> For the complete documentation index, see [llms.txt](https://fraud-block-ip.labxapp.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://fraud-block-ip.labxapp.com/policy/privacy-policy.md).

# Privacy Policy

How LabX Fraud Filter collects, uses, and protects data.

Last updated: August 2026

LabX Fraud Filter ("the app", "we") is a fraud-prevention app for Shopify merchants. This policy explains what data the app processes, why, and how you or your customers can exercise your rights over it.

## Information we collect

### From merchants

When you install the app, we receive standard Shopify OAuth data: your shop's domain, access token, and basic shop details (shop name, contact email, plan). We also store the rules and settings you configure (blocking rules, checkout rules, block page design).

### From your storefront visitors

To evaluate whether a visitor should be allowed, blocked, or redirected, the app processes, for each page load:

* IP address, and IP-derived signals: country, region, ISP/ASN, Tor exit-node status, datacenter/hosting status
* User agent (browser, operating system, device type)
* Referring page and the storefront page requested

This evaluation happens in the visitor's browser and on our server. **Allowed traffic is only ever recorded as an aggregate count** (for the merchant's Analytics dashboard) — no per-visitor record is kept for allowed visits. **Blocked and redirected visits are logged individually** (IP, country, region, ISP, device/browser, page, and timestamp) so the merchant can review and, if needed, correct a mistaken block.

Geolocation lookups are performed against a local, self-hosted database — visitor IPs are never sent to a third-party geolocation service.

### At checkout

When a merchant enables Checkout Protection, the buyer's email, phone, name, shipping/billing country, zip code, or customer tags may be checked against the merchant's rules. This evaluation runs as a Shopify Function on Shopify's own infrastructure. **The app does not receive, transmit, or store this checkout data** — the Function only returns an allow/block decision to Shopify.

### On signup forms

When a merchant enables disposable-email blocking, an email address typed into a newsletter/signup form is checked against a list of known disposable-email domains **entirely in the visitor's browser**. The email address is never sent to our servers for this check.

## How we use information

* To evaluate and enforce the fraud rules the merchant has configured
* To show the merchant their own Analytics dashboard and visitor log
* To operate, secure, and improve the app
* To communicate with the merchant about their account, billing, or material changes to the app

We do not sell personal data, and we do not use storefront visitor data for advertising or marketing purposes.

## How we share information

* **Shopify** — as required to operate the app on Shopify's platform
* **The merchant** — blocked-visitor details and analytics are shown to the merchant who installed the app on their own store, as the direct purpose of the app
* We do not sell or rent personal data to any other third party

## Data retention

Merchant configuration and blocked-visitor records are retained for as long as the app is installed, so the merchant can review fraud activity over time. If a merchant uninstalls the app, associated data is retained only as long as reasonably necessary before deletion, or deleted sooner at the merchant's request.

## Your rights

Depending on your location, you may have the right to:

* Be informed about what personal data we hold
* Access the personal data we hold about you
* Correct inaccurate personal data
* Request erasure of your personal data, subject to any legal or fraud-prevention retention requirements
* Receive your data in a portable format
* Restrict or object to certain processing

The app also honors Shopify's mandatory data-protection webhooks (`customers/data_request`, `customers/redact`, `shop/redact`), so a data or deletion request submitted through Shopify is automatically routed to us.

To exercise any of these rights, contact us using the details below.

## Contact

Questions or requests about this policy or your data can be sent to **<info@shop-wil.com>**.
