DisputeShield

Security

Last updated: June 29, 2026

DisputeShield uses Shopify authentication, verified platform communication, store-aware access boundaries, and careful issue monitoring to help protect merchant workflows.

Overview

This page summarizes the security practices DisputeShield uses to help protect merchant workflows. It is not a certification, audit report, or guarantee of absolute security.

DisputeShield is built for Shopify merchants, so our controls focus on authenticated access, verified platform communication, store-aware boundaries, careful issue monitoring, and limiting unnecessary exposure of merchant and customer data.

Shopify authentication

DisputeShield uses Shopify authentication to confirm that people using the app are connected to an authorized merchant account before showing store information.

  • Merchant workspaces are loaded only after Shopify authentication checks succeed.
  • Requests that cannot be tied to authorized Shopify access are rejected.
  • Account and store context is applied only after access has been confirmed.
  • Shopify access is maintained through approved app flows.

Platform event verification

Shopify can send important store and account events to DisputeShield. The app checks those events before using them in merchant workflows.

  • Platform events are checked for authenticity before processing.
  • Unexpected or incomplete platform events are not accepted as normal workflow input.
  • Privacy-related platform events are minimized to the information needed to handle the request.
  • When a merchant uninstalls the app, DisputeShield starts the account cleanup steps tied to that uninstall event.

Store access boundaries

DisputeShield keeps each merchant workspace tied to the Shopify store connected to the authenticated account.

  • The app confirms merchant and store access before showing protected information.
  • Requests are denied when the merchant or store context cannot be confirmed.
  • Store selection is handled through protected app controls rather than editable page state.
  • Access checks help prevent users from viewing stores outside their authorized merchant context.

Shopify permissions

DisputeShield asks Shopify for the permissions needed to support order review, dispute workflows, customer context, product context, payment dispute information, legal policy review, and order updates.

A merchant's Shopify approval controls what store data the app can access for that store.

Access protection

DisputeShield handles Shopify access on trusted application infrastructure and avoids placing sensitive service credentials in public app code.

We do not claim a specific security certification on this page unless that program is in place and documented.

Data minimization and redaction

DisputeShield includes safeguards designed to reduce the amount of sensitive data used in analytics, issue monitoring, privacy request handling, and support views.

  • Product analytics is designed to exclude common sensitive fields such as credentials, contact details, addresses, and platform verification details.
  • Product analytics avoids sending direct merchant identifiers where less identifying references can be used instead.
  • Support views are designed to mask sensitive customer, address, payment, and attachment details where that information is not needed.
  • Operational data is redacted for common sensitive fields before it is used in support or service workflows.

Logs and issue monitoring

Logs and issue-monitoring records help us troubleshoot issues, monitor service health, and investigate security events. We use monitoring tools carefully and try to avoid sending sensitive merchant, customer, credential, address, and payment data into analytics or error-reporting systems.

  • Product analytics is only sent when analytics is enabled.
  • Error reports are limited to information needed to understand and fix service issues.
  • Operational records may still include technical information needed to troubleshoot service issues.

Rate limits and abuse controls

DisputeShield includes abuse controls for public verification flows and sensitive app actions. These controls help reduce automated misuse, but they are not a substitute for protecting merchant accounts and Shopify admin access.

  • Public verification flows include rate-limiting controls to reduce repeated automated attempts.
  • The app checks submitted information before using it in protected workflows.
  • The terms of service prohibit attempts to bypass access controls, rate limits, or security protections.

Third-party services

DisputeShield works with service providers that help run the app, deliver Shopify workflows, process billing, report errors, analyze product usage, or support merchant-requested integrations.

Those providers operate under their own security programs, terms, and privacy commitments. Merchants should review any connected provider before enabling an integration.

Merchant responsibilities

Security is shared. DisputeShield protects the app workflow, while merchants remain responsible for the Shopify store, staff access, connected services, and the accuracy of data submitted through the service.

  • Protect Shopify admin accounts with strong passwords and multi-factor authentication where available.
  • Limit app and integration access to staff who need it for their role.
  • Review connected apps and remove access when a staff member or vendor no longer needs it.
  • Keep business policies, support contacts, and dispute evidence accurate and authorized for use.
  • Report suspected unauthorized access promptly.

Security reports

If you believe you found a security issue, contact us at support@usedisputeshield.com with enough detail for us to understand and reproduce the concern.

Please avoid destructive testing, privacy-invasive testing, social engineering, denial-of-service attempts, or accessing data that does not belong to you.

Changes to this page

We may update this Security page as the product, infrastructure, integrations, or security practices change.

When security claims change materially, we will update the date on this page so merchants can review the latest version.