OrderVet
ScreenWatchlistRulesDecisionsEvidenceConnections

Privacy Policy

How OrderVet collects, uses, and protects data. Last updated: August 27, 2026.

1. Who we are & our role

OrderVet (“OrderVet,” “we,” “us”) is an order fraud-screening service for online merchants. When a merchant connects their store, we process that store’s order and customer data on the merchant’s behalf and under their instructions — the merchant is the data controller and OrderVet acts as their data processor. This policy explains what we process and how we protect it. For requests about a specific order, customers should contact the merchant they purchased from; you may also contact us at support@murraymovementlabs.com.

2. Data we process

To screen an order for fraud, we read only what that transaction contains:

  • Buyer and cardholder name
  • Email address and phone number
  • Billing and shipping addresses
  • Order IP address
  • Order value, currency, and line items
  • Card BIN (the first 6–8 digits only) and the gateway’s AVS/CVV match results
  • The buyer’s prior-order count with that same store (a trust signal)

We never receive or store full card numbers or CVV codes. The payment gateway returns only pass/fail match indicators, never the underlying values.

If the merchant installs our optional checkout beacon, it collects coarse, non-identifying device/session attributes (timezone, browser user-agent, screen size, WebGL renderer, touch capability, and an automation flag) to detect bots and spoofed devices. The beacon sets no cookies and performs no cross-site tracking.

3. Why we process it

Solely to screen the transaction for fraud and to help the merchant defend against chargebacks — for example, detecting billing/shipping mismatches, freight-forwarder and reship addresses, disposable emails, card and IP inconsistencies, and cross-order patterns, and assembling chargeback-representment evidence. We do not build consumer profiles, we do not sell or rent data, and we do not use it for advertising or marketing.

4. Subprocessors

We use a small set of service providers to run the service and to perform specific fraud checks. They process data only to provide their function to us and are bound by their own terms; they may not use it for their own purposes. Which fraud-check providers are used depends on the merchant’s configuration.

  • Supabase — database, authentication, and hosting
  • Vercel — application hosting
  • Stripe — subscription billing (processes the merchant’s payment details, not shoppers’)
  • IPQualityScore — IP, email, and phone risk checks (optional)
  • Neutrino — card BIN metadata lookup (optional)
  • Smarty — address verification (optional)
  • Twilio — phone line-type lookup (optional)

5. Retention

We keep data only as long as it serves fraud screening:

  • Cross-order linkage signatures — 90 days
  • Checkout beacons — 3 days
  • Chargeback-evidence records — about 13 months (to cover the dispute lookback window)
  • Screening decisions — retained for the merchant’s dispute file until the merchant deletes them or disconnects

Raw third-party provider responses are discarded after a screen; only the resulting signal and its citation are kept.

6. Security

  • All data is encrypted in transit (HTTPS/TLS) and at rest.
  • Each merchant’s data is isolated by database row-level security — a merchant can access only their own records.
  • Connected-platform credentials are additionally encrypted with AES-256-GCM, with the key held outside the database.
  • Administrative keys are held server-side only; staff access is least-privilege.
  • We maintain a security-incident response process and notify affected merchants promptly.

7. Your rights & data deletion

We honor access and erasure requests. For Shopify stores, the mandatory customers/data_request, customers/redact, and shop/redact webhooks are implemented; equivalent handling applies to other platforms. A merchant can also delete their screening data or disconnect their store at any time, which removes our access. Depending on your location you may have rights under the GDPR, UK GDPR, or CCPA/CPRA; contact the merchant, or us at support@murraymovementlabs.com, to exercise them.

8. International processing

Data is hosted with the providers listed above and may be processed in the United States. We rely on our subprocessors’ safeguards for any cross-border transfers.

9. Changes

We may update this policy; material changes will be reflected by the “last updated” date above and, where appropriate, communicated to connected merchants.

10. Contact

Questions about this policy or our data practices: support@murraymovementlabs.com.

© 2026 Murray Movement Labs LLCPrivacyTerms