Who we are
Rebuttal is a Shopify application operated by NorthMastApps, based in Portugal. Rebuttal helps Shopify merchants prepare evidence responses to payment disputes (chargebacks). Contact: northmastapps@gmail.com.
Our role.
For personal data belonging to a merchant's customers, the merchant is the data controller and we act as a data processor on the merchant's behalf, under Shopify's platform terms and this policy. For data about merchants themselves (account and billing information), we are the controller.
What we collect and why.
When a merchant installs Rebuttal, we collect and store, for each new order: customer name, email address, billing and shipping addresses; order contents and totals; checkout session details (IP address, browser user agent, language); payment verification results (AVS/CVV outcome codes, plus the card's issuing-bank identification number and brand — never full card numbers); fulfillment and delivery tracking; a snapshot of the product listing as it appeared at the time of purchase; and a copy of the store's refund policy and terms of service in effect at the time of purchase. When a payment dispute occurs, we store the dispute details provided by Shopify and generate an evidence document from the data above. We collect this data for one purpose: assembling evidence that the merchant may review and submit in response to payment disputes. We do not use it for advertising, profiling, or any other purpose, and we never sell personal data.
Where data is stored.
Data is stored on infrastructure provided by Fly.io in Frankfurt, Germany (EU). We use Sentry for error monitoring, configured so that request contents and personal data are not transmitted with error reports. Data is exchanged with Shopify as required for the app to function. We use no other subprocessors and share data with no other parties, except where required by law.
Evidence integrity.
Order-time evidence — payment verification, session details, the product listing, and store policies — is captured once, at the time of the order, and never modified or refetched afterward: a listing or policy changed after the sale is exactly what the snapshot exists to prove. The one exception is fulfillment: shipping and delivery status are updated as the carrier reports them, and the evidence document shows its own capture time for that section separately, so it is always clear when each piece of evidence was recorded.
Retention and deletion.
Evidence data is retained while the merchant has Rebuttal installed, because dispute deadlines can arrive months after an order. We honor Shopify's mandatory privacy webhooks: when a customer requests deletion through their merchant, that customer's captured order data is redacted. One deliberate exception applies: where an order is the subject of a payment dispute, the generated evidence for that dispute is retained even after a redaction request, because it forms part of the merchant's legal response to the dispute — a legitimate interest recognized under data-protection law. That evidence is deleted when the merchant uninstalls, on Shopify's standard redaction schedule (48 hours after uninstall), along with all of the store's other data. Merchants may also request earlier deletion at northmastapps@gmail.com.
Data subject rights.
Customers seeking access to or deletion of their data should contact the merchant they purchased from, who can fulfill the request through Shopify's built-in privacy tools. We act on those requests directly: deletion is processed automatically, and for data-access requests we compile the customer's data and forward it for the merchant to deliver. We also respond to merchant-forwarded requests at northmastapps@gmail.com.
Security.
Data is transmitted over HTTPS and stored in access-controlled infrastructure.
Changes.
We'll update this page when our practices change, with the date above revised accordingly.