1. Who we are
Tenpenny Software is a sole proprietorship and the developer of Argumentum, a Shopify app listed under the Shopify Partner Program. Tenpenny Software’s mailing address is PO Box 672, Zillah, Washington 98953, United States. When a merchant installs Argumentum on their Shopify store, Tenpenny Software processes certain information from that store — described below — solely to provide the App’s dispute-documentation features to that merchant.
2. Scope of this policy
This policy covers the information Argumentum collects and processes through its integration with a merchant’s Shopify store — via Shopify’s Admin API, webhooks, and the App itself. It does not cover Shopify’s own collection and use of information as the operator of the Shopify platform; that is governed by Shopify’s own Privacy Policy. It also does not cover any other app or service a merchant may use.
Argumentum is an embedded admin tool used by a merchant’s own staff. Most of the information described below relates to a merchant’s store, orders, and customers — not to the merchant’s personal information as an individual, except where a member of the merchant’s team interacts with the App directly (for example, an account holder’s contact email, or notes a staff member types into the App).
3. Information we collect
We collect information from Shopify (via the Admin GraphQL API and webhooks Shopify sends us once a merchant installs the App and grants the requested access scopes), information a merchant enters directly into the App, and a small amount of information we derive automatically to help flag weak or missing evidence.
From Shopify, about the merchant’s store
| Category | Examples |
|---|---|
| Shop account details | Store domain, store contact email, currency, and preferred language |
| Orders | Order number, line items, prices and totals, currency, order date, and financial/fulfillment status |
| Customers | Name, email address, and phone number, as recorded on an order |
| Addresses | Billing and shipping addresses as they existed at the time of each order |
| Fulfillments | Carrier, tracking numbers, and shipment/delivery timestamps |
| Disputes | Dispute reason, type, amount, status, evidence deadline, and outcome, as reported by Shopify Payments |
| Purchase IP address | The customer’s IP address at checkout, used only to compute a billing-address/location match signal (see below); not stored alongside other order data beyond that use |
We do not receive or store full card numbers, CVV codes, or similar cardholder authentication data — Shopify and Stripe do not provide that information to apps. Where a dispute or its underlying charge includes limited payment details such as card brand or the last four digits of a card, we may store that as part of the dispute’s evidence record, and use it to suggest — never automatically link — which of a merchant’s orders a dispute likely corresponds to when it doesn’t match automatically; see the “derived automatically” paragraph below.
Entered directly into the App by the merchant
- Communication-log notes — free-text notes a merchant’s staff choose to record about their contact with a customer regarding an order or dispute. These may contain personal information if the merchant chooses to include it.
- Evidence packet edits — narrative text and item-inclusion choices a merchant edits before exporting a dispute evidence packet.
- Uploaded attachments (Standard and Pro plans only) — screenshots or documents a merchant’s staff choose to attach to an order as supporting evidence, such as a screenshot of a delivery confirmation or a customer conversation. These are appended to that order’s exported evidence-packet PDF and may contain personal information if the merchant chooses to include it; unlike the Shopify-sourced data above, this content does not come through Shopify at all. Uploaded images have identifying metadata (such as GPS location and device information) automatically removed before storage — see Section 8.
- Settings — a merchant’s email-alert and IP-geolocation-lookup preferences (see Section 9).
Derived automatically
To help flag when a dispute is missing strong evidence, we compute a small number of automated signals from the data above — for example, whether a customer’s purchase IP address appears to be located near their billing address (using a third-party IP geolocation lookup — see Section 6), whether an order is missing shipping tracking or a communication-log entry, whether a dispute captured from a merchant’s connected Stripe account may describe the same real-world event as a separate dispute already on the same order (so the merchant can check, rather than treat two records as automatically duplicate or automatically distinct), and, for a dispute that doesn’t automatically match one of the merchant’s orders, which orders it might correspond to based on amount, currency, card details, and order date. These signals are shown to the merchant as readiness indicators or suggestions requiring the merchant’s own confirmation; they are heuristics intended to help a merchant prepare stronger evidence or find the right order, not automated decisions made about a customer, and we never link a dispute to an order, or treat two dispute records as the same or different, without the merchant affirmatively confirming it.
4. How we use information
- To detect and track payment disputes as they occur on a merchant’s store.
