Effective July 11, 2026 · From Andamento Advisors LLC
A plain-language summary of what Predispute reads from your store, what it never touches, and how long it keeps anything. The privacy policy is the formal version.
Predispute connects through the read-only scopes your platform grants at install. On Shopify and Stripe that is your disputes and the orders or charges behind them: amounts, reason codes, networks, dates, the issuing bank where the platform provides it, and the fulfilment and address details already attached to the order.
Access is read-only. Predispute never writes to your store, moves money, or changes your orders.
No full card numbers, no CVV codes, no bank account numbers, no cardholder Social Security numbers. Predispute works from dispute and order metadata alone, which keeps it outside PCI DSS scope.
Your data is encrypted in transit and at rest and held with a small set of vetted infrastructure providers. It is never sold and never shared with advertisers. Improvements to the decisioning logic use only anonymized, aggregated metadata, never identifiable store data.
| Dispute and volume snapshots | 13 months, then monthly aggregates |
| Computed ratios and anonymized outcomes | Indefinitely |
| Alerts | 12 months |
| Store profile | While installed, plus 30 days |
| Error and webhook logs | 30 days |
Uninstalling the app deletes your store's data. Shopify's mandatory erasure requests are honored automatically, and you can ask us to access, correct, or delete anything by emailing hello@predispute.com; we respond within 30 days.