Shield Privacy Policy
Last updated: 27 September 2026
Shield is a Shopify app provided by om enterprise ("we"). It helps Shopify merchants detect and stop bots and fraudulent orders. This policy explains what personal data Shield processes, why, and for how long. Merchants who install Shield are the controllers of their customers' data; we process it on their behalf.
Data we process
- Merchant data: store domain, Shield settings, plan and subscription status, and the Shopify access token needed to operate the app.
- Order data (received from Shopify when an order is created): order ID and number, order total and currency, customer ID, email, name, shipping and billing address, phone, browser IP address, browser user agent and checkout token.
- Storefront signals (from the Shield app embed, only when the merchant enables it): a device fingerprint (a SHA-256 hash computed in the shopper's browser from a random per-browser ID and basic device characteristics), whether the browser is controlled by automation software, and a count of interactions in the current visit. These are stored as cart attributes on the shopper's cart. No keystrokes, mouse movements or page contents are collected.
How we store it
Shield does not store raw emails, IP addresses, street addresses, phone numbers or fingerprints. It stores keyed one-way hashes (HMAC-SHA256) so repeated use can be recognised without keeping the original value. Names and email domains are checked in memory and not stored. Shield stores the order's risk score, decision, and the reasons for the decision.
Why we process it
Solely to provide fraud and bot protection to the merchant: scoring each order, holding or flagging risky orders, and stopping checkouts from automated browsers or from devices and emails linked to orders the merchant's store blocked. We do not sell personal data, use it for advertising or marketing, or share it across stores.
Automated decisions and human review
Shield makes automated decisions: it can flag or hold an order, and it can stop a checkout. Anyone stopped at checkout sees a message asking them to contact the store; the merchant can review the case and remove the device or email from the blocklist. Automatic cancellation is off by default and only runs if the merchant turns it on. Customers can ask the store for their order to be reviewed by a person at any time.
Order confirmation
When a merchant turns on order confirmation, Shield emails the buyer of a cash-on-delivery or flagged order a link to confirm the order, and may send one reminder. Buyers with an Indian mobile number also receive the link by SMS. The email address and phone number are read from the order at sending time and are not stored by Shield; Shield keeps only the order number, the confirmation status and timestamps, for 90 days. Pressing the link's button confirms the order; merely opening the link changes nothing.
Service providers
- Shopify: provides the order data and runs Shield's checkout rule.
- Railway: hosts Shield's servers and database (SOC 2 Type II; data encrypted at rest with AES-256).
- IPQualityScore: when enabled, receives the IP address and browser user agent of borderline orders only, to check IP reputation.
- Resend: delivers order confirmation emails when a merchant turns that feature on; receives the buyer's email address, the order number and the store name.
- Fast2SMS: delivers order confirmation SMS to Indian mobile numbers; receives the buyer's phone number, the order number, the store name and a short link code.
- DB-IP: Shield finds the country of an order's IP address with the free DB-IP country database, loaded on Shield's own servers. No data is sent to DB-IP. IP Geolocation by DB-IP.
Retention
- Order risk history: 180 days.
- Device records: 180 days after last use.
- Checkout blocklist entries: 30 days.
- Checkout start times: 7 days. IP reputation results: 24 hours.
- All data for a store is deleted when Shopify sends the shop/redact request after the app is uninstalled.
Security
Data is encrypted in transit (TLS for public traffic, WireGuard between our services) and at rest by our hosting provider. Access to production systems is limited to the operator, protected by strong passwords and two-factor authentication, and logged. Logs never contain raw personal data.
Your rights
Customers can request access to or deletion of their data through the store they purchased from. Shield handles Shopify's customers/data_request, customers/redact and shop/redact requests automatically. You can also contact us at chandanrajawat1998@gmail.com.
Changes
We will update this page when our practices change and show the date of the latest update above.