Backstop: Chargeback Watch
Privacy Policy
Last updated August 24, 2026
What Backstop does
Backstop watches a Shopify store for payment disputes and assembles evidence documents from the store's own order data. It is installed by merchants; the personal data it touches belongs to the merchant's customers, and Backstop processes it only on the merchant's behalf.
What we process, and why
- Dispute records: amount, reason code, deadline, status, and the associated order number. This is the product: a queue of disputes with deadlines.
- Order data for evidence: order details, line items, fulfillment and tracking records, and the customer's name, email, and billing/shipping addresses. These appear in the evidence document the merchant reviews and submits to their payment processor. We deliberately do not request customer phone numbers; the evidence does not need them.
- Store settings: the refund policy text and feature preferences the merchant saves in the app.
That is the whole list. No analytics profiles, no tracking pixels, no advertising identifiers, no data enrichment.
What we never do
- We never sell personal data, to anyone, for anything.
- We never use customer data for marketing.
- We never submit anything to a bank or processor ourselves. The merchant reviews the exact document and submits it in Shopify.
Where data lives
Data is stored in the United States: application hosting on Amazon Web Services and a PostgreSQL database on Neon. Data is encrypted in transit (TLS) and at rest, including backups. Access is limited to the app itself and its developer.
Retention and deletion
- Uninstalling Backstop ends billing and triggers deletion of the store's data through Shopify's mandatory redaction process.
- Customer redaction requests forwarded by Shopify (GDPR/CCPA) are honored automatically: the customer's identifying data is removed from our records.
- While the app is installed, dispute and evidence records are kept so the merchant has their dispute history. That history is the service.
Subprocessors
Amazon Web Services (hosting, email) and Neon (database). Both are bound by their own security and privacy commitments; neither receives data for any purpose other than running Backstop.
Your rights
Merchants can export or delete their data at any time by contacting us, or delete everything by uninstalling. End customers should direct requests to the merchant they bought from. Shopify routes those requests to us automatically and we honor them.
Contact
support@heybackstop.com A person reads this inbox.