What Verifai reads from a customer's order, why, and how long it stays — written for merchants, their customers, and anyone reviewing this app.
Every claim below is read off what the code actually does — the retention window, the vendors, the compliance webhooks — not boilerplate copied from a template. If a data practice changes, this page changes with it.
Verifai is a Shopify app that automatically checks cash-on-delivery (COD) orders for common fraud and delivery-risk signals — an invalid phone number, a mistyped email, an incomplete address, a duplicate order — and tags each order Verified or Manual Review so a merchant only has to look at the orders that actually need a human decision.
To check an order, Verifai reads the following from the order Shopify sends us:
This is the same customer information already visible on the order inside Shopify Admin — Verifai does not collect anything a customer was not already asked for at checkout.
Prepaid orders are counted for totals but no personal data is stored for them at all: counting an order does not require knowing who placed it.
Every field above feeds one or more automated checks — phone validity, email deliverability, address completeness, whether the delivery IP is near the shipping address, whether this looks like a duplicate order, and this customer's past order history with this store. None of it is used for marketing, sold, or shared with any party beyond what's described below.
The IP address is located using a database hosted inside Verifai's own infrastructure. It is never sent to a third-party geolocation service.
A merchant can optionally connect their own account with the following vendors, to move some checks from free, offline detection to a live, paid lookup. Each is only contacted if the merchant has entered their own credentials for it in Settings — nothing is sent to any of them by default.
Vendor credentials a merchant enters are encrypted at rest (AES-256-GCM) and are never shown again in full once saved. Results from these lookups are cached for 90 days under a one-way hash of the phone number or email address — never the value itself — so the cache can never become a second, unpurged copy of a customer's contact details.
Personal data tied to an order (name, phone, email, address, IP) is automatically erased after 180 days. The purge runs on a schedule inside the app every 12 hours; it does not depend on anyone remembering to run it. The verdict itself — whether the order was Verified, held for review, or flagged high-risk, and why — is kept afterwards as part of the store's own operating history, with the personal data already stripped out of it.
Verifai supports Shopify's mandatory customer-privacy webhooks:
Questions about this policy or how your data is handled — reach us at [email protected].
Verifai is built and operated by TechnoBrains Business Solutions LLP.