Privacy Policy

Last updated: April 5, 2026

Contents

  1. Overview
  2. What We Collect
  3. Chrome Extension Data Practices
  4. How We Use Your Data
  5. What We Do Not Do
  6. Data Storage & Security
  7. Sub-Processors
  8. Data Retention
  9. Your Privacy Rights
  10. California Privacy Rights (CCPA/CPRA)
  11. Healthcare Data (HIPAA)
  12. Children's Privacy
  13. International Data Transfers
  14. Changes to This Policy
  15. Contact Us

This Privacy Policy describes how VPayment Solutions LLC ("Company," "we," "us," or "our") collects, uses, stores, and protects information when you use ShopConnect, including the Chrome browser extension, web console, and all related services (collectively, the "Service"). This policy applies to all users: merchants, ISOs, agents, sub-agents, and their employees.

1. Overview

ShopConnect is a payment connector that enables merchants to process payments through their chosen payment processor while using their existing business software. To provide this service, we need to access certain data from your browser when you are on supported business software platforms.

The short version: We read invoice data from your business software to facilitate payments. We do not read, store, or transmit full credit card numbers. We do not sell your data. We do not use your data for advertising.

2. What We Collect

2.1 Account Information

When you create an account, we collect:

2.2 Payment Processor Credentials

When you or your ISO/agent configure a payment processor, we collect:

These credentials are encrypted at rest and are never exposed to the client-side application after initial entry. They are used solely to route payment requests to your configured processor.

2.3 Invoice Data (Read by the Extension)

When the extension is active on a supported business software platform, it reads:

2.4 Transaction Records

When a payment is processed through ShopConnect, we record:

2.5 Usage Data

We collect standard usage data including:

We do not collect browsing history, keystrokes, or data from websites other than supported business software platforms.

3. Chrome Extension Data Practices

This section specifically addresses data practices of the ShopConnect Chrome extension, as required by Google's Chrome Web Store Developer Program Policies.

3.1 When the Extension Activates

The extension only activates on domains listed in its configuration — these are the websites of supported business software platforms. The extension does not activate on, read data from, or interact with any other websites, including search engines, social media, email, banking sites, or personal browsing.

3.2 What the Extension Reads

On supported platforms, the extension reads only financial document data (invoice amounts, numbers, and associated customer names) necessary to facilitate payment processing. It does not read:

3.3 Where Extension Data Goes

Data Type Destination Purpose
Invoice data ShopConnect servers Display in payment interface, transaction records
Payment amount Your payment processor's API Process the transaction
Payment confirmation Your business software (via extension) Record payment status

3.4 Google Limited Use Compliance

ShopConnect's use of data obtained through the Chrome extension complies with Google's Chrome Web Store Developer Program Policies, including the Limited Use requirements.

Specifically:

3.5 First-Run Consent

Upon first installation, the extension presents a data use disclosure within its interface. You must actively confirm this disclosure (via an explicit user action) before the extension begins reading financial data from business software platforms.

4. How We Use Your Data

We use collected data for the following purposes:

Purpose Data Used Legal Basis
Process payments Invoice data, processor credentials Contract performance
Transaction history & reporting Transaction records Contract performance
Account management Account information Contract performance
Service communications Email, phone Legitimate interest
Error detection & service improvement Usage data, error logs Legitimate interest
Security & fraud prevention Account activity, transaction patterns Legitimate interest / legal obligation
Legal compliance Transaction records, account data Legal obligation

5. What We Do Not Do

We make the following commitments about your data:

5.1 Do Not Track Signals

ShopConnect does not currently respond to Do Not Track (DNT) signals from browsers, as no uniform standard for honoring DNT signals has been established. However, as stated above, we do not engage in cross-site tracking for advertising purposes regardless of your DNT setting.

6. Data Storage & Security

We implement the following security measures to protect your data:

While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7. Sub-Processors

We use third-party service providers ("sub-processors") to operate the Service. Each sub-processor is bound by data protection obligations no less protective than those in this Privacy Policy.

Category Function
Cloud infrastructure & database Hosting, data storage, authentication
Payment processors Transaction processing (as configured by you)
Email delivery Account verification, service notifications
Error monitoring Crash reporting, service reliability

A current list of specific sub-processors and their locations is available upon request by contacting aashil@shopconnectpro.com.

We will notify you of any material changes to our sub-processor list that may affect the processing of your data.

8. Data Retention

Data Type Retention Period Reason
Account information Duration of account + 30 days Service operation
Transaction records Duration of account + 7 years Financial recordkeeping requirements
Processor credentials Duration of account (deleted on termination) Service operation only
Usage data & error logs 90 days Service improvement

Upon account termination, we delete or anonymize your data within the timeframes above, subject to our legal retention obligations.

9. Your Privacy Rights

Regardless of your location, we honor the following data rights for all users:

How to Exercise Your Rights

Submit requests to aashil@shopconnectpro.com with the subject line "Privacy Rights Request." We will:

We will not discriminate against you for exercising your privacy rights. You will not receive a different level of service or pricing for making a request.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

Category Collected Sold Shared for Ads
Identifiers (name, email, phone) Yes No No
Commercial information (transactions) Yes No No
Internet activity (usage data) Yes No No
Professional information (business name) Yes No No
Sensitive PI (processor credentials) Yes No No

To make a CCPA request, contact aashil@shopconnectpro.com. You may also designate an authorized agent to make a request on your behalf.

11. Healthcare Data (HIPAA)

For merchants in healthcare verticals (medical, dental, chiropractic, veterinary, physical therapy, mental health, etc.):

Merchants in healthcare verticals remain responsible for their own HIPAA compliance obligations.

12. Children's Privacy

The Service is intended for use by businesses and their authorized adult employees. We do not knowingly collect personal information from children under the age of 13 (or 16 in applicable jurisdictions). If we become aware that we have collected personal information from a child, we will promptly delete that information.

13. International Data Transfers

Our servers and sub-processors are primarily located in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, we rely on Standard Contractual Clauses or other appropriate safeguards as required by applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

15. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, contact us: