LEGAL
Data Processing Terms
Last updated: August 3, 2026
1. Parties and acceptance
These terms form a data processing agreement between the merchant using WCT Platforms (the Controller) and WCT Consulting AB, Swedish organization number 559593-7110 (the Processor). By installing, authorizing or using ChargebackBot or another WCT Platforms product, the merchant instructs WCT Consulting AB to process data as described here.
2. Instructions and purpose
WCT Consulting AB processes data only on documented merchant instructions to provide, secure and support the enabled service. For ChargebackBot this includes matching disputes to orders, reading fulfillment and tracking information, verifying delivery, coordinating proof of delivery and maintaining an operational audit trail. Data is not sold or used for advertising.
3. Data and data subjects
The service is designed to minimize data. It may process merchant staff identifiers, order and dispute identifiers, order numbers, fulfillment and shipment tracking data, proof-of-delivery metadata, connected-service references and technical logs. ChargebackBot does not require customer names, postal addresses, email addresses or telephone numbers.
4. Confidentiality and security
Access is limited to authorized personnel and systems. WCT Consulting AB uses access controls, encrypted network connections, restricted service credentials, encrypted Shopify installation tokens, validation, logging and managed infrastructure protections appropriate to the risk.
5. Subprocessors
The merchant authorizes infrastructure and integration providers required for the configured workflow, which may include Render, Supabase, Shopify, Re:amaze, Discord and shipment-tracking services. WCT Consulting AB remains responsible for its processor obligations and will use providers subject to appropriate contractual protections.
6. Retention and deletion
Completed ChargebackBot case and tracking records are retained for no more than 12 months after their last update. Technical job-run records are retained for 90 days. Completed privacy-request audit records are retained for 30 days. Expired OAuth state records are deleted automatically. Temporary proof-of-delivery files are transferred in memory and are not intentionally retained by WCT Platforms. Active in-transit cases remain until resolved or deleted on merchant instruction.
7. Individual rights and merchant assistance
WCT Consulting AB will assist the merchant with authorized access and deletion requests. Shopify privacy webhooks are authenticated, recorded with the minimum identifiers required and used to delete matching order or shop data where applicable.
8. Deletion and return
On termination or valid merchant instruction, WCT Consulting AB will delete or return personal data unless retention is required by law. Shopify installation credentials are removed when the app is uninstalled, and shop data is removed following an authenticated shop-redaction request.
9. Incidents and audits
WCT Consulting AB will notify affected merchants without undue delay after becoming aware of a personal-data breach relevant to the service and will provide information reasonably necessary to demonstrate compliance with these terms.
10. Contact
WCT Consulting AB · Org. no. 559593-7110 · Sweden
support@wctplatforms.se
