Scam Shield — Privacy Policy
Last updated: September 28, 2026
1. Who we are
Scam Shield is a Shopify app operated by Liran Brook, Osek Murshe (licensed dealer) no. 231451511, 8 Shaul HaMelech St., Kiryat Ono, Israel ("we", "us"). For data we receive from merchants' stores, we act on the merchant's behalf (as a processor), and we are the controller of the shared fraud-prevention network described below.
Contact: liran.brook@gmail.com
2. What Scam Shield does
Scam Shield helps Shopify merchants spot orders that may lead to chargebacks or transaction-denial fraud. When a store that uses the app receives an order, Scam Shield checks whether the same or similar customer details were recently used at other stores that also use Scam Shield (the "Network"). It then adds a risk level (low, medium or high), with the reasons, to that order in the merchant's Shopify admin.
3. Data we process
From each order at a participating store:
customer name (full, first and last);
shipping and billing address: street, city, region, postal code and country;
email address and phone number;
order ID, order number, store domain, order total and currency, and order time.
From each merchant: the store domain, an access token for the store, and subscription status.
We do not receive or process payment card numbers, bank details or passwords.
4. How we process it
Names, addresses, emails and phone numbers are normalised and converted into keyed one-way hashes (HMAC). We store only these hashes, not the original text.
Hashes from one store are compared with hashes from other participating stores. Merchants see only factual signals, for example "the same name and address were used at 3 stores in the last 24 hours". They never see another store's name, orders or customers.
When a merchant opens the Scam Shield dashboard, customer names for that merchant's own flagged orders are fetched live from Shopify for display. They are not stored.
Store access tokens are stored encrypted.
Scam Shield only provides information. The merchant makes every decision about an order. We make no automated decision that cancels or refuses an order.
We do not sell data, use it for advertising, or use it to train AI or machine-learning models.
5. Why and on what basis
We process this data only to detect and prevent payment fraud and chargeback abuse across participating stores. The legal basis is the legitimate interest of merchants, and of the public, in preventing fraud (GDPR Art. 6(1)(f)). Merchants expressly authorise the Network when they accept the Scam Shield Terms of Service. Processing also follows the Israeli Privacy Protection Law, 5741-1981, and its regulations.
6. Where data is stored, and who processes it
Data is stored and processed with Cloudflare, Inc. (Cloudflare Workers and D1), our only subprocessor. The database is located in Western Europe. Data is encrypted in transit (TLS) and at rest. Shopify supplies the order data under its own terms.
7. Retention and deletion
Order hashes are kept for 90 days and then deleted automatically.
When a merchant uninstalls the app, all data about that store and its customers is deleted within 30 days (and normally within about 48 hours, when Shopify sends its shop-deletion request).
When a customer asks a merchant to erase their data, Shopify forwards the request to us and we delete that customer's records.
Encrypted backups are kept for up to 30 days, after which deleted data no longer exists in them either.
8. Your rights
Customers of participating stores, and merchants, may ask to access, correct or delete their data, or object to its processing, under the Israeli Privacy Protection Law and, where it applies, the GDPR. On request, we provide the data we hold in a structured, machine-readable format. Because we store only hashes, we may need the details you used when ordering (name, address, email or phone) to find your records. Customers can also contact the store they ordered from, which can submit the request through Shopify. You may also complain to the Israel Privacy Protection Authority or to your local data-protection authority.
9. Security and breaches
We limit access to the app's systems to authorised personnel, require two-factor authentication, keep secrets in an encrypted store, and log access. If a personal-data breach occurs, we will notify Shopify within 24 hours of discovering it, and notify affected merchants and the relevant authorities as the law requires.
10. Changes
If we change this policy, we will update the date above. We will tell merchants about material changes in the app or by email.
11. Contact
Liran Brook (Osek Murshe 231451511) · liran.brook@gmail.com
————————
Scam Shield — מדיניות פרטיות
עודכן לאחרונה: 28 בספטמבר 2026
1. מי אנחנו
Scam Shield היא אפליקציה ל-Shopify המופעלת על ידי לירן ברוק, עוסק מורשה מס' 231451511, שאול המלך 8, קריית אונו, ישראל ("אנחנו"). לגבי מידע שאנו מקבלים מחנויות הסוחרים, אנו פועלים מטעם הסוחר (כמעבד מידע). לגבי רשת מניעת ההונאות המשותפת המתוארת להלן, אנו בעלי השליטה במאגר.
יצירת קשר: liran.brook@gmail.com
2. מה Scam Shield עושה
Scam Shield עוזרת לסוחרים ב-Shopify לזהות הזמנות שעלולות להסתיים בהכחשת עסקה או בהונאת חיוב חוזר. כאשר חנות שמשתמשת באפליקציה מקבלת הזמנה, Scam Shield בודקת אם פרטי לקוח זהים או דומים שימשו לאחרונה בחנויות אחרות שמשתמשות ב-Scam Shield ("הרשת"). לאחר מכן היא מוסיפה להזמנה בממשק הניהול של Shopify רמת סיכון (נמוכה, בינונית או גבוהה) ואת הסיבות לה.
