English
Last updated: August 28, 2026
Scam Shield is a Shopify app that helps merchants identify at-risk orders by detecting repeated use of the same customer details (name, address, city) across different orders, in order to expose fraud attempts such as chargeback fraudsters operating against multiple stores. This document explains what data the app reads, why, and how it is stored.
What data we process
When a Shopify store installs Scam Shield, the app subscribes to the order-creation webhook (orders/create) and processes, for every new order: the customer's name, the shipping or billing address (street, city, postal code, country), and the order and store identifiers. The app does not read payment details, credit card numbers, or passwords - these are never accessible to it through Shopify.
How we use the data
The data is normalized (including full support for Hebrew addresses) and converted into a hash for comparison across orders. The system checks whether the same identity details were used in past orders, and calculates a risk score (low, medium, or high). The risk score is written back to the order in the Shopify admin, so the merchant can decide how to proceed. The data is never sold, rented, or shared with third parties for marketing purposes.
Data retention
Normalized order data is stored in a secure database (Cloudflare D1) for the purpose of future order comparison, and is retained only for as long as needed for that purpose. A merchant may request data deletion at any time by contacting the support address below.
Compliance with Shopify's Protected Customer Data requirements
The app implements Shopify's mandatory Protected Customer Data webhooks, including customer data requests (customers/data_request), customer data erasure (customers/redact), and shop data erasure on app uninstall (shop/redact).
Merchant and customer rights
You may contact us at any time to request to view, correct, or delete data stored by the app, in accordance with applicable privacy laws (including GDPR, where applicable).
Contact
For questions about this privacy policy, please contact us at: liran.brook@gmail.com
————————
עברית
עודכן לאחרונה: 28 באוגוסט 2026
Scam Shield היא אפליקציית שופיפיי שמסייעת לסוחרים לזהות הזמנות בסיכון על ידי איתור שימוש חוזר באותם פרטי לקוח (שם, כתובת, עיר) בין הזמנות שונות, כדי לחשוף ניסיונות הונאה כגון מכחישי עסקה הפועלים מול כמה חנויות. מסמך זה מסביר אילו נתונים האפליקציה קוראת, לשם מה, וכיצד הם נשמרים.
אילו נתונים אנחנו מעבדים
כאשר חנות שופיפיי מתקינה את Scam Shield, האפליקציה נרשמת ל-webhook של יצירת הזמנה (orders/create) ומעבדת עבור כל הזמנה חדשה: שם הלקוח, כתובת המשלוח או החיוב (רחוב, עיר, מיקוד, מדינה), ומזהה ההזמנה והחנות. האפליקציה אינה קוראת פרטי תשלום, מספרי כרטיס אשראי או סיסמאות - אלה אינם נגישים לה כלל דרך שופיפיי.
כיצד אנחנו משתמשים בנתונים
הנתונים מנורמלים (כולל תמיכה מלאה בכתובות בעברית) ומומרים לטביעת אצבע (hash) לצורך השוואה בין הזמנות. המערכת בודקת האם אותם פרטי זהות שימשו בעבר בהזמנות אחרות, ומחשבת דירוג סיכון (נמוך, בינוני או גבוה). דירוג הסיכון נכתב חזרה להזמנה בממשק הניהול של שופיפיי, כדי שהסוחר יחליט כיצד לפעול. הנתונים אינם נמכרים, מושכרים או משותפים עם צדדים שלישיים למטרות שיווק.
שמירת נתונים
נתוני ההזמנות המנורמלים נשמרים במסד נתונים מאובטח (Cloudflare D1) לצורך השוואה עתידית בין הזמנות, ונשמרים למשך הזמן הנדרש לצורך תכלית זו בלבד. סוחר יכול לבקש מחיקת נתונים בכל עת בפנייה לכתובת התמיכה המפורטת למטה.
עמידה בדרישות שופיפיי להגנת מידע לקוחות
האפליקציה מיישמת את ה-webhooks המחייבים של שופיפיי להגנת מידע לקוחות (Protected Customer Data), לרבות בקשת מידע לקוח (customers/data_request), מחיקת מידע לקוח (customers/redact), ומחיקת מידע חנות עם הסרת האפליקציה (shop/redact).
זכויות הסוחר והלקוח
ניתן לפנות בכל עת בבקשה לעיין, לתקן או למחוק נתונים שנשמרו על ידי האפליקציה, בהתאם לחוקי הגנת הפרטיות הרלוונטיים (לרבות GDPR ככל שהוא חל).
יצירת קשר
לשאלות בנוגע למדיניות פרטיות זו, ניתן לפנות אלינו בכתובת: liran.brook@gmail.com