Privacy policy
Last updated 9 October 2026
FraudToad is a Shopify app that looks for card testing: people running stolen cards through cheap orders to find the ones that work. This page explains what data the app reads from a store that installs it, what it keeps, for how long, and who else handles it.
- We read order and payment details from Shopify to score each order for card testing, for the store that installed the app.
- Order details are deleted 31 days after the order. Everything is deleted 48 hours after a store uninstalls the app.
- We don't sell data, show ads, or send customer data to AI services.
- If you bought from a store that uses FraudToad, the store decides what happens to your order. Contact the store first.
Who we are, and whose data this is
FraudToad is run by the FraudToad team. You can reach us at [email protected].
FraudToad works on behalf of the Shopify merchants who install it. For data about a store's customers, the merchant is the controller (the business responsible for it) and we are their processor: we use it only to provide the app to that store, as the store sets it up. Each store's data is kept in its own separate database and is never combined with another store's.
For data about the merchants themselves (the store's address, the staff email addresses that receive alerts, and so on) we are the controller.
What we read about a store's customers
When a customer places an order, Shopify sends the app the order. From it, FraudToad uses:
- Contact details: the email address and phone number on the order.
- Address: the street lines, postal code and country of the shipping address (or the billing address if there is no shipping address). We keep only the countries and a keyed one-way hash of the address, so orders to the same address can be linked without storing the address itself.
- Network and browser: the IP address the order was placed from, and a one-way hash of the browser's user agent and language setting.
- Card details as Shopify provides them: the card's BIN (its first 6 to 8 digits, which identify the issuing bank), last 4 digits, brand, wallet (such as Apple Pay), and expiry date, plus the address check (AVS) and security code check (CVV) results from the payment provider. We keep the BIN, last 4, brand and wallet, and a keyed fingerprint made from the BIN, last 4 and expiry, so the same card can be recognised across orders. Shopify never gives apps full card numbers or security codes, so we never see them.
- Customer account: the Shopify customer ID, when the account was created, and how many orders it has placed. For an order the rules have flagged, we also look up that customer's earlier orders with the store (whether they were paid, fulfilled, cancelled or disputed) to recognise repeat customers in good standing.
- The order itself: order number, total and currency, payment transactions and gateway, sales channel, order and customer tags, and Shopify's own fraud risk recommendation.
We don't keep customers' names. Shopify's order message includes names and full addresses; the app holds that message only until it has processed it, normally within seconds, and keeps only the fields above.
Why
For one purpose: to score each order for card testing for the merchant, and to act on the score as the merchant has set the app up to (see automated decisions). Card testing shows up as a pattern across orders, such as one card used on many new accounts or many cards from one IP address, so the app compares each new order with the store's other recent orders. These details are what make that possible.
What we keep about merchants
- The store's Shopify address and an access token for the store, stored encrypted, so the app can act on orders.
- The store's settings, including the staff email addresses that receive alerts.
- A record of when the app was installed and uninstalled.
How long we keep it
- Order details (everything listed above, and the rules each order triggered) are deleted 31 days after the order.
- The audit log keeps a summary of each decision for the merchant's records: the order number, total, score, which rules fired and what the app or the merchant did. It holds no email, phone, IP address, address or card details. It is kept while the app is installed.
- Blocklist entries (a card fingerprint, IP address, email, phone, address hash or customer ID) that the app adds on its own expire after 30 days by default. Entries a merchant adds by hand last until the merchant removes them or the period they chose ends.
- Allowlist entries (a card fingerprint, email or customer ID of a trusted customer) last until the merchant removes them.
- Tests on past orders. When a merchant tests the app on their last 60 days of orders, those orders are read into a separate database and deleted when the test finishes; only the summary of results is kept.
- Backups of each store's database are encrypted and kept for up to 30 days, then deleted.
- Server logs record what the app did (order numbers, scores, errors) and are kept by our hosting provider for a few days.
