Checkout Firewall privacy policy
Checkout Firewall is a public Shopify app that helps merchants stop card-testing attacks before they reach a payment processor. This policy describes what we process and why.
What we process
We process checkout identity needed to match merchant lists and hashed reputation: email, phone, shipping or billing address, postal code, and Shopify customer id when present. We never receive payment card numbers, CVV, or magnetic stripe data.
How identifiers are stored
Canonical forms are HMAC-hashed before they enter shared reputation tables. One merchant cannot see another merchant’s customers or the raw values another shop reported. Hashing reduces accidental cross-store leakage; it is not anonymity and does not replace GDPR or CPRA obligations.
Shop-local data
Blacklists, whitelists, fraud reports, and activity logs stay scoped to the installing shop. Display labels are masked so the merchant can recognize what they entered.
Purpose
Processing is limited to checkout fraud prevention: compiling Validation Function rules, logging merchant-visible decisions, detecting card-testing bursts, and operating a hashed cross-store reputation set.
Retention and deletion
Observation and decision records are retained up to 180 days unless a merchant uninstalls or Shopify sends a mandatory redact webhook sooner. Shop uninstall and shop/redact delete that shop’s local data. customers/redact deletes matching hashed observations and reports for that shop.
Buyer impact
In Monitor mode the Function never blocks checkout. In Balanced or Aggressive, high-confidence matches can stop checkout. Merchants can whitelist an identifier or mark a report as a false positive.
Contact
Merchants should contact the app operator through the Shopify App Store listing support channel.