Skip to main content
UK GDPR & EU GDPR Shopify mandatory privacy webhooks

Privacy Policy & Data Processing Notice

Operated by Runivox Ltd (United Kingdom) · Last updated 19 September 2026 · Version 1.4

Commitment. ProofBack is a chargeback dispute defence tool. We do not sell, rent or otherwise monetise your data or your customers’ data. Personal data is accessed strictly to verify purchase authorisation, review fulfilment records and assemble evidence packets under payment network dispute rules.

1. Legal entity and roles

ProofBack is owned and operated by Runivox Ltd (“Company”, “we”, “our”), a private limited company registered in England and Wales, company number 15894120.

For the purposes of the UK Data Protection Act 2018, the UK GDPR and, where applicable, Regulation (EU) 2016/679:

  • The merchant is the data controller. You own the customer relationship and decide what personal data is collected through your Shopify store.
  • Runivox Ltd is the data processor. We process personal data solely on your documented instructions, to defend payment disputes and compile evidence dossiers on your behalf.

2. Categories of personal data processed

To meet the evidentiary requirements set by the payment networks, ProofBack accesses only the data necessary for representment:

Category Elements Purpose
Transaction Order ID, line items, currency, price, timestamp Itemised invoice exhibit
Cardholder identity Name, email address, phone number, billing address Establishing buyer identity and checkout intent
Security identifiers IP address, device fingerprint, AVS and CVV result codes Visa CE 3.0 data matching for reason code 10.4
Fulfilment Carrier name, tracking number, dispatch and delivery timestamps recorded by Shopify Proof of delivery exhibit

We do not collect or store payment card numbers. Card data remains with Shopify Payments and the acquiring processor; ProofBack only ever sees the card brand and the last four digits.

3. Use of AI and model training

ProofBack can use the Anthropic Claude API to draft dispute rebuttal letters. Under Anthropic’s commercial terms, data sent through the API is not used to train its models. Prompts are transmitted over encrypted connections and are not retained by ProofBack after the letter has been generated.

Where no AI provider is configured, letters are produced entirely by a local deterministic template and no data leaves our infrastructure.

4. Shopify mandatory privacy webhooks

In line with the Shopify Partner Programme, ProofBack exposes the three required endpoints:

  • customers/data_request — responds to a customer’s request for their stored data.
  • customers/redact — erases the personal data held for a specific customer.
  • shop/redact — erases all shop data, received 48 hours after an app uninstall.

5. Sub-processors and international transfers

We engage a small number of sub-processors to operate the service. Where personal data is transferred outside the UK or EEA, transfers are covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

  • Shopify Inc. — source of order, fulfilment and dispute data (Canada / EU).
  • Anthropic PBC — rebuttal letter drafting, when configured (United States).
  • Hosting provider — application hosting and encrypted storage.

6. Retention

Dispute records and evidence packets are retained while your subscription is active and for up to 24 months afterwards, reflecting the window in which payment networks may reopen a case. You may request earlier deletion at any time; we will comply unless retention is required by law.

7. Your rights and how to contact us

Data subjects have the right to access, rectification, erasure, restriction, portability and objection. Because we act as a processor, requests from your customers should be directed to you as the controller; we will assist you in responding.

Contact us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.