Information we process
When you apply as a store, partner, or investor, we use your contact details and the business information you provide to review your application and respond. Applications are delivered to our team through Brevo and do not create an account.
For direct merchant accounts, we process the account holder’s name and email address, business or shop name, storefront URL, selected e-commerce platform, sales currency, aggregate monthly sales volume, average sale, current chargeback ratio, invoice records, business settings, and storefront liveness test records. The sales and chargeback figures are shop-level aggregates supplied by the merchant, not individual customer transaction records.
For the Shopify App, we process Shopify installation identifiers, store configuration, operational order references, timestamps, amounts, currencies, payment and transaction identifiers, risk assessments, merchant decisions, dispute status, reasons, amounts, currencies and deadlines, provider alerts and connection configuration, audit records, billing status, and verified merchant notification recipients.
Evidence access requires Shopify permissions and protected customer data approval. When enabled, customer name, email, and billing and shipping addresses are read from Shopify for dispute review and merchant-confirmed evidence submission. Customer phone numbers and IP addresses are not requested. Lower Chargeback does not contact customers or collect replies.
Store owners can save encrypted business details and dispute information locally in Lower Chargeback. Shopify values take precedence, and saving manual information never changes Shopify records.
Notification recipients
Entered and verified by the merchant; never imported from Shopify customer records.
Payment and decision boundaries
Direct account invoice records contain the invoice amount and status, but Lower Chargeback does not store card numbers. Provider credentials are encrypted before storage and are never returned after they are saved. The Shopify App does not create Shopify refunds, automatically accept or decline network cases, automatically report provider outcomes, send customer messages, or submit dispute evidence without explicit merchant confirmation.
How information is used
Direct account information is used to create and secure the merchant account, issue and display the registration invoice, send account and invoice messages, maintain business settings, run storefront liveness tests, and record their results. Shopify App information is used to synchronize operational order data, present risk signals, record merchant decisions, monitor disputes, match provider alerts to eligible order references, notify verified merchant recipients, maintain billing entitlements and provider connection state, and record merchant-confirmed provider actions.
Evidence drafts and merchant-uploaded PDF, PNG, and JPEG documents support dispute preparation. Documents are stored privately and sent to Shopify only after merchant confirmation. Uploaded files are queued for deletion after confirmed submission; remaining evidence records are deleted no later than 30 days after case closure.
Service providers
Lower Chargeback uses Cloudflare for Worker execution and storage. Brevo sends transactional account, invoice, and operational merchant notifications. For the Shopify App, Lower Chargeback also uses Shopify for operational commerce data and embedded application services, together with only the merchant providers explicitly connected and verified through Provider Hub.
These providers may process information in countries outside the merchant’s country. Where a cross-border transfer requires safeguards, Lower Chargeback relies on the contractual and transfer mechanisms made available by the applicable provider and required by data-protection law.
Retention and deletion
Direct-account data is retained while needed to provide that account and meet its audit obligations. For the Shopify App, operational order, transaction, risk, dispute, and operational aggregate records are retained for no more than 180 days after their last relevant activity. Active provider cases and their source records remain available while action is required; terminal provider cases and their source identifiers, actions, and events are deleted 30 days after closure. Shopify App audit records, observed Shopify users, notification deliveries, and terminal provider-webhook metadata are retained for no more than 180 days.
Provider webhook payload objects and Shopify App webhook receipts are retained for no more than 30 days.
Installation configuration, encrypted credentials, verified recipients, the aggregate billing entitlement, and the minimum records required to honor data-deletion requirements remain only while the App is installed or the enabled service requires them. Uninstalling revokes active Shopify credentials and starts deletion of the installation’s Shopify data. Shopify compliance webhooks take priority and initiate customer or shop data deletion. Subprocessor backup lifecycles remain governed by the applicable provider’s service terms.
Security and access
Production secrets are held in Cloudflare secret configuration. Stored provider credentials and Shopify authorization tokens use authenticated encryption. Administrative access is restricted, operational changes are audited without customer identity values, production data is not copied into demo or test datasets, and security incidents are investigated and contained through the documented response procedure.
Contact
Merchants and data subjects may request access, correction, deletion, restriction, or a copy of information associated with them, or object to eligible processing, by emailing marian@agilemedia.com. The request should identify the relevant shop and relationship to the data so Lower Chargeback can verify authority before responding. Shopify privacy requests may also be initiated through the merchant, which delivers the required Shopify compliance webhook.
Correspondence address: Intrarea Gheorghe Simionescu 19, Apartment B26, Bucharest 031779, Romania.