Privacy Policy

Last updated: 3 October 2026.

CardIntel: BIN & Prepaid Tags (“we”, “the app”) provides a Shopify app that tags orders using card BIN metadata and, if you leave the setting on, appends a card verification report to the order note (Shopify’s order note Timeline cannot show line breaks, so the report is one line). This notice describes our processing of merchant and shop data. It is not legal advice and is not a substitute for review by licensed counsel in your jurisdiction.

Roles

You (the merchant) are the controller of your store, orders, and buyers. Shopify is the platform that hosts checkout, Admin, and Billing. We process shop-install data as an independent controller of that limited dataset, and we process order fields only as needed to tag orders and, when enabled, append a verification report to the order note in your Shopify Admin (those tags and notes then live in Shopify under your control).

We do not have a direct consumer relationship with your buyers. We do not sell personal data.

What we store

What we read and do not persist in our database

On Shopify’s orders/create webhook and during install audit / re-check we read, in application memory:

We do not store PAN, CVV, cardholder name, email, phone, or street address in our database. We do not log GDPR webhook bodies that may contain email or phone. The verification report (brand, issuer, card type, category, issuer country, card usage) is written only to the Shopify order note; we do not keep a copy in our database. We do not write the BIN or full card number. Shopify’s order note Timeline cannot show line breaks, so the report is stored as one line.

Operational logs may include shop domain and order GraphQL id (for example when tagging or note update fails). Those logs are for running the service, not a customer profile store. Retention depends on our hosting setup.

Tags and notes we write stay on the order in your Shopify shop until you or another app remove them. You can turn notes off in App Home.

Cookie

During install we set a short-lived first-party cookie (shopify_oauth_state, about 10 minutes) to protect the OAuth handshake. It is not an advertising cookie.

Shared BIN table

Issuer lookup uses a shared card_bin table (brand, type, country, and similar). It is reference data, not a merchant or buyer file.

Processors and transfers

We use Shopify APIs (including Billing). We host the app and database on infrastructure we operate or rent. Data may be processed outside your country because Shopify and hosting providers operate globally. We do not use the BIN data to market to buyers.

Shopify compliance webhooks

Retention

API credentials are kept while the app is installed and wiped on app/uninstalled (and again on shop/redact). Aggregates and domain may be kept until deletion is required or we no longer need them for operations.

Your rights

Depending on where you are, you may have rights to access, correct, or delete personal data we hold about you as a merchant (typically the shop domain and subscription metadata). Use the contact below. Buyers should contact you or Shopify for order data; we do not keep a buyer database.

Contact

Email support@card-intelligence.com.

Operator name: CardIntel: BIN & Prepaid Tags.

We may update this page. The “Last updated” date will change. Continued use of the app after an update means you have read the new notice.

Terms of Service