Order Risk Guard ("the app", "we") is a Shopify app operated by Betatech. It scores your store's incoming orders for fraud risk so you can decide which ones to fulfill. This policy explains what data the app processes, why, and how it is protected.
Questions or requests? Contact us at [email protected].
1. Who controls the data
When you install the app, you (the merchant) remain the controller of your customers' personal data. We process order data on your behalf, only to provide the fraud-scoring service, and only according to this policy and Shopify's terms.
2. What data we process
When a new order is placed in your store, Shopify sends us an orders/create webhook. From it we process:
- Order identifiers — order ID and order name (e.g. #1042)
- Order totals — price and currency
- Customer contact signals, stored only as irreversible hashes: a hashed email address and a hashed phone number. We never store your customers' plaintext email addresses, names or postal addresses.
- The IP address the order was placed from, used for the geo-IP and velocity checks
- The scoring result — score (0–100), risk level, the reasons behind it, fulfillment-hold state and order status
We also store your shop's myshopify.com domain, your app settings (thresholds, country rules, block lists, digest email address) and your Shopify session tokens, which are needed to write scores and tags back to your orders.
3. Why we process it
- To score each order for fraud risk and show the result in your Shopify admin
- To tag orders and, if you enable it, place fulfillment holds
- To operate dashboards, insights and the optional daily digest email
- To enforce plan quotas and billing state through Shopify's billing API
4. Geo-IP lookups and AI processing
For the IP-versus-shipping-country check we use MaxMind's free GeoLite2 country database, which runs locally on our own server. IP addresses are never sent to MaxMind or to any other third party for this purpose.
On the Pro and Growth plans, orders that score 30 or higher also receive an AI second opinion: an automated fraud judgment from a large language model. For these requests we send a minimized, pseudonymous feature set — never your customer's name, street address, full email address or phone number:
- the domain of the customer's email (e.g. gmail.com), plus yes/no pattern flags about it
- whether a phone number exists at all (never the number itself)
- the shipping country, and whether billing and shipping country match
- whether the address contains a house number and whether it looks auto-generated
- the order total, whether it's the customer's first order, and how many orders share the same signals in the last hour
- Shopify's own risk level for the order
Providers are chosen by region: stores selling into the EU/EEA are routed to OpenAI (certified under the EU-US Data Privacy Framework); all other stores are routed to GLM via z.ai. The provider returns a risk score and a one-sentence explanation that we write onto the order. AI is optional and fail-open — if it's unavailable, scoring continues on the rule engine alone. For how the providers handle data on their side, see their respective privacy notices.
5. Where data is stored
All data is stored in an encrypted-in-transit MySQL database hosted on managed cloud infrastructure. Access is restricted to the app and to Betatech personnel who need it to operate and support the service.
6. Sharing and subprocessors
We do not sell your data or your customers' data. We share only what is necessary with:
- Shopify — the platform the app runs on; scores, tags and holds are written back to your orders through Shopify's APIs
- Our hosting provider — which operates the servers and database the app runs on
- AI providers — OpenAI (for stores selling into the EU/EEA) and z.ai (GLM, for everyone else), used for the optional AI second opinion; only the minimized, pseudonymous features described above are sent
- Email delivery — only if you enable the daily digest, to send the digest to the address you configure
- Google Analytics — this public marketing website (not the app itself) uses Google Analytics to measure aggregate traffic, such as page views and which pages are visited; Google may set cookies or similar identifiers on this website for that purpose. The app inside your Shopify admin sends nothing to Google Analytics.
7. Retention and deletion
- Scored-order records are kept while the app is installed so your dashboard, insights and the refuser-memory rule keep working.
- When Shopify sends us the mandatory shop/redact webhook — for example after you uninstall the app — we permanently delete all scores, settings and session data for your shop.
- When Shopify sends customers/redact for one of your customers, we erase the hashed identifiers and IP address from that customer's order records, keeping only the anonymous score metadata.
8. Customer data requests (GDPR & CCPA)
The app implements all of Shopify's mandatory compliance webhooks: customers/data_request, customers/redact and shop/redact. If one of your customers asks what data is held about them, we can provide the list of their scored orders through support — because emails are stored hashed, the request goes through you as the merchant, and we respond to Shopify's webhooks within Shopify's required timeframes.
9. Security
Data is transmitted over TLS, session tokens are stored server-side and never exposed to the browser, and access to the database is limited to the app itself. Customer emails and phone numbers are stored only as SHA-256 hashes, which cannot be reversed to recover the original values.
10. Changes to this policy
If we change this policy materially, we'll update this page and note the date above. Continued use of the app after a change means you accept the updated policy.
11. Contact
Betatech · [email protected]