Permissions limited to reading data and answering disputes
Chargeback software needs access to your payment data to build evidence. It does not need access to your money. We designed every connection around that difference, and you can see the exact permissions on your processor's screen before you approve anything.
When you connect Stripe, you choose one of two ways.
-
Stripe OAuth with read only access, plus permission to write evidence on disputes so we can submit your response before the deadline.
-
A restricted API key that you create in your own Stripe dashboard, with read access to charges, payment intents, customers, invoices, subscriptions, early fraud warnings and balance transactions, and write access only on disputes.
Neither option includes permission to create charges, refunds, payouts or transfers. The processor itself refuses those requests, so even a mistake in our code could not move money from your account. Other processors such as Shopify, PayPal, Braintree, Checkout.com, Adyen and Authorize.net connect with the narrowest read and dispute scopes each one offers.
Prevention rules that refund or decline certain alerts exist on Growth and higher plans, but they are off by default. They run only on your own account, only after you turn them on, and only within the amount limits you set.
Encryption of credentials and data in transit
-
OAuth tokens, restricted keys and webhook secrets are encrypted at rest with application level encryption before they reach the database.
-
Credentials are never shown again in the app after you save them, never written to logs and never sent by email.
-
All traffic between your browser, our application and your processors uses TLS.
-
Webhooks from processors are verified by signature before any event is accepted.
-
Passwords are stored as salted hashes, and new accounts confirm their email with a one time code.
Data minimization, we store what a dispute pack needs
An evidence pack needs specific facts: the order, the amount, the authorization result, 3D Secure and AVS or CVC checks, delivery or usage proof, customer communication and the policy the customer accepted. We store those facts for disputes and fraud warnings, plus the transaction counts needed to compute your chargeback ratio.
We do not store full card numbers. Processors never share them with us, and evidence packs show only the card brand and last four digits that the processor already provides. We do not pull your full customer list for marketing, and we never contact your customers.
Retention and deletion
| Data | How long we keep it |
|---|---|
| Dispute notices uploaded in the demo | Deleted after 24 hours |
| Dispute, alert and evidence data | While the processor account stays connected |
| Processor credentials after you disconnect | Deleted immediately |
| Dispute data after disconnect | Deleted on request, or within 30 days of account closure |
| Billing records for our own invoices | As long as tax law requires |
You can disconnect any processor account from the integrations page at any time. To delete stored dispute data sooner, email support@nochargeback.com from an owner address of the workspace and we confirm when it is done.
Team roles, seats and access control
Every workspace has an owner, and every other person gets a seat with a role. Owners manage billing and connections, admins manage rules and submissions, and members work on disputes. Starter includes one seat, Growth three, Scale ten with roles, and Enterprise fifty with custom roles.
Enterprise adds single sign on with SAML, so access follows your identity provider and ends when someone leaves your company. Enterprise also includes an audit log that records sign ins, connection changes, rule changes and every evidence submission, with the person and time for each.
Our own staff do not browse merchant data. Access for support happens only when you ask for help with a specific dispute, and it is limited to that workspace.
Infrastructure and subprocessors described by category
-
Application and database are hosted with an infrastructure provider in the EU or US region.
-
Account emails and alerts are sent through a transactional email provider.
-
Evidence letters are drafted with an AI text model provider, used only to write the letter for a dispute. Under our provider terms your data is not used to train their models.
-
Our own subscription billing runs through our payment processor.
-
The public website uses essential cookies only. We do not run advertising trackers.
Enterprise customers receive the full list of subprocessors with the security review pack.
Report a security issue
If you find a vulnerability or suspect that something is wrong with your account, email support@nochargeback.com with the word Security in the subject. Include the steps to reproduce and the affected page. We acknowledge reports within two business days, keep you informed while we fix the issue and do not take action against good faith research that avoids customer data and service disruption.
Security review pack for Enterprise
Finance, risk and procurement teams often need written answers before they approve a vendor. Enterprise includes a security review pack: our data flow description, permission scopes per processor, encryption and retention details, subprocessor list, incident response process and a completed vendor questionnaire. The pack and our data processing agreement are sent by email from support@nochargeback.com after checkout. Enterprise also carries a 99.9 percent uptime SLA.
Can NoChargeback refund my customers or move my money?
No. The permissions we request cover reading payment data and writing dispute evidence only. Your processor rejects any attempt to create a charge, refund, payout or transfer with those permissions. Optional refund rules run only if you turn them on for your own account.
Where is my data stored?
Your workspace is hosted with an infrastructure provider in the EU or US region. Credentials are encrypted at rest and all traffic uses TLS.
Is my dispute data used to train AI models?
No. An AI text model drafts the rebuttal letter for a dispute, and under our provider terms that data is not used for training.
What happens when I disconnect a processor?
We delete the stored credentials for that account immediately. Dispute data is deleted on request, or within 30 days after you close your account.
How do I report a security issue?
Email support@nochargeback.com with Security in the subject line. We acknowledge every report within two business days.
Do you offer a security questionnaire for vendor review?
Yes. Enterprise includes a security review pack with a completed vendor questionnaire, subprocessor list and data processing agreement.