Privacy Policy

Last updated: 2026-08-05

Introduction

Do The Proof (“we,” “our,” or “us”) operates a chargeback dispute management service for Shopify merchants. We help merchants assemble evidence from their Shopify and Stripe accounts, generate draft rebuttal letters, and submit dispute responses to their payment processor. This Privacy Policy explains how we collect, use, share, and protect data in connection with that service.

If you are a merchant using Do The Proof, you are the data controller for your customers’ personal data. Our processing of that data on your behalf is governed by a binding Data Processing Agreement, incorporated into our Terms of Service. This policy describes our practices; the DPA is the contract that governs them. For your own account data (your store details, email address, and billing plan), we are the controller and this policy is our notice to you.

Definitions

Controller:
The entity that determines the purposes and means of processing personal data. Merchants are controllers of their customers’ data. We are the controller of merchant account data.
Processor:
An entity that processes data on behalf of a controller. Do The Proof acts as a processor when handling your customers’ data on your instruction.
Personal Data:
Any information that identifies or can identify a natural person, including names, email addresses, postal addresses, and IP addresses.
Sub-processor:
A third-party service we use to process data on your behalf. See the Sub-processors section for the full list.

Data Collected

Merchant account data

  • Shopify store domain, store name, and numeric store identifier
  • Shopify OAuth access credentials, including refresh tokens where issued (encrypted at rest)
  • Stripe Connect account identifier (we do not receive or store Stripe secret keys or card numbers)
  • Merchant email address (sourced from the Shopify store owner profile) and notification preferences
  • Store settings: currency, timezone, policy URL
  • Billing plan details: the plan you approved on Shopify’s plan selection page, its activation date, and the amounts we report to Shopify for fee calculation

Customer personal data (dispute processing)

When a chargeback dispute is filed on a transaction processed through your store, we retrieve the following from your Shopify and Stripe accounts to assemble evidence:

  • Customer name and email address
  • Billing and shipping addresses
  • Order details: items purchased, amount, date, fulfilment status
  • Tracking numbers and carrier information
  • Prior order history for the same customer
  • Checkout IP address (from Shopify)
  • Refund records (from Stripe)

This data is sourced from your accounts; we do not collect it independently from your customers. Under Shopify’s protected customer data requirements this is Level 2 protected customer data; we process the minimum needed for each dispute, use it only for the purposes stated in this policy, and apply the retention limits described below.

Analytics and error tracking data

  • Page views and in-app navigation events (PostHog; the identifier is your store ID, not your email address)
  • JavaScript errors and server exceptions (Sentry, with PII patterns automatically redacted before transmission)
  • No session recordings, no keystroke logging, no autocapture

Purposes of Processing

  • Dispute evidence assembly: To retrieve order and customer data from your Shopify and Stripe accounts for the purpose of assembling chargeback evidence on your behalf.
  • AI rebuttal generation: To send assembled evidence to Anthropic’s API for generation of a draft rebuttal letter, which is presented to you for review before any submission. Where the evidence cannot support a rebuttal, the service does not generate one and does not fabricate supporting content.
  • Dispute submission: When you choose to submit, we transmit the assembled evidence and your approved rebuttal to Stripe, which forwards it to the card issuer that is deciding the dispute. Submission discloses the customer data listed above to those parties.
  • Billing: To report the dollar amount recovered on disputes we handled for you to Shopify, which calculates and charges our fee on your Shopify invoice. The report contains your store identifier and the recovered amount; it contains no customer personal data.
  • Service operation: To authenticate your account, manage webhooks, send you dispute notifications by email, and operate the application.
  • Error monitoring: To detect and fix bugs that affect service reliability.
  • Product analytics: To understand which features merchants use, measured at store level without individual tracking.

Labelling of AI-generated content

Each rebuttal draft we generate is labeled as AI-generated in your dashboard. The label remains visible until you make your first edit to the draft, and reappears if you regenerate. You may edit, replace, or regenerate any AI-drafted content at any time before submission. Submission is a separate, explicit step taken by you.

The legal basis depends on the role in which we process the data. For your customers’ data, the lawful basis is determined by you as controller; a processor does not have its own Article 6 basis for its controller’s processing.

  • Merchant account data (we are the controller). Contract performance (Art. 6(1)(b)): processing your account data, operating the service, and billing through Shopify are necessary to perform our contract with you. Analytics rest on our legitimate interest (Art. 6(1)(f)) in product improvement, with privacy controls (no autocapture, no email as identifier, PII scrubbing) that minimise the footprint; you may opt out by contacting us.
  • Your customers’ data (you are the controller; we are your processor). We process this data on your documented instructions under the DPA, and you determine the lawful basis. In our understanding, merchants typically rely on legitimate interest (Art. 6(1)(f)) in the establishment, exercise, and defence of legal claims arising from disputed transactions: the data was collected from your customers in the course of their purchase, and processing is limited to what each dispute requires. This description is provided to assist you in documenting your basis; it is not a basis asserted by us.