- To generate a draft evidence packet for each dispute — assembling order, fulfillment, address, communication-log, and (on Standard and Pro plans) uploaded-attachment information into a document the merchant can review, edit, and export before submitting it through Shopify or, at the merchant’s choice, a connected Stripe account (see below).
- To surface readiness indicators (for example, missing tracking or communication records) so a merchant can strengthen a dispute’s evidence before its deadline.
- To send transactional email alerts — a new dispute opening or an approaching evidence deadline — to the store’s contact address.
- To operate, secure, maintain, and troubleshoot the App.
- To respond to data subject requests and comply with legal obligations, including the GDPR-mandated processes described in Section 9.
- To determine and administer the merchant’s subscription plan and usage-based billing through Shopify’s own billing platform (see Section 6) — Tenpenny Software does not separately process payment details for App subscriptions; Shopify bills the merchant directly.
- If a merchant connects their own Stripe account and chooses to submit evidence directly to Stripe from the App (an optional feature, described further in Section 6), to transmit that evidence on the merchant’s explicit, confirmed instruction.
We do not sell personal information, use it for advertising or marketing, or share it with unrelated third parties. We never submit dispute evidence automatically — every evidence packet is reviewed by the merchant first, and nothing leaves the App unless the merchant takes an affirmative export or submit action. Where a merchant connects a payment processor and directs the App to submit evidence to it, that transmission happens only for that specific, explicitly confirmed action — never on a schedule, a deadline, or any other automated trigger.
5. Our role, and our legal basis for processing
With respect to personal information about a merchant’s customers (order and dispute data, addresses, communication-log entries), Tenpenny Software acts as a service provider / data processor on behalf of the merchant, who remains the data controller responsible for their own customers’ personal information. Our processing of that information is governed by our agreement with the merchant (including Shopify’s own API terms) and is limited to what is necessary to provide the App’s dispute-documentation features.
Where data protection law requires a stated legal basis (for example, for individuals in the European Economic Area or the UK), we process personal information on the following bases: performance of our contract with the merchant (providing the App’s core functionality); our and the merchant’s legitimate interests in detecting, documenting, and responding to payment disputes; and compliance with legal obligations, including responding to the data subject requests described in Section 9.
6. Who we share information with
We share information only with the service providers below, each engaged solely to help us operate the App, and only to the extent necessary for the purpose listed. None of them are permitted to use this information for their own independent purposes.
| Provider | Purpose | Information involved |
|---|---|---|
| Neon | Primary database hosting (PostgreSQL) | All information described in Section 3 |
| Cloudflare (R2 object storage) | Storage for exported evidence-packet PDF files and uploaded attachment files (Standard and Pro plans) | PDF files containing order, dispute, and evidence content; uploaded screenshot/document files |
| Postmark | Delivery of transactional alert emails | Store contact email address and alert content |
| ipwho.is | IP geolocation lookup used for the billing-address match signal | Customer purchase IP address only |
| Shopify (Partner API / App Events API) | Reading subscription status and reporting usage for billing | Store identifiers and order-volume usage totals — no customer data |
Our primary database (hosted by Neon, on AWS infrastructure) is located in the AWS US West 2 (Oregon) region. Our other service providers listed above operate their own infrastructure and may store or process information in other locations, including outside the United States.
Payment processors you connect yourself
The table above lists services we chose and engaged to operate the App. Stripe is different: it’s a payment processor you independently choose to use for your own store, and, if you connect it to Argumentum, you do so yourself through Stripe’s own “Connect with Stripe” sign-in — you authorize the connection directly on Stripe’s consent screen, and we never ask you to generate, paste, or hand us a Stripe API key or secret. When you connect Stripe, two things happen only at your explicit direction:
- We read dispute information from your Stripe account so the App can capture and document disputes the same way it does for Shopify Payments disputes.
- If you choose to submit an evidence packet directly from the App (a separate, optional action requiring a further, explicit authorization before anything is sent, and a confirmation before anything is transmitted), we transmit that packet’s content — which may include your customer’s name, email, billing and shipping address, purchase IP address, any communication-log notes you’ve entered, and any attachments (screenshots or documents) you’ve added to the order — to Stripe. The submitted file is the same exported PDF described in Section 3, so an attachment you’ve added is included automatically once it’s part of that PDF; it is not a separate transmission you approve individually.
