Chargetower Defense Ltd (“Chargetower”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website at chargetower.io, use our secure portal at portal.chargetower.io, access our API services, or engage with our chargeback alert, dispute resolution, fraud prevention, and identity verification services.
This Privacy Policy applies to all personal information we process as both a data controller and a data processor in connection with our services, and is issued in accordance with the EU General Data Protection Regulation 2016/679 (the “GDPR”) and the Cyprus Law Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data (Law 125(I)/2018).
Chargetower Defense Ltd
Parodos Eleftherias Street 14, 4520 Parekklisia, Cyprus
Company Number: HE490563 · VAT: CY60346070E
Email: niko@chargetower.io
Website: chargetower.io
You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus at any time. However, we would appreciate the opportunity to address your concerns in the first instance — please contact us at niko@chargetower.io.
Website visitors:
Portal and API users (authorised clients):
As part of our chargeback alert, fraud prevention, and identity verification services, we process customer data on behalf of our merchant clients, including:
Important: We act as a data processor for this information. Our merchant clients remain the data controllers and are responsible for ensuring they have appropriate legal bases for sharing this data with us.
Website analytics:
Service analytics:
We process personal information under the following legal bases of Article 6 GDPR:
When processing customer data on behalf of merchant clients, we rely on the documented instructions and legal bases established by our clients as data controllers, in accordance with Article 28 GDPR.
We may share personal information with trusted third-party service providers who assist us in operating our business, including cloud hosting and infrastructure providers, analytics and monitoring services, communication and support platforms, and security and fraud prevention partners. All third-party processors are contractually obligated under Article 28 GDPR to protect your information and use it only for specified purposes.
We may disclose personal information when required by law, regulation, legal process, or governmental request, or to comply with legal obligations, protect our rights and property, ensure the safety of our users and the public, or investigate potential violations of our terms.
In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction, subject to appropriate data protection safeguards.
We may share information for other purposes with your explicit consent.
Our primary processing takes place within the European Economic Area (EEA). Where we transfer personal information to countries outside the EEA, we ensure appropriate safeguards are in place under Chapter V of the GDPR, including:
Cookies are small text files stored on your device when you visit our website. They help us provide a better user experience and understand how our website is used.
When you first visit our website, we display a cookie consent banner that allows you to accept all cookies or choose essential-only. We will not place any non-essential cookies on your device until you have given consent through this banner. You can change your choice at any time by clicking the “Cookies” link in the footer of any page. You can also control cookies through your browser settings, though disabling certain cookies may affect website functionality.
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations under Cyprus and EU law, and resolve disputes.
Specific retention periods:
When retention periods expire, we securely delete or anonymise personal information using industry-standard methods.
We implement appropriate technical and organisational security measures, as required by Article 32 GDPR, to protect personal information against unauthorised access, alteration, disclosure, or destruction, including:
Under the GDPR and Cyprus data protection law, you have the following rights:
To exercise any of these rights, please contact us at niko@chargetower.io. We will respond to your request within one month, though this may be extended in complex cases as permitted by Article 12(3) GDPR.
Our services are designed for businesses and are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.
We will only send marketing communications to individuals who have given explicit consent or where we have a legitimate interest (for existing business clients regarding similar services). You can unsubscribe at any time by clicking the unsubscribe link in any marketing email, contacting us at niko@chargetower.io, or updating your preferences in your account settings.
Our website may contain links to third-party websites, plugins, and services. This Privacy Policy does not apply to these external sites. We recommend reviewing the privacy policies of any third-party services you use.
When providing services to merchant clients, we act as a data processor under Article 28 GDPR. This means we process customer data only on behalf of and according to documented client instructions, clients remain responsible as data controllers, we implement appropriate technical and organisational measures, and we assist clients with their data protection obligations.
Our data processing arrangements with clients are governed by separate Data Processing Agreements (DPAs) that form part of our service contracts.
