Vexor is a Shopify app operated by Pretan Technologies ("we", "us"). It detects bots and AI agents on a merchant's storefront, flags order abuse, and assembles chargeback evidence. This policy explains what we collect from stores that install Vexor, what we do with it, and how long we keep it.
We do not sell data, we do not share it with advertisers, and we do not use one merchant's data to build products for another.
Who is responsible for what
The merchant who installs Vexor is the data controller for their shoppers' personal data. We act as their data processor: we only process what the app needs in order to work, and only on that merchant's behalf.
What Vexor collects
Storefront visitors
When a merchant enables the Vexor Sentinel app embed, a small script runs on their storefront and sends us signals about each visit. Specifically:
| Data | Stored as | Why |
|---|---|---|
| IP address | Irreversible salted hash. The raw address is never written to our database. | Linking visits and orders from the same network |
| Browser and device characteristics (user agent, screen size, language, time zone, graphics renderer) | User agent in full; the rest combined into a non-reversible fingerprint hash | Detecting headless browsers, automation tools and AI agents |
| Behaviour on the page (page views, scrolling, mouse movement and keyboard counts, timing, add-to-cart and checkout events) | Counts and timings only, never keystroke content | Telling humans from scripts |
| A random visitor ID | Stored in the visitor's browser and in our database | Recognising the same visitor across pages |
| Country | Country code only | Traffic reporting |
The script sets no advertising or tracking cookies, follows shoppers across no other sites, and collects no names, email addresses, payment details or form contents.
Orders
With the merchant's permission, Shopify sends us each new order after installation. We keep a reduced copy: order number and total, currency, discount codes used, line item titles and quantities, fulfilment and tracking details, billing and shipping country, the Shopify customer ID, and the payment status. Email addresses and street addresses are stored only as irreversible hashes, which lets us spot the same buyer or address without holding the values themselves.
We do not request or store payment card numbers. Shopify never shares them with apps.
Chargebacks
When a Shopify Payments dispute opens, we store its amount, reason, status and deadline so the merchant can assemble evidence from the order history they already hold.
Merchant account
We store the store domain, the plan chosen, app settings, an access token issued by Shopify, and an optional alert email address supplied by the merchant.
What we never collect
- Raw IP addresses (hashed before storage)
- Shopper names, email addresses or street addresses in readable form
- Payment card or bank details
- Anything a shopper types into a form
- Browsing activity on sites other than the merchant's storefront
How long we keep it
- Visitor sessions and detections: 90 days, then deleted.
- Order and chargeback records: for as long as the app is installed, because abuse rules compare new orders against earlier ones.
- After uninstall: Shopify sends us a shop redaction request 48 hours later, and we delete everything belonging to that store, including access tokens.
- On a customer erasure request: Shopify notifies us and we erase that customer's records within 30 days, as the law requires.
Who we share data with
We use a small number of service providers, each bound to process data only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | Frankfurt, EU |
| Supabase | Database | Frankfurt, EU |
| Resend | Alert emails to merchants | United States |
| Shopify | The platform the app runs on | Per Shopify's own terms |
Pretan Technologies is based in Zimbabwe, so data processed by us may be accessed from there. Transfers out of the EEA and UK rely on the European Commission's Standard Contractual Clauses.
Rights of shoppers
Shoppers should contact the store they bought from, since that merchant controls their data. When a merchant passes on a request through Shopify, we act on it: access requests are answered with the records we hold, and erasure requests remove them. Merchants can also email us directly at support@vexorzw.com.
Security
Data is encrypted in transit and at rest. Access tokens and identifiers are stored in a database that is not publicly reachable, and every request from a storefront is verified as genuinely signed by Shopify before we accept it.
Changes
If we change this policy in a way that affects what we collect, we will email the address on the merchant's Shopify account before the change takes effect.
Contact
Pretan Technologies, Harare, Zimbabwe — support@vexorzw.com