FraudToad

Privacy policy

Last updated 9 October 2026

FraudToad is a Shopify app that looks for card testing: people running stolen cards through cheap orders to find the ones that work. This page explains what data the app reads from a store that installs it, what it keeps, for how long, and who else handles it.

Who we are, and whose data this is

FraudToad is run by the FraudToad team. You can reach us at [email protected].

FraudToad works on behalf of the Shopify merchants who install it. For data about a store's customers, the merchant is the controller (the business responsible for it) and we are their processor: we use it only to provide the app to that store, as the store sets it up. Each store's data is kept in its own separate database and is never combined with another store's.

For data about the merchants themselves (the store's address, the staff email addresses that receive alerts, and so on) we are the controller.

What we read about a store's customers

When a customer places an order, Shopify sends the app the order. From it, FraudToad uses:

We don't keep customers' names. Shopify's order message includes names and full addresses; the app holds that message only until it has processed it, normally within seconds, and keeps only the fields above.

Why

For one purpose: to score each order for card testing for the merchant, and to act on the score as the merchant has set the app up to (see automated decisions). Card testing shows up as a pattern across orders, such as one card used on many new accounts or many cards from one IP address, so the app compares each new order with the store's other recent orders. These details are what make that possible.

What we keep about merchants

How long we keep it

Who else handles it

We don't sell or rent personal data, share it for advertising, or use it for anything other than running FraudToad for the store it came from. These services process it for us:

ServiceWhat forWhat it handles
CloudflareHosting the app and storing each store's database, backups and logsEverything described on this page
ResendSending email alerts to the merchant's staffThe recipients' email addresses and the alert: order number, score and which rules fired, with no customer details
ShopifyThe platform the app runs onShopify is where the data comes from. The app writes tags, holds, risk notes and cancellations back to the store's orders, and, if the merchant turns on the checkout lock, a list of blocked emails and customer IDs that the store's checkout reads

If a merchant builds Shopify Flow workflows on FraudToad's decisions, Flow receives the order, its score and the rules that fired, and does with them what the merchant's workflow says.

We don't use cookies or analytics on this website. Inside the app, Shopify's own sign-in is used to identify the merchant's staff.

No AI on customer data

FraudToad scores orders with fixed rules that anyone can read in our help pages. We don't send customer data to AI or machine learning services, and we don't use it to train models.

Automated decisions

FraudToad can act on orders on its own, which can affect the customer who placed them. Here is what it does and what control the merchant has:

If you think a store cancelled your order by mistake, contact the store. The merchant can see why the order was flagged, allowlist you, and remove any block.

Your rights

Depending on where you live, laws such as the GDPR in the EU and UK and the CCPA in California give you the right to know what personal data is held about you, to get a copy, to have it corrected or deleted, to object to its use, and not to be subject to some decisions made only by automated means.

If you are a store's customer, make your request to the store, since it decides how your data is used. Shopify passes data and deletion requests from stores on to us, and we help the store answer them: we tell the store what we hold about you and delete it. One exception: if a card, IP address or address of yours was blocked as a likely card tester, that block can stay after the deletion, no longer linked to your name, email or orders, because keeping it is needed to prevent fraud. Order details are deleted after 31 days regardless. You can also write to us and we will pass your request to the store.

If you are a merchant, write to us about the data we hold on your store, or uninstall the app to have all of it deleted.

We don't sell personal information or share it for cross-context behavioural advertising, as those terms are used in the CCPA.

Security

Data travels over encrypted connections. Each store's data lives in its own database, the store's Shopify access token is encrypted, and card and address details are kept only as keyed hashes. Inside the app, staff can only see the store they are signed in to.

Where it is processed

Cloudflare and Resend run their services in several countries, including the United States, so data may be processed outside the country where you live. Both offer data processing terms that include the EU standard contractual clauses for these transfers.

Children

FraudToad is a tool for businesses. It isn't directed at children and doesn't knowingly collect their data beyond what appears on a store's orders.

Changes

If we change this policy, we'll update it here and change the date at the top.

Contact

Email [email protected]. If it's about an order, include the store's address (yourstore.myshopify.com) and the order number.