Last updated: 3 October 2026.
CardIntel: BIN & Prepaid Tags (“we”, “the app”) provides a Shopify app that tags orders using card BIN metadata and, if you leave the setting on, appends a card verification report to the order note (Shopify’s order note Timeline cannot show line breaks, so the report is one line). This notice describes our processing of merchant and shop data. It is not legal advice and is not a substitute for review by licensed counsel in your jurisdiction.
You (the merchant) are the controller of your store, orders, and buyers. Shopify is the platform that hosts checkout, Admin, and Billing. We process shop-install data as an independent controller of that limited dataset, and we process order fields only as needed to tag orders and, when enabled, append a verification report to the order note in your Shopify Admin (those tags and notes then live in Shopify under your control).
We do not have a direct consumer relationship with your buyers. We do not sell personal data.
example.myshopify.com).On Shopify’s orders/create webhook and during install audit / re-check we read, in application memory:
We do not store PAN, CVV, cardholder name, email, phone, or street address in our database. We do not log GDPR webhook bodies that may contain email or phone. The verification report (brand, issuer, card type, category, issuer country, card usage) is written only to the Shopify order note; we do not keep a copy in our database. We do not write the BIN or full card number. Shopify’s order note Timeline cannot show line breaks, so the report is stored as one line.
Operational logs may include shop domain and order GraphQL id (for example when tagging or note update fails). Those logs are for running the service, not a customer profile store. Retention depends on our hosting setup.
Tags and notes we write stay on the order in your Shopify shop until you or another app remove them. You can turn notes off in App Home.
During install we set a short-lived first-party cookie (shopify_oauth_state, about 10 minutes) to protect the OAuth handshake. It is not an advertising cookie.
Issuer lookup uses a shared card_bin table (brand, type, country, and similar). It is reference data, not a merchant or buyer file.
We use Shopify APIs (including Billing). We host the app and database on infrastructure we operate or rent. Data may be processed outside your country because Shopify and hosting providers operate globally. We do not use the BIN data to market to buyers.
customers/data_request — no-op. We have no customer rows to return.customers/redact — no-op. We have no customer rows to delete.app/uninstalled — we delete the access token, refresh token, scopes, and subscription id so a later reinstall must authenticate again. Daily counters and install-audit status stay.shop/redact (about 48 hours after uninstall) — we wipe those credentials again if anything remains, and mark the shop redacted. The shop domain, last plan status, daily counters, and install-audit status stay so we can understand churn and billing history. That means uninstall plus shop/redact is not full erasure of the shop record. Email us if you need remaining shop records deleted; we will handle requests as required by applicable law. A later install on the same domain stores a new token.API credentials are kept while the app is installed and wiped on app/uninstalled (and again on shop/redact). Aggregates and domain may be kept until deletion is required or we no longer need them for operations.
Depending on where you are, you may have rights to access, correct, or delete personal data we hold about you as a merchant (typically the shop domain and subscription metadata). Use the contact below. Buyers should contact you or Shopify for order data; we do not keep a buyer database.
Email support@card-intelligence.com.
Operator name: CardIntel: BIN & Prepaid Tags.
We may update this page. The “Last updated” date will change. Continued use of the app after an update means you have read the new notice.