Privacy Policy
1. Introduction
Dispute Defense for Stripe ("we", "us", "our") provides an automated dispute response and evidence compilation application for merchants utilizing Stripe. This Privacy Policy describes how we collect, use, and protect data when you install and use our Stripe App extension and Cloudflare Workers API backend.
2. Information We Collect
To compile evidence packages and respond to chargebacks on your behalf, we access and process data strictly limited to the permissions you grant in your Stripe Dashboard:
- Dispute Metadata: Dispute ID, disputed amount, currency, chargeback reason, dispute status, and bank response deadlines.
- Transaction & Customer Records: Stripe Charge IDs, customer billing email addresses, billing names, and invoice references.
- Card & Security Checks: Stripe Radar risk scores, CVC verification checks, and 3D Secure authentication outcomes.
3. How We Use Your Information
We process merchant and customer data solely for the purpose of:
- Generating factual, customized AI rebuttal text tailored to specific dispute reasons.
- Formatting and rendering Service Documentation and Receipt PDFs for submission to Stripe and issuing banks.
- Displaying dispute case statuses and evidence verification in the merchant dashboard.
We do NOT:
- Collect, access, or store credit card numbers, CVVs, or full payment credentials.
- Access or initiate payouts, bank account modifications, or transfers.
- Sell, rent, or monetize your or your customers' data to third parties.
- Use your data to train public artificial intelligence models.
4. Data Storage & Security
- In-Isolate Execution: All data processing runs within ephemeral Cloudflare V8 worker isolates.
- Encryption: All data in transit is encrypted using TLS 1.3. Evidence PDF artifacts stored in Cloudflare R2 are encrypted at rest with AES-256.
- Data Isolation: Multi-tenant database records in Cloudflare D1 are strictly segmented by merchant account ID.
- PII Sanitization: Customer emails and sensitive credentials are automatically sanitized prior to AI prompt generation.
5. Contact & Data Deletion Requests
For privacy inquiries, GDPR/CCPA data requests, or to request complete deletion of your merchant account data:
Email: dispute.defense@outlook.com