Retention

  • Active merchant accounts: Retained for as long as the app is installed, plus a 30-day grace period after uninstallation, then permanently deleted by an automated daily job. If Shopify sends us its shop/redact compliance webhook, deletion occurs immediately at that point instead, including any dispute records that are still open. The precedence between that store-level instruction and the customer-level erasure deferral is stated in the Erasure section below.
  • Dispute records: Retained for 90 days after a dispute reaches a closed state (won, lost, expired, withdrawn, not contested, or a closed inquiry), then permanently deleted, including the evidence, the drafted rebuttal, and cached order data. A dispute you declined to contest is treated as closed once its response deadline has passed, even if the processor’s closing notification does not arrive.
  • Customer erasure requests: Recorded immediately on receipt (the timing of the erasure itself is described in the Erasure section below).
  • Database backups: Our database provider takes an encrypted backup daily and retains backups on a seven-day rolling basis; purged data ages out of backups within seven days.
  • Deletion records: When we delete your store's data, we keep one record that the deletion happened: your store's domain, when it was requested, when it finished and what triggered it (an uninstall, a redaction request from Shopify, or the dispute retention schedule). It holds no customer data and no dispute content. We keep it for 730 days so we can show a deletion was carried out, then it is deleted.
  • Error events (Sentry): 30 days.
  • Analytics events (PostHog): Set by the retention configuration on our analytics project; events are retained while they remain necessary for analysis of product usage, and we review that configuration against that need at least annually.

Erasure

Erasure requests reach us through Shopify’s customers/redact compliance webhook or by direct request to us. We record each request on receipt and replace the customer’s identifying evidence fields with [REDACTED] sentinel values. Those fields are the customer name, email address, billing and shipping addresses, IP address, signature references, and order history. Original values are not recoverable from our systems once replaced. Files you uploaded to the disputes covered by a request are deleted outright rather than redacted. The only thing that outlives a deletion is the deletion record described under Retention.

Erasure is deferred where the request relates to a chargeback that remains open, meaning a dispute still being defended or awaiting the issuer’s decision. In those circumstances the data covered by the request constitutes the evidence on which the defence of the claim depends. Article 17(3)(e) of the GDPR provides that the right to erasure does not apply to the extent that processing is necessary for the establishment, exercise or defence of legal claims. Where erasure is deferred, the request remains on record and an automated daily process completes the erasure once the dispute closes.

Drafted rebuttal text may identify the customer. It is retained on the same basis while the claim remains live and is deleted with the dispute record no later than 90 days after the dispute closes.

Deferral does not extend indefinitely. Where we are not contesting a dispute, deferral ends at that dispute’s response deadline.

Precedence of deletion instructions. The deferral above applies to customer-level erasure: an individual customer’s customers/redact request and the scheduled retention deletions. A store-level deletion instruction (Shopify’s shop/redact webhook, sent after you uninstall) is an instruction from you, the controller, to delete your own records. On receipt of that instruction we delete all records immediately, including disputes that are still open. Article 17(3)(e) permits, but does not require, retention of evidence while a claim is live, and your deletion instruction prevails. A merchant that wants an open dispute defended should not uninstall until the dispute closes.

Evidence submitted to Stripe or a card issuer before an erasure request is received is held in those parties’ systems, is subject to their retention rules, and cannot be recalled by us.

Sub-processors

We use the following third-party services to operate Do The Proof. Each receives only the data necessary for its specific function.

ServicePurposeData category
AnthropicAI rebuttal generationDispute evidence (contains customer PII). Not used to train models under Anthropic’s commercial terms; retained transiently by Anthropic for abuse monitoring under those terms.
SupabaseDatabase hostingAll application data (credentials encrypted at the application layer; storage and backups encrypted by the provider)
VercelApplication hostingRequest logs (no raw bodies)
InngestBackground job processingDispute and store identifiers in job payloads (no customer PII)
StripeDispute data source and submission channelDispute data read from, and approved evidence submitted to, your connected Stripe account
ShopifyOrder data source, app platform, and billingOrder data read from your store; recovered-amount totals reported for fee billing
SentryError monitoringStack traces and diagnostics (PII patterns scrubbed before sending)
PostHogProduct analyticsStore-level events (no customer PII, no email)
ResendTransactional emailMerchant email address and dispute notification content (order reference, amounts)

Changes to this list: when we add or replace a sub-processor that processes your customers’ personal data, we update this list and email registered merchants at least 14 days before the change takes effect. You may object on reasonable data-protection grounds within that window; the objection mechanism and its remedy are in the DPA.

