Order Vault

Privacy Policy

This policy explains what Order Vault accesses, stores, and does with data when a merchant installs it on their Shopify store.

Who we are

Order Vault is built and operated by PINUYA LLC. Order Vault is a Shopify app that helps merchants review orders flagged as risky, confirm them with the customer, and assemble chargeback evidence.

Who is the data controller

The merchant who installs Order Vault on their store is the data controller for their store's order and customer information. Order Vault processes that data on the merchant's behalf, strictly to provide the app's features. If you are a customer of a store using Order Vault and have a question about your order or data, please contact that store directly first — they control your data and can act on your request fastest.

Data we access and store

To do its job, Order Vault requests the following permissions from Shopify: read and write orders, read customers, manage merchant-managed fulfillment orders, read fulfillments, and read Shopify Payments disputes. For every order placed while Order Vault is installed, it keeps an evidence record; orders flagged for review also get a verification case. Together these contain:

  • An order summary (order number, date, total, status).
  • The customer's name, email address, and phone number.
  • The billing and shipping addresses on the order.
  • Payment result details Shopify makes available for the transaction: the card's last 4 digits, card brand and BIN when present, and the AVS and CVV result codes returned by the payment gateway. We never receive or store full card numbers — Shopify does not expose them to apps.
  • Shopify's fraud risk assessment for the order.
  • Fulfillment and shipment tracking information.
  • A timeline of events for the order (e.g. hold placed, verification sent, decision made).
  • The customer's verification record when they confirm an order through our verification page: the time of confirmation, IP address, browser user agent, and any optional note they add.
  • Dispute (chargeback and inquiry) records Shopify sends us for the order.
  • The merchant's own app settings: notification email address and sender display name.
  • The Shopify access token issued when the merchant installs the app, so Order Vault can act on their store.

How we use it

This data is used only to run the app's core workflow: deciding whether a flagged order needs customer verification, sending that verification request, holding fulfillment until a decision is made, and building a chargeback evidence file the merchant can send to their payment processor or bank if a dispute is opened. Emails we send are transactional only — a verification request to the customer, or a notification to the merchant. We do not sell or share this data with third parties for their own purposes, run marketing campaigns, or use tracking pixels.

Sharing and subprocessors

We use a small number of subprocessors to run Order Vault, each limited to what they need to do their job:

  • ShopifyThe e-commerce platform Order Vault runs on and reads order/customer data from.
  • Resend (resend.com)Delivers transactional emails: customer verification requests and merchant notifications.
  • Railway (railway.com)Hosts the Order Vault application and its database.
  • Cloudflare (cloudflare.com)DNS and encrypted database backup storage.

Retention and deletion

  • Evidence records, order cases, event history and dispute records are deleted automatically 18 months after they were created, which covers standard chargeback response windows. Records for an order that still has an open verification case or an open or recent chargeback are kept until that is resolved.
  • If a merchant uninstalls Order Vault, Shopify notifies us 48 hours later and we delete all of that store's data — order cases, evidence records, disputes, event history, settings, and the store's access token.
  • If a customer asks a store to erase their data, Shopify forwards that request to us and we delete the order-scoped records tied to that customer.
  • If a customer asks a store what data is held about them, Shopify forwards that request to us; we look up what we hold and notify the merchant so they can respond, without exposing the customer's personal data in that notification.

Security

  • All traffic to and from Order Vault is encrypted in transit (HTTPS/TLS).
  • Data is encrypted at rest at the storage level by our hosting provider.
  • Daily database backups are encrypted (age) before leaving the server, stored in Cloudflare R2, and kept for 30 days.
  • Staff access is limited to the owner's accounts, all protected by strong passwords and two-factor authentication.
  • An application log records when merchant staff view or export customer personal data.
  • Development and production run on separate environments and databases.
  • Secrets and credentials are kept out of source code.

We do not provide a general-purpose data browser to third parties, and we do not claim any specific security certification (e.g. SOC 2). Details of how we process data as a processor are in our Data Processing Addendum.

Your rights

Depending on where you live, you may have rights over your personal data under laws such as the GDPR or CCPA/CPRA — for example, the right to access, correct, or delete the data a store holds about you, or to know what has been collected. Because the store you ordered from is the data controller, the fastest way to exercise these rights is to contact that store directly. If you'd like to reach Order Vault about data we process on a merchant's behalf, email pinuya.llc@gmail.com and we will assist or route your request to the relevant store.

Children

Order Vault is a business tool for merchants and is not directed at children. We do not knowingly collect data from children.

Changes to this policy

If we make material changes to this policy, we will update the "Last updated" date at the bottom of this page.

Contact

Questions about this policy or how Order Vault handles data can be sent to pinuya.llc@gmail.com. See also our Terms of Service and Data Processing Addendum.