Merchants may connect their Shopify store to Chargetower by installing the Chargetower app from the Shopify App Store or from an installation link we provide. This section describes what the app does with store data. We act as a data processor for this data; the merchant remains the data controller.
What the app reads. To find the order behind a chargeback or fraud alert, the app reads orders from the connected store: the order id and number, its creation date, totals and currency, and from the order’s payment transactions the payment gateway, the masked card number (of which only the last four digits are compared with the alert) and the card BIN. With the store’s permission, the app also reads the store’s Shopify Payments disputes (type, status, reason, amount, dates and the order they belong to) to show the merchant their own chargeback rate. The app does not request or store the customer’s name, shipping or billing address or phone number, and does not store the customer’s email address; the one case in which an email address is read is described under Subscriptions below. The resulting match is stored next to the alert.
Store connection data. The app stores the store’s domain and name, the store owner’s email address, the access token Shopify issues to the app, and the statement descriptors the store uses on card statements. When a merchant installs the app from the Shopify App Store, the store owner’s email address is used to create the merchant’s Chargetower account.
Automatic refunds. A merchant may allow the app to refund a disputed order automatically when an alert is matched to it with certainty, within limits the merchant sets in the portal. The merchant can switch this off at any time. A refund returns the customer’s own payment to the card it was paid from. Where nothing of the order has been shipped and the whole order is refunded, the app also cancels the order in Shopify so that it is not shipped; the merchant can switch this off for a store.
Subscriptions. Where a merchant enables cancelling a subscription on refund and gives the app their Seal Subscriptions API token, the app finds the subscription behind the refunded order in the merchant’s own Seal account and asks Seal to cancel it by Seal’s own subscription id. For a store installed from the Shopify App Store, nothing read from Shopify is sent to Seal. For a store connected through an installation link we provide, the app reads the order’s contact email address from Shopify and searches the merchant’s Seal account by it; the address is used for that search only and is not stored.
Where the data goes. Alerts are delivered to Chargetower by our alert provider, ChargeForwards. It receives the store’s name and the statement descriptors enrolled for alerts, and the outcome recorded for each alert, which it passes to the card network programme: whether the charge was refunded, the amount, the time and an optional comment, which may name the order number. It receives no other order data and no customer data. Shopify receives the API requests needed to read orders and disputes and, where enabled, to create refunds and cancel orders. The service is hosted by Amazon Web Services in the European Union (Stockholm region), and email is sent through Resend (European Union region). Store data is not used for advertising, profiling or analytics about the merchant’s customers, and is not sold.
Retention. Alert and order-match data is kept for as long as the merchant’s account is active, because it is the merchant’s record of their disputes, and is deleted when the account is closed. When the app is uninstalled from a store, the store’s access token and details are deleted within 48 hours of Shopify’s request.
Requests from a store’s customers. Shopify forwards customer data requests and erasure requests to the app. Because the app holds no customer identity data, a data request is answered with the fact that no such data is held; an erasure request removes any order candidate lists kept for the named orders. Each request is recorded so the merchant can show what was asked and what was done. A store’s customer who wants to exercise their rights should contact the merchant, who can contact us at the address in Section 17.
Email: niko@chargetower.io
Post: Chargetower Defense Ltd, Parodos Eleftherias Street 14, 4520 Parekklisia, Cyprus
Office of the Commissioner for Personal Data Protection of the Republic of Cyprus
1 Iasonos Street, 1082 Nicosia, Cyprus
Website: www.dataprotection.gov.cy
Email: commissioner@dataprotection.gov.cy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this policy, notify you via email if you have provided your email address, and post a notice on our website. We encourage you to review this Privacy Policy regularly.
This Privacy Policy is designed to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Cyprus Law 125(I)/2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, the ePrivacy Directive 2002/58/EC and its Cyprus implementation, and other applicable data protection laws. We regularly review our data protection practices to ensure ongoing compliance.