Privacy Policy

FraudPilot: High-risk order review for Shopify

Effective date: September 14, 2026

This Privacy Policy explains how Alpenglow Software LLC ("we," "us," "our"), operator of FraudPilot ("the App"), collects, uses, stores, and protects information when you install and use the App through the Shopify platform. FraudPilot is a human-review queue for orders that Shopify's risk engine flags as medium or high risk. It enriches each flagged order with the facts you need to make a call, lets you record your decision (approve, cancel, or tag), and keeps an immutable, append-only decision log you can export as chargeback-representment evidence. FraudPilot is read-only against your Shopify data and does not decide for you. See Section 1 for details.

1. Information We Collect

Data from Shopify APIs

The App requests the following Shopify access scopes:

The App requests no write scopes. It does not cancel, modify, refund, fulfill, or tag orders on your behalf, and it does not change any customer or order record in Shopify. Any action you take on an order is completed by you in the Shopify Admin.

Protected Customer Data (Level 1)

Two of the fields above are treated as Shopify Protected Customer Data at Level 1 (identifiers only, with no name, address, email, or phone):

The App does not request or access any Level 2 Protected Customer Data (name, address, email, or phone). Those fields are withheld by Shopify unless an app is separately approved for them, and FraudPilot does not request that approval.

Data collected through the Shopify session

Shopify provides the following data as part of the standard app authentication process:

This session data is managed by Shopify's official session storage library and is required for the App to function within the Shopify Admin. The App additionally stores the staff user identifier derived from the session with each recorded decision, so the decision log accurately attributes who made each call.

Data we generate and store

As you use the App, we store:

Data we do NOT collect

We do not use artificial intelligence or machine learning to process your data, and your data is not used to train AI or machine-learning models.

2. How We Use Your Information

We use the data we collect solely to provide and improve the App's services:

We do not sell your data, and we do not use it for advertising, marketing, profiling, or automated decision-making. FraudPilot makes no automated decision about any order or customer; every decision recorded in the App is one a member of your staff made.

For the purposes of applicable data protection laws, you (the merchant) are the data controller for the order and customer data made available through the App. Alpenglow Software LLC acts as a data processor, processing that data solely on your behalf and as described in this policy. For any data we collect directly from you (such as support communications), we act as an independent data controller.

3. How We Process Order Data

Order and risk data flows through the App as follows:

  1. When Shopify flags an order as medium or high risk (or when the App reads a flagged order via the Admin API), the App fetches the order facts and risk signals over the read_orders scope and the customer identifier over the read_customers scope.
  2. The client IP on the order is reduced to a /24 network prefix and resolved to a country using a local geographic-IP database in the same step. The raw IP is discarded and never written to storage.
  3. The App assembles an enrichment snapshot from these facts, adds order-velocity and prior-decision context drawn only from your own store's records, and places the order in your review queue.
  4. When you make a decision, the App writes an append-only decision-log entry capturing the action, your reason, and the evidence snapshot as it stood at that moment.
  5. Enrichment and decision records are displayed to you in the App and can be exported for representment.

The decision log is append-only: the App exposes no path to edit or delete a logged decision through normal use. This is what makes the log usable as tamper-resistant evidence. The only paths that remove decision-log rows are the data-deletion obligations described in Section 6 (customer redaction, shop redaction, or a deletion request you make).

4. Data Storage and Security

5. Third-Party Services

The App uses the following third-party services to operate:

ServicePurposeData shared
Shopify Admin API Authentication, order and risk-assessment data, customer identifier Session tokens, GraphQL order and customer queries
Railway Application and database hosting All stored data (encrypted in transit; access tokens encrypted at rest)
Resend Transactional email: a daily review digest to Paid-plan stores (contact us to stop receiving it), and operator alerts Recipient email address and message content (queue counts and notifications). No customer identifiers or order-level personal data are sent.
Inngest Background job scheduling Shop ID and job parameters only. No customer personal data is placed in job payloads.

The App also uses geoip-lite, an open-source geographic-IP database that runs entirely on our server. No data is sent to any external service for IP-to-country resolution.

If we add or replace a sub-processor in a way that materially affects how your data is processed, we will update this Privacy Policy and notify you through the App.

6. Data Retention

7. Your Rights

You have the right to:

Regarding your customers. FraudPilot does not collect customer names, addresses, email addresses, or phone numbers. It does store two Level 1 identifiers tied to a flagged order: the Shopify Customer identifier and the coarsened /24 network prefix. Because these identifiers can be associated with an order, and through your Shopify records with an identifiable customer, we treat the order-linked review artifacts and decision-log rows as personal data rather than as anonymous data. FraudPilot honors Shopify's customer privacy webhooks for this data:

If a customer contacts you with a data request, you may contact us and we will assist. We respond to all data requests within 30 days.

8. International Data Transfers

Your data is processed and stored on servers located in the United States. By using the App, you consent to the transfer of your data to the United States for processing.

9. Cookies and Tracking

The App does not use cookies, tracking pixels, or any analytics or advertising technologies, and it does not track your behavior within the Shopify Admin. FraudPilot has no storefront component and collects nothing from your store's visitors.

10. Children's Privacy

The App is designed for use by Shopify merchants (business users) and is not directed at children under 13. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

Email: support@alpenglowsoftware.com