The App is designed for use by Shopify merchants (business users) and is not directed at children under 13. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at: