Privacy policy
How DupeGuard handles your data
Last updated 27 July 2026
DupeGuard is a Shopify app that identifies shoppers claiming a one-per-customer discount more than once under different identities. Doing that requires reading order and customer records from the stores that install it. This page sets out exactly what is read, why, where it is kept, and how to have it removed.
Who is responsible for what
For the shopper data processed through the app, the merchant who installs DupeGuard is the data controller and DupeGuard is a data processor acting on their instructions. DupeGuard does not decide what a merchant sells, who shops with them, or what happens to a flagged order — the merchant does.
What DupeGuard reads
When a merchant installs the app, they grant access to the following through Shopify’s Admin API. Nothing outside this list is requested.
| Data | Why it is needed |
|---|---|
| Order records — totals, discount codes used, dates, cancellation and refund status | To tell which orders used a protected discount code, and to calculate the money-saved figure |
| Customer name, email address and phone number | To recognise when several accounts belong to the same shopper — for example a Gmail alias or a dotted variant of the same mailbox |
| Shipping and billing addresses | To recognise repeat orders going to the same doorstep under different names |
| Discount configuration for the codes a merchant chooses to protect | To know which codes to watch |
Because of the permissions Shopify grants, the historical audit generally covers roughly the last 60 days of orders rather than a store’s entire history.
What DupeGuard does not do
- It does not sell, rent or share personal data with third parties.
- It does not use the data to build cross-merchant profiles. Every store’s data is kept separate and is only ever queried within that store’s own scope.
- It does not run advertising trackers, web pixels or third-party analytics on a merchant’s storefront.
- It does not process payment card details. It never sees them.
Where data is stored
Data is held in a PostgreSQL database hosted by Render in Frankfurt, Germany (EU). Access credentials for a merchant’s store — the tokens that allow DupeGuard to call the Shopify API on their behalf — are encrypted at rest using AES-256-GCM. Traffic between Shopify, DupeGuard and merchants is encrypted in transit over HTTPS.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Render | Application hosting and database | Frankfurt, Germany (EU) |
| Shopify | Source of the data, and the platform the app runs inside | Per Shopify’s own terms |
How long data is kept
Order and customer records are kept for as long as the merchant has DupeGuard installed, because the app’s whole function is comparing a new order against earlier ones. There is no separate archive and no backup copy kept beyond the hosting provider’s own routine database backups.
When a merchant uninstalls, Shopify notifies DupeGuard 48 hours later and every record belonging to that store is deleted — orders, customers, addresses, linked-account groups, flags, settings and the stored access token. Nothing is retained for analytics or product improvement.
Requests from shoppers
Shoppers should contact the store they bought from; the merchant is the controller and can raise the request through Shopify, which passes it to DupeGuard automatically. DupeGuard implements all three of Shopify’s mandatory privacy webhooks:
- Data request — the merchant is given everything DupeGuard holds about that shopper, so they can pass it on.
- Shopper deletion — that shopper’s personal data is deleted. Where an order record is kept for the store’s own accounting, it is detached from the person first, so it no longer identifies anyone.
- Store deletion — everything held for that store is deleted, as described above.
A shopper who would rather approach DupeGuard directly can write to the address below, though the merchant will usually need to be involved to confirm who the request concerns.
Changes
If this policy changes materially, the date at the top of this page changes with it and merchants with the app installed are notified.
Contact
DupeGuard is operated by Silver Shark OÜ, registry code 14520447, registered at Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 10151, Estonia.
Questions about this policy, or a request relating to your data: info@silvershark.com.