我们处理的信息
当您以商店、合作伙伴或投资者身份申请时,我们会使用您的联系方式和提供的业务信息来审核申请并回复。申请通过 Brevo 发送给我们的团队,不会创建账户。
对于直销商户账户,我们会处理账户持有人姓名和email地址、企业或商店名称、店面URL、所选电子商务平台、销售货币、每月总销售额、平均销售额、当前卡支付争议率、发票记录、业务设置和店面活跃度测试记录。销售和卡支付争议数据是商户提供的店铺层面的汇总数据,而不是单个客户的交易记录。
For the Shopify App, we process Shopify installation identifiers, store configuration, operational order references, timestamps, amounts, currencies, payment and transaction identifiers, risk assessments, merchant decisions, dispute status, reasons, amounts, currencies and deadlines, provider alerts and connection configuration, audit records, billing status, and verified merchant notification recipients.
证据访问需要 Shopify 权限以及受保护客户数据的批准。启用后,将从 Shopify 读取客户姓名、电子邮箱、账单地址和收货地址,用于争议审查和经商家确认的证据提交。不请求客户电话号码或 IP 地址。Lower Chargeback 不联系客户或收集回复。
店主可以在 Lower Chargeback 内保存加密的企业资料和争议信息。Shopify 的值优先,保存手动输入的信息绝不会更改 Shopify 记录。
通知收件人
Entered and verified by the merchant; never imported from Shopify customer records.
支付和决策边界
Direct account invoice records contain the invoice amount and status, but Lower Chargeback does not store card numbers. Provider credentials are encrypted before storage and are never returned after they are saved. The Shopify App does not create Shopify refunds, automatically accept or decline network cases, automatically report provider outcomes, send customer messages, or submit dispute evidence without explicit merchant confirmation.
如何使用信息
Direct account information is used to create and secure the merchant account, issue and display the registration invoice, send account and invoice messages, maintain business settings, run storefront liveness tests, and record their results. Shopify App information is used to synchronize operational order data, present risk signals, record merchant decisions, monitor disputes, match provider alerts to eligible order references, notify verified merchant recipients, maintain billing entitlements and provider connection state, and record merchant-confirmed provider actions.
证据草稿以及商家上传的 PDF、PNG 和 JPEG 文档用于准备争议材料。文档以私密方式存储,仅在商家确认后发送给 Shopify。确认提交后,上传的文件将进入删除队列;其余证据记录最迟在案件结案后 30 天内删除。
服务提供商
Lower Chargeback uses Cloudflare for Worker execution and storage. Brevo sends transactional account, invoice, and operational merchant notifications. For the Shopify App, Lower Chargeback also uses Shopify for operational commerce data and embedded application services, together with only the merchant providers explicitly connected and verified through Provider Hub.
These providers may process information in countries outside the merchant’s country. Where a cross-border transfer requires safeguards, Lower Chargeback relies on the contractual and transfer mechanisms made available by the applicable provider and required by data-protection law.
保留和删除
Direct-account data is retained while needed to provide that account and meet its audit obligations. For the Shopify App, operational order, transaction, risk, dispute, and operational aggregate records are retained for no more than 180 days after their last relevant activity. Active provider cases and their source records remain available while action is required; terminal provider cases and their source identifiers, actions, and events are deleted 30 days after closure. Shopify App audit records, observed Shopify users, notification deliveries, and terminal provider-webhook metadata are retained for no more than 180 days.
提供商 Webhook payload 对象和 Shopify App Webhook 接收记录保留不超过 30 天。
安装配置、加密凭据、已验证的收件人、汇总计费权益以及遵守数据删除要求所需的最少记录,仅在应用已安装或启用的服务需要时保留。卸载会撤销有效的 Shopify 凭据,并开始删除该安装的 Shopify 数据。Shopify 合规性 Webhook 具有优先级,并会启动客户或商店数据删除。子处理者备份生命周期仍受适用提供商服务条款的约束。
安全和访问
Production secrets are held in Cloudflare secret configuration. Stored provider credentials and Shopify authorization tokens use authenticated encryption. Administrative access is restricted, operational changes are audited without customer identity values, production data is not copied into demo or test datasets, and security incidents are investigated and contained through the documented response procedure.
联系方式
商家和数据主体可以通过 emailing 请求访问、更正、删除、限制或与其相关的信息副本,或反对符合资格的处理 marian@agilemedia.com. The request should identify the relevant shop and relationship to the data so Lower Chargeback can verify authority before responding. Shopify privacy requests may also be initiated through the merchant, which delivers the required Shopify compliance webhook.
通讯地址:Intrarea Gheorghe Simionescu 19,公寓 B26,布加勒斯特 031779,罗马尼亚。