Privacy Policy & Data Processing Notice
Operated by Runivox Ltd (United Kingdom) · Last updated 19 September 2026 · Version 1.4
1. Legal entity and roles
ProofBack is owned and operated by Runivox Ltd (“Company”, “we”, “our”), a private limited company registered in England and Wales, company number 15894120.
For the purposes of the UK Data Protection Act 2018, the UK GDPR and, where applicable, Regulation (EU) 2016/679:
- The merchant is the data controller. You own the customer relationship and decide what personal data is collected through your Shopify store.
- Runivox Ltd is the data processor. We process personal data solely on your documented instructions, to defend payment disputes and compile evidence dossiers on your behalf.
2. Categories of personal data processed
To meet the evidentiary requirements set by the payment networks, ProofBack accesses only the data necessary for representment:
| Category | Elements | Purpose |
|---|---|---|
| Transaction | Order ID, line items, currency, price, timestamp | Itemised invoice exhibit |
| Cardholder identity | Name, email address, phone number, billing address | Establishing buyer identity and checkout intent |
| Security identifiers | IP address, device fingerprint, AVS and CVV result codes | Visa CE 3.0 data matching for reason code 10.4 |
| Fulfilment | Carrier name, tracking number, dispatch and delivery timestamps recorded by Shopify | Proof of delivery exhibit |
We do not collect or store payment card numbers. Card data remains with Shopify Payments and the acquiring processor; ProofBack only ever sees the card brand and the last four digits.
3. Use of AI and model training
ProofBack can use the Anthropic Claude API to draft dispute rebuttal letters. Under Anthropic’s commercial terms, data sent through the API is not used to train its models. Prompts are transmitted over encrypted connections and are not retained by ProofBack after the letter has been generated.
Where no AI provider is configured, letters are produced entirely by a local deterministic template and no data leaves our infrastructure.
4. Shopify mandatory privacy webhooks
In line with the Shopify Partner Programme, ProofBack exposes the three required endpoints:
-
customers/data_request— responds to a customer’s request for their stored data. -
customers/redact— erases the personal data held for a specific customer. -
shop/redact— erases all shop data, received 48 hours after an app uninstall.
5. Sub-processors and international transfers
We engage a small number of sub-processors to operate the service. Where personal data is transferred outside the UK or EEA, transfers are covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
- Shopify Inc. — source of order, fulfilment and dispute data (Canada / EU).
- Anthropic PBC — rebuttal letter drafting, when configured (United States).
- Hosting provider — application hosting and encrypted storage.
6. Retention
Dispute records and evidence packets are retained while your subscription is active and for up to 24 months afterwards, reflecting the window in which payment networks may reopen a case. You may request earlier deletion at any time; we will comply unless retention is required by law.
7. Your rights and how to contact us
Data subjects have the right to access, rectification, erasure, restriction, portability and objection. Because we act as a processor, requests from your customers should be directed to you as the controller; we will assist you in responding.
Contact us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.