None. Chargebackify holds no SOC 2 report, no ISO certification and no independent penetration test, and it would be easy to imply otherwise on a page like this. What we can tell you instead is exactly what the app can reach: your Shopify Payments disputes, the orders behind them, and the ability to refund those orders. It holds no credentials of yours, sits outside your payment flow, and every refund it issues is recorded in your own Shopify admin where you can audit it without asking us for anything.
Traffic runs over TLS, and the database is encrypted at rest by the hosting provider. The app is small and so is the team: treat production access as available to the people who operate it, rather than assuming a separation of duties we are not yet large enough to have.
We never store full card numbers. Networks provide a truncated fingerprint, which is what matching uses. Refunds are executed through your processor's API using credentials you grant and can revoke.
99.95% uptime target on the alert pipeline, measured monthly and published on the status page. Alerts that arrive during an incident are queued and processed on recovery, and any missed inside the window are not billed.
On-call rotation with a 15-minute acknowledgement target. Customer-affecting incidents are posted to the status page as they are investigated, not after they are resolved.
Chargeback prevention infrastructure, starting with Shopify. Alerts, refunds and ratio monitoring in one place.
Network rule changes, threshold updates and merchant teardowns. Once a month.
No spam. Unsubscribe anytime.