Back to InboundCheck
Zero-PII Verified
Enterprise Privacy Standard

Privacy Policy

Effective Date: September 2026 • Version 3.1

1. Zero-PII Storage Architecture

InboundCheck is engineered from the ground up for strict data minimization. We do not store, harvest, or monetize your end customers’ Personally Identifiable Information (PII). When processing Shopify transactional order notifications or webhook events:

  • Customer email addresses are pseudonymized or hashed in memory.
  • Credit card numbers, payment tokens, and billing addresses are never ingested or transmitted to our servers.
  • Customer physical mailing addresses and private purchase items are strictly filtered prior to telemetry analysis.

2. DNS Telemetry & Deliverability Data Collected

To provide multi-resolver DNS audit services and spam filter diagnostics, InboundCheck collects and processes:

  • Public DNS Records: SPF TXT records, DKIM public key selectors, DMARC policy alignment, MX routing hosts, and BIMI certificates.
  • Reputation & Blacklist Logs: Public DNSBL / RBL index status across Spamhaus, Barracuda, SpamCop, and related authoritative reputation databases.
  • Merchant Account Information: Merchant contact email, business name, Shopify myshopify.com domain, and billing subscription identifiers (managed via Stripe).

3. DNS API Provider Credentials

When you opt to connect Cloudflare or GoDaddy credentials for 1-click automated DNS remediation:

  • API tokens and secret keys are encrypted at rest using AES-256 / Fernet envelope cryptography.
  • Keys are never exposed in user-facing client state and are masked in transit (••••••••••••••••).
  • Credentials are used solely to inject or rollback DNS records explicitly confirmed by the merchant.

4. GDPR, CCPA & International Compliance

In accordance with the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):

  • Right to Deletion: Merchants can remove any monitored domain or request complete tenant account termination anytime via the dashboard.
  • Cryptographic Multi-Tenancy: All database queries are isolated with Supabase Row-Level Security (RLS) enforcing auth.uid() = user_id.
  • Sub-processors: We utilize SOC-2 Type II certified sub-processors including Supabase (PostgreSQL hosting), Stripe (PCI-DSS Level 1 payment processing), and Cloudflare (edge delivery).

5. Contact Our Privacy Officer

If you have any questions regarding our zero-PII commitment or data processing policies, contact our privacy engineering team directly at: privacy@inboundcheck.com