PayPal support is planned but not yet available. We have built the capability to detect and document disputes on a merchant’s own connected PayPal account, and to submit evidence to PayPal directly (including responding to more than one round of evidence PayPal may request on the same dispute) — the same exported PDF described in Section 3, so it would include any attachments you’ve added the same way a Stripe submission does above — but this feature is switched off pending PayPal’s own approval of Tenpenny Software as an integration partner — an external process outside our control, with no guaranteed timeline. No merchant can currently connect a PayPal account through Argumentum, and until that changes, we do not read from, or transmit anything to, any PayPal account. We will update this policy with the specifics of that connection method before the feature becomes available to any merchant.
We do not consider Stripe (or, once available, PayPal) one of our own sub-processors the way the providers in the table above are: each is your own payment processor account, and once information reaches it, that processor’s handling of the information is governed by your own agreement with it, not by this policy. We list Stripe here for transparency about where your data can go, not because we’ve chosen it on your behalf — nothing is ever sent to Stripe unless you’ve both connected it and taken the specific action to submit.
We may also disclose information where required to do so by law, or to protect the rights, property, or safety of Tenpenny Software, our merchants, or others. If Tenpenny Software is ever involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy the merchant is notified of.
7. How long we keep information
We retain information for as long as the App remains installed on a merchant’s store, so that evidence packets, the readiness dashboard, and dispute history stay accurate and available to the merchant.
For a store that remains installed, we also apply automatic retention limits to personal information, rather than keeping it indefinitely. Once a payment dispute is closed (won, lost, or accepted) and more than 75 days have passed since its evidence deadline, and the underlying order itself is more than 540 days old, we automatically purge the personal information tied to that dispute’s order — the customer’s email address, phone number, billing and shipping address, and purchase IP address — along with any communication-log notes, uploaded attachment files, subscription-cancellation notes, the evidence packet’s narrative text, and any fraud-signal details derived from that information, from our active systems. Both conditions must be met — a closed dispute on a recent order isn’t purged until the order itself also crosses the 540-day mark, since a genuinely new dispute can still arrive on an order until then. Non-personal business records tied to the dispute (its amount, status, and outcome) are retained for our own recordkeeping. If a store has more than one dispute tied to the same order, we defer purging that order’s information until every dispute on it has itself become eligible for purging, so a still-open dispute’s evidence isn’t affected.
Separately, for an order that was never the subject of any payment dispute at all, we purge that order’s personal information once the order itself is more than 540 days old — the same age threshold used above, applied on its own since there’s no dispute-closure event to also wait for.
When a merchant uninstalls the App, Shopify notifies us via its mandatory shop/redact webhook,
and we erase the store’s account and associated data, and delete our copy of any stored access
credentials for that store.
When Shopify notifies us that a specific customer’s personal data must be erased (the
customers/redact webhook, triggered by a customer or merchant request through Shopify), we redact
that customer’s personal details — name, contact information, addresses, and any communication-log
notes or uploaded attachment files tied to their orders — from our records, while retaining non-personal
business records (such as order totals and
dispute outcomes, stripped of identifying detail) where reasonably necessary for financial recordkeeping.
An evidence packet a merchant has already exported and downloaded may continue to exist on the merchant’s own devices or systems, and on Shopify’s own systems once submitted as dispute evidence — those copies are outside our control and not affected by our own retention or erasure processes.
8. How we protect information
- Each store’s Shopify access credentials are encrypted at rest (AES-256-GCM) before being stored — we do not store them in plain text. Connecting Stripe uses Stripe’s own OAuth sign-in, so we never receive or store a Stripe API key or secret from a merchant at all — we hold only Stripe’s identifier for the connected account, which is not a secret on its own, and act on it using our own platform-level Stripe credential.
- Every webhook we receive — from Shopify or Stripe — is cryptographically verified against that sender’s own signature before we process it, so we only ever act on requests genuinely sent by the provider it claims to be from.
- Exported evidence-packet PDFs and uploaded attachment files are stored in a private cloud storage bucket that is not publicly accessible. The only way file contents leave our systems is through an individually generated, short-lived (15 minute) download link issued to an authenticated merchant, or the direct-submission feature described in Section 6.
- Uploaded attachments are validated by inspecting the file’s actual content, not just its name or declared type, and only image (JPEG, PNG, HEIC/HEIF) or PDF files are accepted; any other file is rejected. Uploaded images have identifying metadata (such as GPS location and device information) automatically removed as part of processing them for storage.
