Checkout Firewall privacy policy

Checkout Firewall is a public Shopify app that helps merchants stop card-testing attacks before they reach a payment processor. This policy describes what we process and why.

What we process

We process checkout identity needed to match merchant lists and hashed reputation: email, phone, shipping or billing address, postal code, and Shopify customer id when present. We never receive payment card numbers, CVV, or magnetic stripe data.

How identifiers are stored

Canonical forms are HMAC-hashed before they enter shared reputation tables. One merchant cannot see another merchant’s customers or the raw values another shop reported. Hashing reduces accidental cross-store leakage; it is not anonymity and does not replace GDPR or CPRA obligations.

Shop-local data

Blacklists, whitelists, fraud reports, and activity logs stay scoped to the installing shop. Display labels are masked so the merchant can recognize what they entered.

Purpose

Processing is limited to checkout fraud prevention: compiling Validation Function rules, logging merchant-visible decisions, detecting card-testing bursts, and operating a hashed cross-store reputation set.

Retention and deletion

Observation and decision records are retained up to 180 days unless a merchant uninstalls or Shopify sends a mandatory redact webhook sooner. Shop uninstall and shop/redact delete that shop’s local data. customers/redact deletes matching hashed observations and reports for that shop.

Buyer impact

In Monitor mode the Function never blocks checkout. In Balanced or Aggressive, high-confidence matches can stop checkout. Merchants can whitelist an identifier or mark a report as a false positive.

Contact

Merchants should contact the app operator through the Shopify App Store listing support channel.