Legal
Privacy Policy
Last updated: September 27, 2026
1. Who we are
Linesman is a Shopify app operated by Giorgi Mazm (Germany). Contact: [email protected].
For shopper data, the merchant who installs Linesman is the controller and we act as their processor. For the merchant’s own account data, we are the controller.
2. What Linesman does
Linesman detects automated (bot) checkouts, card-testing attempts and fake customer accounts on a merchant’s Shopify store. It can block suspicious checkouts at the payment step (only when the merchant turns blocking on), and it helps the merchant find and delete fake customer records.
3. Data we process for merchants
- Customer email, phone and shipping address (from checkouts, orders and new customers). We use them to spot bot patterns, for example disposable email domains or the same address used with many emails within an hour. We store them only as salted one-way hashes, plus a masked email such as
sa***@gmail.comso the merchant can recognise an entry. We never store them in readable form. - Customer names. Checked only for placeholder names such as “John Doe”. We store the result (yes or no), never the name.
- Order, checkout and customer IDs from Shopify, to link events and run the cleanup the merchant asks for.
- Merchant account data: the store domain, plan, staff and contact emails for alerts, and settings.
- A Klaviyo API key, only if the merchant connects Klaviyo. It is encrypted (AES-256-GCM).
We never receive or store payment card data. We never sell data, and we don’t use it for advertising or to train models.
4. The storefront Shield
When the merchant enables the Linesman app embed, a small script checks, after the shopper’s first interaction, whether the browser behaves like a person. It sets no cookies and reads no personal data. It keeps a short-lived check token in the browser’s session storage and adds it to the cart as an attribute. The shopper’s IP address is used only for rate limiting, as a salted hash that is deleted after 60 seconds.
5. Where data is stored and who processes it
Our database and queue are hosted in the United States (Railway, US West). Subprocessors:
- Railway: hosting, database and queue.
- Resend: emails to the merchant (alerts and summaries). Shoppers never receive email from us.
- Klaviyo: only if the merchant connects it. We send the emails of profiles the merchant chose to suppress to the merchant’s own Klaviyo account.
6. How long we keep data
- Checkout scores (hashes, masked email, decision): 90 days.
- Suspicious-customer flags: 180 days.
- Attack history and usage analytics (no customer data): about 13 months.
- Raw Shopify checkout events: at most 10 minutes, deleted right after scoring. Webhook receipts: 7 days.
- Merchant account data: until the app is uninstalled. Shopify then asks us to erase the store’s data, and we delete it.
7. Your rights
Shoppers who want to access or delete their data should contact the store they bought from. The merchant’s request reaches us through Shopify’s privacy webhooks, and we answer or erase within the required time. Merchants can contact us directly at [email protected].
8. Security
- Customer identifiers are hashed before they are stored; logs contain no personal data.
- Secrets are encrypted at rest; all traffic uses TLS.
- Access is limited to the operator, with two-factor authentication on every system.
- We have a written incident response plan and notify affected merchants without undue delay.
9. Changes
If this policy changes in a way that matters, we’ll update the date above and tell merchants inside the app.