- After uninstall. Shopify tells us 48 hours after a store uninstalls the app, and we then delete everything we hold for that store. Copies in backups are gone once those backups expire.
Who else handles it
We don't sell or rent personal data, share it for advertising, or use it for anything other than running FraudToad for the store it came from. These services process it for us:
| Service | What for | What it handles |
|---|---|---|
| Cloudflare | Hosting the app and storing each store's database, backups and logs | Everything described on this page |
| Resend | Sending email alerts to the merchant's staff | The recipients' email addresses and the alert: order number, score and which rules fired, with no customer details |
| Shopify | The platform the app runs on | Shopify is where the data comes from. The app writes tags, holds, risk notes and cancellations back to the store's orders, and, if the merchant turns on the checkout lock, a list of blocked emails and customer IDs that the store's checkout reads |
If a merchant builds Shopify Flow workflows on FraudToad's decisions, Flow receives the order, its score and the rules that fired, and does with them what the merchant's workflow says.
We don't use cookies or analytics on this website. Inside the app, Shopify's own sign-in is used to identify the merchant's staff.
No AI on customer data
FraudToad scores orders with fixed rules that anyone can read in our help pages. We don't send customer data to AI or machine learning services, and we don't use it to train models.
Automated decisions
FraudToad can act on orders on its own, which can affect the customer who placed them. Here is what it does and what control the merchant has:
- Shadow mode is the default. A newly installed app scores orders and holds the ones it would have cancelled, but cancels nothing. The merchant has to switch automatic cancelling on.
- The merchant picks the strongest action the app may take on its own: hold only, cancel and void, or cancel, void and block.
- Held orders wait for a person. The merchant reviews each held order, with every rule that fired and why, and approves or cancels it. If a held order isn't reviewed in time (48 hours by default), the app follows the merchant's setting for that: by default, very small orders and higher scores are cancelled and the rest are released.
- When automatic cancelling is on, an order with a high score is cancelled and its payment voided before it is captured, so the customer is not charged. The highest scores also put the card, IP address, email and customer account on the store's blocklist. If the store has turned on the checkout lock, a blocked email or account is also stopped at checkout.
- Trusted customers are protected. Repeat customers in good standing are allowlisted automatically, and the merchant can allowlist any customer or card. An allowlisted customer's order is never cancelled automatically, only held at most.
If you think a store cancelled your order by mistake, contact the store. The merchant can see why the order was flagged, allowlist you, and remove any block.
Your rights
Depending on where you live, laws such as the GDPR in the EU and UK and the CCPA in California give you the right to know what personal data is held about you, to get a copy, to have it corrected or deleted, to object to its use, and not to be subject to some decisions made only by automated means.
If you are a store's customer, make your request to the store, since it decides how your data is used. Shopify passes data and deletion requests from stores on to us, and we help the store answer them: we tell the store what we hold about you and delete it. One exception: if a card, IP address or address of yours was blocked as a likely card tester, that block can stay after the deletion, no longer linked to your name, email or orders, because keeping it is needed to prevent fraud. Order details are deleted after 31 days regardless. You can also write to us and we will pass your request to the store.
If you are a merchant, write to us about the data we hold on your store, or uninstall the app to have all of it deleted.
We don't sell personal information or share it for cross-context behavioural advertising, as those terms are used in the CCPA.
Security
Data travels over encrypted connections. Each store's data lives in its own database, the store's Shopify access token is encrypted, and card and address details are kept only as keyed hashes. Inside the app, staff can only see the store they are signed in to.
Where it is processed
Cloudflare and Resend run their services in several countries, including the United States, so data may be processed outside the country where you live. Both offer data processing terms that include the EU standard contractual clauses for these transfers.
Children
FraudToad is a tool for businesses. It isn't directed at children and doesn't knowingly collect their data beyond what appears on a store's orders.
Changes
If we change this policy, we'll update it here and change the date at the top.
Contact
Email [email protected]. If it's about an order, include the store's address (yourstore.myshopify.com) and the order number.