- Data is transmitted over encrypted (HTTPS/TLS) connections.
- Every store’s data is isolated from every other store’s data within our database.
- Administrative and automated endpoints are protected with secret-based authentication, rate limiting, and timing-safe comparison to resist brute-force and timing attacks.
- Our database provider (Neon) encrypts stored data and database backups at rest, and restricts production access to least-privilege, role-based access; Neon undergoes annual independent SOC 2 and ISO audits.
- Our cloud storage provider (Cloudflare R2) encrypts every stored file at rest by default; Cloudflare holds SOC 2 Type II and ISO 27001 certifications covering R2.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal information, we will notify affected merchants and take appropriate steps as required by applicable law.
As a developer on the Shopify Partner Program, we’re also subject to Shopify’s own review of how we access and handle data obtained through the Shopify platform, including its protected customer data requirements and periodic compliance reviews.
9. Your rights and choices
For merchants
- Email alerts can be turned off at any time from the App’s Settings page, or via the unsubscribe link included in every alert email.
- IP-geolocation lookup (used only for the billing-address match signal described in Section 3) can be disabled at any time from the App’s Settings page; once disabled, no lookup request is made for that store.
- Uninstalling the App stops all further data collection and, per Section 7, triggers deletion of the store’s stored data.
- Merchants may contact us at any time using the details in Section 14 to ask what information we hold about their store or to request its deletion.
For a merchant’s customers
Because Tenpenny Software acts as a processor on behalf of the merchant (Section 5), a customer wishing to exercise a data protection right — such as a right to access, correct, or delete their personal information — should generally contact the merchant’s store directly, since the merchant controls that relationship. Where such a request is submitted through Shopify (for example, under GDPR or a similar law), we act on it automatically:
- Data access requests — we compile the personal information we hold about the specified customer (profile details, orders, addresses, line items, fulfillments, disputes, and communication-log notes) and send it to the requesting store’s contact email, for the merchant to relay to the customer.
- Data erasure requests — we redact the specified customer’s personal information from our systems, as described in Section 7.
Residents of certain jurisdictions (for example, California) may have additional statutory rights over their personal information. Because we hold customer information only as a processor for merchants, we direct such requests to the relevant merchant where required, but merchants and customers are welcome to contact us directly and we will assist promptly.
10. Cookies and tracking
Argumentum is an embedded application that runs inside Shopify Admin. We do not use advertising cookies, third-party marketing trackers, or behavioral-advertising pixels. The App relies on Shopify’s own session mechanism (App Bridge) to recognize an authenticated member of the merchant’s staff inside Shopify Admin; we do not track merchants or customers across other websites.
11. International data transfers
Tenpenny Software is operated as a sole proprietorship in Washington, United States, and our primary database is hosted in the United States (AWS US West 2, Oregon — see Section 6). Depending on where a merchant and their customers are located, processing personal information through the App may involve transferring it to the United States and to other countries where our service providers listed in Section 6 operate — and, if a merchant connects and uses Stripe’s optional direct-submission feature, to wherever that merchant’s own Stripe account operates. Where applicable data protection law requires it, we rely on appropriate safeguards — such as the Standard Contractual Clauses incorporated into our Data Processing Addendum, available to any merchant who wants a formal document to point to or execute — for these transfers.
12. Children’s privacy
Argumentum is a business tool intended for use by merchants’ staff and is not directed to children. We do not knowingly collect personal information directly from children. Customer data processed through the App originates from a merchant’s own order records, not from any direct interaction with children by us.
13. Changes to this policy
We may update this policy from time to time to reflect changes to the App or to applicable law. We will revise the “Last updated” date above when we do, and where a change is material, we will take reasonable steps to notify merchants (for example, by email or an in-app notice) before it takes effect.
14. Contact us
If you have questions about this policy, want to know what information we hold, or want to submit a request described above, contact us at:
Tenpenny Software
PO Box 672
Zillah, WA 98953
United States
admin@tenpennysoftware.com
This policy describes Tenpenny Software’s handling of information through the Argumentum app only. For Shopify’s own data practices as the platform operator, see Shopify’s Privacy Policy. See also our Terms of Service and Data Processing Addendum.