DisputePack is a Shopify app operated by Ollfy. We read only the Shopify data needed to build chargeback evidence, we never touch your payouts, and we never sell merchant or customer data.
1. Who this policy is for
DisputePack is a tool for merchants (Shopify store owners) to respond to payment disputes (chargebacks). We process store and customer data on behalf of the merchant, who is the data controller. We act as a data processor.
2. Data we access and store
When you install DisputePack, and only to build dispute evidence, we access the following via the Shopify Admin API and store it:
| Category | What it includes |
|---|---|
| Store information | Store name, domain, contact email, timezone, plan. |
| Order data (disputed orders) | Order number, amount, currency, line items, fulfilment and tracking, delivery status, and payment verification results (AVS/CVV, card brand and last four digits — never the full card number). |
| Customer data (disputed orders) | Customer email, name, billing and shipping address, phone (where present), and order-history counts. |
| Dispute data | The Shopify Payments dispute record — reason, network, deadline, status. |
| Merchant-provided | Files you upload as evidence, your internal notes, and app settings. |
We do not access or modify your payouts or bank details, we never see full card numbers, and we never write to your store. Our access is read-only.
3. How we use data
- To gather and organise evidence for a chargeback and generate a downloadable PDF pack.
- To draft a suggested rebuttal letter (see subprocessors).
- To send you deadline reminders and dispute notifications by email.
- To show you analytics — win rates, dispute ratio, repeat customers — for your own store only.
We do not sell your data or your customers' data, we do not use it for advertising, and we do not use it to train our own models.
4. Subprocessors
We share the minimum data necessary with:
| Subprocessor | Purpose |
|---|---|
| Shopify | The source of the data and the platform the app runs on. |
| Hostinger | Application hosting, database and file storage. |
| Mailtrap | Delivery of notification and digest emails. |
| OpenAI | Drafting rebuttal letters. |
Customer email is redacted before the context is sent, and no customer name or address is included — OpenAI receives only order and evidence facts. Data sent to the OpenAI API is not used to train OpenAI's models.
5. Data retention and deletion
- Generated PDF evidence packs are automatically deleted after 90 days.
- On a customer data-erasure request (Shopify's
customers/redactwebhook, sent 48 hours after a request), we erase that customer's stored personal data — database records and any stored files. - On app uninstall or store erasure (Shopify's
shop/redactwebhook), we erase all data we hold for the store, including stored files. - Merchants can request deletion at any time by contacting us at the address below.
6. Security
- All data is transmitted over TLS/HTTPS.
- OAuth access and refresh tokens are encrypted at rest. Databases and file storage use encryption at rest.
- Access to production data is restricted to authorised personnel and logged.
- Each store's data is isolated from every other store's.
7. Your rights
Depending on your location (e.g. GDPR/UK-GDPR, CCPA/CPRA), you and your customers may have rights to access, correct or delete personal data, and to object to or restrict its processing.
Because we act on behalf of merchants, customer requests are usually made to the merchant, who can action them through Shopify — which triggers our erasure webhooks — or by contacting us directly.
8. International transfers
DisputePack's servers and database are located in the United Kingdom. If you or your customers are outside the United Kingdom, using the app means data is transferred there. Our subprocessors may process data elsewhere; where required, we rely on appropriate safeguards (e.g. UK International Data Transfer Agreement or Standard Contractual Clauses) for those transfers.
9. Changes
We may update this policy. Material changes will be posted here with a new "Last updated" date.
10. Contact
- Privacy & support: contact@ollfy.com
- Company: Ollfy — a fully remote software studio, operating from the United Kingdom.
- Company-wide policy: Ollfy privacy policy, which covers all of our apps.
For anything relating to your data or this policy, email contact@ollfy.com and a person will reply.