3. המידע שאנו מעבדים
מכל הזמנה בחנות משתתפת:
שם הלקוח (מלא, פרטי ומשפחה);
כתובת משלוח וחיוב: רחוב, עיר, אזור, מיקוד ומדינה;
כתובת אימייל ומספר טלפון;
מזהה הזמנה, מספר הזמנה, דומיין החנות, סכום ההזמנה ומטבע, ומועד ההזמנה.
מכל סוחר: דומיין החנות, אסימון גישה לחנות וסטטוס המנוי.
איננו מקבלים ואיננו מעבדים מספרי כרטיסי אשראי, פרטי בנק או סיסמאות.
4. כיצד אנו מעבדים את המידע
שמות, כתובות, כתובות אימייל ומספרי טלפון עוברים נרמול ומומרים לגיבובים (hash) חד-כיווניים מבוססי מפתח (HMAC). אנו שומרים רק את הגיבובים, לא את הטקסט המקורי.
גיבובים מחנות אחת מושווים לגיבובים של חנויות משתתפות אחרות. הסוחרים רואים רק אותות עובדתיים, למשל "אותו שם ואותה כתובת שימשו ב-3 חנויות ב-24 השעות האחרונות". הם לעולם אינם רואים שם של חנות אחרת, את ההזמנות שלה או את הלקוחות שלה.
כאשר סוחר פותח את לוח הבקרה של Scam Shield, שמות הלקוחות בהזמנות המסומנות של החנות שלו נשלפים מ-Shopify בזמן אמת לצורך תצוגה בלבד. הם אינם נשמרים.
אסימוני הגישה לחנויות נשמרים מוצפנים.
Scam Shield מספקת מידע בלבד. כל החלטה לגבי הזמנה מתקבלת על ידי הסוחר. איננו מקבלים החלטה אוטומטית שמבטלת או דוחה הזמנה.
איננו מוכרים מידע, איננו משתמשים בו לפרסום, ואיננו משתמשים בו לאימון מודלים של בינה מלאכותית או למידת מכונה.
5. מטרה ובסיס חוקי
אנו מעבדים את המידע אך ורק כדי לזהות ולמנוע הונאות תשלום והכחשות עסקה בחנויות המשתתפות. הבסיס החוקי הוא האינטרס הלגיטימי של הסוחרים, ושל הציבור, במניעת הונאות (סעיף 6(1)(f) ל-GDPR). הסוחרים מאשרים את הרשת במפורש כשהם מקבלים את תנאי השימוש של Scam Shield. העיבוד נעשה גם בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, ולתקנות מכוחו.
6. היכן המידע נשמר ומי מעבד אותו
המידע נשמר ומעובד אצל Cloudflare, Inc. (Cloudflare Workers ו-D1), מעבד המשנה היחיד שלנו. מסד הנתונים ממוקם במערב אירופה. המידע מוצפן בהעברה (TLS) ובאחסון. Shopify מספקת את נתוני ההזמנות בהתאם לתנאים שלה.
7. שמירה ומחיקה
גיבובי ההזמנות נשמרים 90 יום, ולאחר מכן נמחקים אוטומטית.
כאשר סוחר מסיר את האפליקציה, כל המידע על החנות ועל לקוחותיה נמחק תוך 30 יום (ובדרך כלל תוך כ-48 שעות, כאשר Shopify שולחת את בקשת מחיקת החנות).
כאשר לקוח מבקש מסוחר למחוק את המידע שלו, Shopify מעבירה אלינו את הבקשה ואנו מוחקים את הרשומות של אותו לקוח.
גיבויים מוצפנים נשמרים עד 30 יום, ולאחר מכן גם מהם לא ניתן לשחזר מידע שנמחק.
8. הזכויות שלך
לקוחות של חנויות משתתפות, וכן סוחרים, רשאים לבקש לעיין במידע עליהם, לתקן אותו או למחוק אותו, או להתנגד לעיבודו, לפי חוק הגנת הפרטיות, ובמקרים הרלוונטיים לפי ה-GDPR. לבקשתך נמסור את המידע שאנו מחזיקים בפורמט מובנה וקריא למכונה. מאחר שאנו שומרים גיבובים בלבד, ייתכן שנזדקק לפרטים ששימשו בהזמנה (שם, כתובת, אימייל או טלפון) כדי לאתר את הרשומות. לקוחות יכולים לפנות גם לחנות שבה הזמינו, והיא תוכל להגיש את הבקשה דרך Shopify. ניתן גם להגיש תלונה לרשות להגנת הפרטיות או לרשות הגנת המידע במדינתך.
9. אבטחה ואירועי אבטחה
אנו מגבילים את הגישה למערכות האפליקציה לגורמים מורשים, מחייבים אימות דו-שלבי, שומרים סודות באחסון מוצפן ומתעדים גישה. אם יתרחש אירוע אבטחה הכולל מידע אישי, נודיע ל-Shopify תוך 24 שעות מגילויו, ונודיע לסוחרים המושפעים ולרשויות הרלוונטיות כנדרש בדין.
10. שינויים
אם נשנה את המדיניות, נעדכן את התאריך שבראש העמוד. על שינויים מהותיים נודיע לסוחרים באפליקציה או באימייל.
11. יצירת קשר
לירן ברוק (עוסק מורשה 231451511) · liran.brook@gmail.com