Privacy Policy
1. Introduction
2. Definitions
- Affiliate means an entity that controls, is controlled by or is under common control with the Company, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Chargebackhit (referred to as either "ChargebackHit", "CBH", "Company", "We", "Us" or "Our" in this Agreement) refers to ChargebackHit affiliates.
- Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Country refers to: Republic of Cyprus.
- Customer means a person who makes a payment for Merchant's online goods and/or services and initiate chargeback prevention procedure.
- EEA includes all current member states to the European Union and the European Economic Area.
- GDPR means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- Merchant means a business that sells online goods and/or services to customers and uses CBH's chargeback prevention services.
- Personal Data is any information that relates to an identified or identifiable individual, such as a name, email, a telephone number, IP address, etc.
- Process, in respect of personal data, includes to collect, store, use, restrict, erase, destruct and disclose to others.
- Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Service refers to the services provided by CBH, such as chargeback prevention services, and other related technical services, as well as the Website infrastructure, where applicable.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
- Third-Party Service Providers refer to third-party companies that offer services designed to minimise the occurrence and impact of chargebacks. These providers use various technologies to analyse transactional data, and may collaborate with Merchants, financial institutions, and Customers to resolve disputes and prevent fraudulent activities.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Website refers to ChargebackHit, accessible from or .
- You means a person whose personal data is processed by ChargebackHit, including, inter alia, Customer who initiate chargeback prevention procedure, and the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
3. Data we collect
- Full name
- Email address
- Your company's website
- Other data You provide when using Our Website, such as the messages you sent to our support team
- Name, username;
- Email address;
- Telephone number;
- IP address;
- Postal and billing address (state, zip code, city);
- Date of birth;
- Order description;
- Date and amount of transaction;
- Transaction data;
- Mask card;
- Device (e.g., operating system and browser);
- Length of customer relationship.
| Source | Name | Purpose | Expiration |
|---|---|---|---|
| Google* | __Secure-3PSIDCC | This Cookie, installed by Google, is used to ensure that user authentication remains secure across third-party websites. | 1 year |
| __Secure-1PSIDCC | This Cookie, installed by Google, provides additional layers of HTTPS-based security for authentication tokens within Google domains. | 1 year | |
| SIDCC | This Cookie, installed by Google, is used to protect user data from unauthorized access in services like Gmail. | 1 year | |
| __Secure-3PSID | This Cookie, installed by Google, is used to securely authenticate the user across different Google domains. | 1 year | |
| __Secure-1PSID | This Cookie, installed by Google, provides additional layers of HTTPS-based security for authentication tokens within Google domains. | 1 year | |
| SID | This Cookie, installed by Google, is used for user authentication and session management in Google services. | 1 year | |
| SAPISID | This Cookie, installed by Google, is used to manage anti-forgery efforts and secure sign-ins across Google services. | 1 year | |
| APISID | This Cookie, installed by Google, is used to collect user behavior information and ad targeting within the Google ecosystem. | 1 year | |
| HSID | This Cookie, installed by Google, is used to verify the Google account user and protect against fraudulent use of login credentials and user data. | 1 year | |
| SSID | This Cookie, installed by Google, is used to maintain session-specific settings like language preferences in Google services. | 1 year | |
| __Secure-1PAPISID | This Cookie, installed by Google, is used when the website uses HTTPS to ensure secure data transmission; it's a secure version of APISID. | 1 year | |
| __Secure-3PAPISID | This Cookie, installed by Google, is used in third-party websites using Google services for secure data transmission; it's another secure variant of APISID. | 1 year | |
| NID | This Cookie, installed by Google, is used to store user preferences and targeted ad settings. | 6 months | |
| 1P_JAR | This Cookie, installed by Google, is used for website analytics and ad revenue tracking; it compiles site usage statistics and tracks conversion rates. | 1 month | |
| OTZ | This Cookie, installed by Google, is used to gather aggregated user behavior for Google Analytics. | 24 hours | |
| AEC | This Cookie, installed by Google, is used for tracking user interactions within the website, often for the purpose of analytics or customization. | 6 months | |
| _grecaptcha | This local storage, installed by Google, is used to provide spam protection. | 6 months | |
| fr | This Cookie, installed by Facebook, is used to enhance advertising experiences through real-time bidding from third-party advertisers. | 30 days | |
| sb | This Cookie, installed by Facebook, is used to save browser details and securely identify the browser during server-client interaction. | 1 year | |
| datr | This Cookie, installed by Facebook, identifies the web browser being used to connect to Facebook independent of the logged-in user. | 1 year | |
| Pipedrive | __cf_bm | This Cookie is used to distinguish between human and bot traffic, improving website security. | 24 hours |
| Chargebackhit | _omappvp | This Cookie is used for identifying new and returning users, often for the purpose of marketing or web analytics. | session |
| Chargebackhit | _ga_17EZ0BF6SS | This Cookie calculates visitor, session, and campaign data for the website's analytics report. | 2 years |
| Chargebackhit | _gat_gtag_UA_224714314_1 | This Cookie is used to throttle the request rate, reducing the load on servers during high-traffic periods. | 10 minutes |
| Chargebackhit | _gid | This Cookie is used to collect user data to distinguish between different users visiting the website for analytics purposes. | 24 hours |
