🛡️

ShipWard Privacy Policy

Last Updated: September 18, 2026

1. Overview

ShipWard ("we", "our", or "us") provides a Shopify application that enables merchants to offer package protection, warranties, and automated claims resolution to their customers. This Privacy Policy outlines our policies regarding the collection, use, and disclosure of personal and store information when you install and use the ShipWard application.

2. Information We Collect

To provide our services, ShipWard collects the following information via Shopify APIs:

  • Merchant Store Information: Store name, myshopify domain, primary email, and currency settings to configure fee calculation and dashboard reporting.
  • Order Data: Order IDs, order numbers, line items, and shipping status to verify whether an order has ShipWard package protection.
  • Customer Dispute Information: Customer email, order number, proof description, and optional image attachments submitted voluntarily by customers when filing a claim via the storefront dispute portal.

3. How We Use Information

We use the collected information strictly for:

  • Verifying protected package status during claims intake.
  • Allowing merchants to review, approve, or decline claims.
  • Generating replacement draft orders in the merchant's Shopify Admin upon claim approval.
  • Providing merchants with accurate net profit and claims loss metrics.

We do not sell, rent, or monetize merchant or buyer personal data to third parties.

4. GDPR & CCPA Compliance

ShipWard fully complies with European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We support mandatory compliance webhooks:

  • customers/data_request: Provides customer dispute data upon verified request.
  • customers/redact: Anonymizes and redacts customer personal data within 30 days.
  • shop/redact: Deletes all merchant and store-associated records within 48 hours of app uninstallation.

5. Security & Retention

All data in transit is encrypted using modern Transport Layer Security (TLS 1.3). All incoming Shopify webhooks are authenticated via HMAC-SHA256 signatures. Data is retained only as long as necessary to fulfill dispute resolution and warranty verification.

6. Contact Us

If you have questions regarding this Privacy Policy or data handling practices, please contact us at:

[email protected]