Legal

Privacy Policy

Last updated: June 2025

Damage Control ("we", "our", "us") is committed to protecting the privacy of Shopify merchants and their customers. This privacy policy explains what data we collect, how we use it, how we store it, and your rights regarding your information. By installing and using the Damage Control app, you agree to the practices described in this policy.

What Data We Collect

We collect the minimum data necessary to provide our fraud detection, bot blocking, dispute management, and risk monitoring services. The data falls into three categories:

Shopify Store Data

Through Shopify OAuth, we access store orders, disputes, products, and customer details necessary for fraud analysis and dispute management. This data is accessed via Shopify's official API and is subject to Shopify's own data handling policies.

Visitor Events

Our tracker script collects IP addresses, browser fingerprints (canvas, WebGL, hardware signals), user agent strings, and page view events. This data is used exclusively for bot detection, fraud scoring, and generating proof tokens. We do not track individual browsing behavior beyond what is necessary for security analysis.

Merchant Configuration

Settings you configure within the app, including sensitivity levels, block lists, killswitch preferences, and notification settings. This data is stored to maintain your app configuration across sessions.

How We Use Your Data

All data collected by Damage Control is used exclusively to provide and improve our core services:

  • Fraud detection and bot scoring to identify and block malicious visitors
  • Real-time risk analysis to assess order legitimacy and trigger automated actions
  • Dispute management to track, translate, and help you respond to chargebacks
  • Order guard automation with optional Auto-Cancel to cancel fraudulent orders, plus attacker blocking and real-time alerts (alerts fire whether or not Auto-Cancel is enabled)
  • Risk monitoring to calculate your exposure to Visa VAMP and Mastercard ECM programs
  • Generating proof tokens for checkout validation (visitor events only)

We never use your data for advertising, marketing, or any purpose unrelated to the app's core functionality. We never sell, rent, or trade your data to third parties for their own use.

Data Storage and Security

All data is stored in MongoDB hosted on Railway, a modern cloud infrastructure provider. Data is encrypted at rest using industry-standard encryption. Access to production data is restricted to authorized personnel through role-based access controls. We maintain audit logs of all data access and regularly review security practices. Our infrastructure runs on Railway with auto-scaling, ensuring consistent performance and reliability without manual intervention.

Data Sharing

We never sell your data. We share data only in the following limited circumstances: with Shopify as required by the platform (to operate the app within their ecosystem and comply with their terms of service), and with our infrastructure provider Railway (who processes and stores data on our behalf under strict data processing agreements). We do not share data with any other third parties, advertising networks, or data brokers.

Data Retention

Visitor events (IP addresses, fingerprints, page views) are retained for 90 days and then automatically deleted. Merchant configuration and order analysis data is retained for the duration of your app subscription. Upon app uninstallation, all of your data is automatically and permanently deleted from our systems within 7 days. This includes store data, visitor events, configuration settings, block lists, and dispute records.

GDPR Compliance

We are fully committed to GDPR compliance. Full data deletion is performed automatically on app uninstall, ensuring your right to erasure. Customer data access requests are handled through Shopify, as they are the data controller for customer information. As a Shopify app, we process data under Shopify's data processing terms, which are GDPR-compliant. If you are a merchant located in the European Economic Area, you have the right to access, rectify, or delete your data at any time by contacting us at the email address below.

Contact Us About Privacy

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us at: