GuardPanda · Merchant resources
Privacy Policy
Last updated: September 27, 2026
This policy explains how GuardPanda handles information when merchants install and use its Shopify dispute-evidence workspace.
1. Who operates GuardPanda
GuardPanda is operated by 徐敏学 (Minxue Xu), an individual based in China. Contact x17661959@gmail.com for privacy questions or requests. GuardPanda is an independent application, not Shopify, a bank, a payment processor, or a law firm.
For customer information supplied by a merchant, we process information on the merchant’s instructions to provide the service. The merchant remains responsible for its customer notices and lawful use of that information. We are responsible for our own account administration, security, and support records.
2. Information we process
Depending on the permissions granted, we read store identifiers, order and customer identifiers, order dates and values, product information, refund and payment transaction records, fulfillment and tracking information, order notes, and staff comments on the order Timeline. We may read customer names, shipping addresses, and order IP addresses where access is authorized. We retain snapshots of available product details and published store policies.
Payment evidence can include masked card details and AVS/CVV verification results provided by Shopify. We do not request full card numbers or actual card security codes. Do not upload these values. This application does not collect a device fingerprint.
We also process evidence files and text uploaded by merchants, case details, deadlines, review and submission records, merchant-recorded outcomes, account sessions, operational logs, and messages sent to support. Uploaded material may contain additional personal information chosen by the merchant.
3. Why we use information
We use information to authenticate merchants, synchronize accessible orders, preserve source versions, organize disputes, prepare PDF evidence packages, display merchant-recorded outcomes, resolve support requests, prevent unauthorized access, and fulfill privacy and legal obligations. We do not use customer information for advertising or sell it.
Access is limited to the store associated with the authenticated session. The app does not automatically submit an evidence package to a bank or payment provider. A merchant chooses whether and where to submit an exported file.
4. Service providers and international processing
AWS hosts the application and database in the United States (Ohio). Operational infrastructure may also use AWS content delivery and logging services. The operator is based in China, and authorized support access may occur from China. Using the service can therefore involve cross-border processing.
When shipment enrichment is enabled, tracking numbers are sent to 17TRACK to retrieve carrier events. When IP enrichment is enabled, an order IP address is sent to IPinfo over HTTPS to obtain country-level and network information. IPinfo Lite does not provide a verified street address or city. These services are used to provide the requested features, not for advertising.
Shopify supplies the underlying order data and handles installation and authentication. We may also disclose information to authorized service providers needed for hosting and support, where required by law, or to protect the service. Where applicable law requires a transfer mechanism or additional agreement, it must be in place before the affected processing occurs; use of the app alone is not a substitute for it. See the Data Processing Terms for the current provider list.
5. Retention, uninstalling, and deletion
Order snapshots, cases, uploaded evidence, and exports are retained while needed for the merchant’s use of the installed application. The current service does not automatically remove active case records after a fixed age. Merchants can request deletion by contacting us.
Uninstalling revokes app access, removes application sessions, and stops new synchronization. Uninstalling is not itself an immediate deletion of every stored record. When Shopify delivers its shop-redaction request, the app removes the store’s live workspace, related evidence, and sessions. Customer deletion requests are tracked for processing; linked records are removed or redacted and unlinked material is subject to manual review.
Minimal identifiers may remain while necessary to prevent deleted customer data from being imported again and to document request handling. Logs and isolated backup copies may remain until their applicable retention periods expire. We review relevant copies and service-provider records when handling a deletion request. Contact us for information about a particular request. Files already downloaded by a merchant or sent to a bank remain under that recipient’s control.
6. Security and browser storage
The app uses Shopify authentication, store-scoped access checks, HTTPS, and verification of Shopify webhook signatures. No security measure eliminates all risk. We investigate reported incidents and notify affected parties as required by applicable law.
The embedded production app uses Shopify session-token authentication. Shopify and hosting services may process technical connection information. A separate local demonstration uses a session cookie and fictional records; that demonstration is disabled in production.
7. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to processing, obtain a copy of your data, or complain to a relevant supervisory authority. Customers should normally contact the merchant they purchased from, which controls the order. We assist the merchant with appropriate requests and verify identity before disclosure or deletion.
Send requests to x17661959@gmail.com with the store domain and the nature of the request. Do not include passwords, access tokens, full card numbers, or card security codes. We respond within the time required by applicable law. Merchants can stop further access by uninstalling the app.
8. Changes
We update this policy when our service or practices change. The date on this page identifies the current version. Material changes will be communicated through the app or available merchant contact channels where required.