| Chargebackhit | _ga_2JVMLZBK68 | This Cookie is used to separate users and collect analytics data. | 1 year |
| Chargebackhit | _ga_DTJ98L1DYJ | This Cookie calculates visitor, session, and campaign data for the website's analytics report. | 2 years |
| Chargebackhit | cookieyes-consent | This Cookie is used to confirm that the user has agreed to the website's cookie usage policy. | no longer than 6 months |
| Chargebackhit | _fbp | This Cookie is used to facilitate ad targeting and optimization by storing data on user interactions with ads across various platforms. | 3 months |
| Chargebackhit | _lfa | This local storage is used for tracking user behaviour over the long term, often for marketing analysis and customer segmentation. | 2 years |
| Chargebackhit | _ga | This Cookie calculates visitor, session, and campaign data for the website's analytics. | 2 years |
| DoubleClick*** | DSID | This Cookie, installed by DoubleClick, is used for collecting users' behaviour and interactions with ads, making it possible for advertisers to serve more relevant content to the target audience. | 24 hours |
| DoubleClick | IDE | This Cookie, installed by DoubleClick, is used for serving targeted ads and evaluating the effectiveness of advertising campaigns. | 1 month |
| DoubleClick | __gfp_s_64b | This Cookie, installed by DoubleClick, is used for analytics and tracking. It helps in measuring the performance and effectiveness of various types of advertising campaigns. | 2 weeks |
| DoubleClick | ar_debug | This Cookie, installed by DoubleClick, is used for debugging and analytic purposes on the DoubleClick platform. It helps in troubleshooting and performance optimization of advertising scripts and modules. | 1 month |
| Getsitecontrol**** | gsc | This local storage file, installed by Getsitecontrol, contains analytical information about the number of visits to our Website. | Expires when deleted in browser |
| Getsitecontrol | gscs | This local storage file, installed by Getsitecontrol for creating an analytics report of the Website's performance. It contains information about geolocation, device, the number of viewed pages, the source you come to our Website from, how many sessions you had on our Website, the date and time of the last visit. | Expires when deleted in browser |
| Getsitecontrol | gscw | This local storage file, installed by Getsitecontrol, collects analytical information about our widgets used on the Website: the statistics of view, submit, closing actions, and start and stop conditions. | Expires when deleted in browser |
| Optinmonster***** | _omappvp | This Cookie, installed by Optinmonster, is used for identifying new and returning users, often for the purpose of marketing or web analytics. | session |
| Optinmonster | omVisitsFirst | This local storage, installed by Optinmonster, is used to hold page, referrer and timestamp data for when a specific visitor first visited your site. | persistent |
| Optinmonster | _omappvs | This Cookie, installed by Optinmonster, is used to provide functions across pages. | session |
| Leadfeeder****** | _lfa_expiry | This local storage, installed by Leadfeeder, is used to store and track audience reach. | 2 years |
* This service may also collect information regarding the use of other sites, apps and online resources. You can learn about Google's practices on the Google website.
** Local storage is a client-side storage solution with a larger capacity than Cookies and is not sent to the server with HTTP requests.
*** DoubleClick is a subsidiary of Google, a digital advertising platform.
**** Getsitecontrol is using local storage instead of cookies. The information about the way Getsitecontrol stores and processes data can also be found on the Getsitecontrol website.
***** Optimonster is a lead generation tool that helps businesses capture visitor information through various types of forms and pop-ups. You can learn about Optimonster's practices on the Optimonster website.
****** Leadfeeder is a B2B analytics tool that identifies website visitors to help businesses generate leads and enhance sales efforts. You can learn about Leadfeeder's practices on the Leadfeeder website.
- For the Chrome web browser, please visit this page from Google.
- For the Internet Explorer web browser, please visit this page from Microsoft.
- For the Firefox web browser, please visit this page from Mozilla.
4. How do we use Your Personal Data
- Ensuring the protection of Personal Data in accordance with applicable data protection regulations (e.g., the GDPR);
- providing You with necessary information about the processing and the recipients of their Personal Data, such as CBH;
- supporting the exercise of the rights of Customers under the applicable legislation, etc.
5. Personal Data recipients
6. Data retention
7. Data transfers
8. Data Security
- Perimeter isolation between production, data and testing environments;
- Limited number of publicly accessible entry points;
- Regular vulnerability scanning;
- Production network perimeter scanning;
- Administrative access is allowed only through bastion sites;
- Personal data and card data is stored and processed only encrypted;
- Access to systems is differentiated by the roles;
- Use of WAF to prevent threads from Top 10 OWASP;
- 24×7 anomalies monitoring;
- Regular revision of security rules.
9. Your rights
- to obtain confirmation as to whether or not We process Your Personal Data, and, where that is the case, the information about such processing;
- to request rectification of inaccurate Personal Data;
- to request erasure of Your Personal Data in certain circumstances provided by law;
- to restrict the processing, for example when the processing is unlawful;
- to object to processing of Your Personal Data which is based on a legitimate interest;
- to receive Your Personal Data We process in a structured, commonly used and machine-readable format and to transmit those data to another controller;
- to withdraw any consent that was given at any time.
10. Children
11. California residents
- the categories of Personal Data to be collected;
- the purposes for which the categories of Personal Data shall be used;
- the categories of sources from which the Personal Data are being collected;
- the categories of third parties with whom We may share Personal Data.