No AI training on your data. We do not use merchant or customer data, including derived or aggregated forms, to train, fine-tune, or improve any AI system, whether ours or a third party’s. Evidence is sent to the AI model for inference only, to produce the draft presented for your review. The Anthropic row above states Anthropic’s commitment; this paragraph states ours.

International Transfers

Our sub-processors are primarily located in the United States. If you are located in the European Economic Area or the United Kingdom, your data is transferred to the US under Standard Contractual Clauses (and, for the UK, the applicable UK Addendum or IDTA) or equivalent transfer mechanisms. Specific transfer mechanisms for each sub-processor are available on request at hello@dotheproof.com.

Security Measures

  • Encryption at rest: Shopify access and refresh tokens are encrypted with AES-256-GCM before database storage. The encryption key is stored separately from the database. Database storage and backups are additionally encrypted by our database provider.
  • Encryption in transit: All connections use TLS 1.2 or higher.
  • No payment credentials: We hold no card numbers, no bank details, and no Stripe secret keys. Payments to us are processed entirely by Shopify.
  • Scrubbing before telemetry: PII patterns (email addresses, tokens, identifiers) are redacted from error reports before transmission.
  • Access control: Merchant data is scoped to the authenticated store session; no cross-merchant access is possible through the application layer. Operator access to production data is limited to the service operator.
  • Environment separation: Production and staging run on separate databases, separate credentials, and separate payment-platform environments.

Breach Notification

If a personal data breach affects your account data or your customers’ personal data, we will notify you without undue delay after becoming aware of it, by email to your account address. The notification describes the nature of the breach, the data affected so far as then known, and the measures taken or proposed, and is supplemented as further information becomes available. For your customers’ data this is our processor obligation under Article 33(2), restated in the DPA. Whether and how to notify your customers or a supervisory authority is your decision as controller, and we will assist.

Your Rights

GDPR / UK GDPR rights (EEA and UK merchants and their customers)

  • Access: Request a copy of the data we hold. Customer access requests routed through Shopify’s customers/data_request webhook are logged on receipt. The export is compiled manually and delivered to you, the merchant, within 30 days, for you to provide to your customer. There is no automated export.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion. See the Erasure section above, including the legal-claims deferral that applies while a dispute remains open.
  • Restriction: Request that we pause processing while a disagreement about the data is resolved. Restriction is handled manually on request; there is no self-serve control.
  • Portability: Request your data in a machine-readable format.

Right to object

Where processing is based on legitimate interests (our analytics of merchant usage, or the legal-claims interest described in the Legal Basis section), you have the right to object at any time, on grounds relating to your particular situation. To object, email hello@dotheproof.com. On receipt of an objection we will cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

Complaints

Complaints about our handling of personal data may be submitted by anyone, electronically, by emailing hello@dotheproof.com with the subject line “Data protection complaint”. We acknowledge complaints within 30 days of receipt and inform you of the outcome of our review without undue delay thereafter.

You also have the right to lodge a complaint with a supervisory authority: in the EEA, the authority of your habitual residence, place of work, or the place of the alleged infringement; in the UK, the Information Commissioner’s Office (ICO, ico.org.uk/make-a-complaint). A complaint may be made to the authority whether or not a complaint has first been made to us.

California rights (CCPA/CPRA)

We do not currently meet the CCPA’s thresholds for a covered business (annual revenue, volume of California consumers’ data, or revenue from selling personal information). We extend the following to California residents voluntarily, on the same 30-day terms as above:

  • Know: Request disclosure of the personal information we collect and how it is used.
  • Correct: Request correction of inaccurate personal information.
  • Delete: Request deletion of your personal information.
  • Non-discrimination: Exercising any of these rights does not change the price or quality of the service.
  • No sale or sharing: We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not currently process opt-out preference signals such as Global Privacy Control.

To exercise any of these rights, email hello@dotheproof.com, or (for merchants) write from your dashboard account email so we can verify you without further steps. We respond within 30 days, or any shorter period applicable law requires.

Cookies

We use a session cookie to maintain your authenticated state (set by Auth.js, marked HttpOnly and Secure). PostHog uses a localStorage+cookie persistence strategy for analytics with no cross-site tracking. No advertising cookies or third-party tracking pixels are present. You can disable cookies in your browser settings; this will require you to log in again on each visit.

Children

This service is directed at businesses and is not intended for individuals under the age of 16. We do not knowingly collect personal data from minors.

Changes to This Policy

We will notify you of material changes to this policy by email at least 14 days before they take effect. This policy is a notice of our practices, not a contract; binding commitments are stated in the Terms and the DPA, each of which has its own amendment mechanism.

Contact

Questions about this policy or data requests: hello@dotheproof.com