BuyerProtectionAustralia

Data map · 2026-08-15.1

Know where the data goes.

Every live connection. Every dataset. Every retention owner.

Primary hostingObserved Railway runtime region: us-east4-eqdc4a
Data termsCounterparty-specific
Recovery evidenceDeployment-specific
Live runtime

Railway

BuyerProtection data is processed and persisted in the hosting environment. Order-source ingestion excludes raw customer identity, addresses, card data and raw webhooks by contract; other user-supplied support and account fields remain in scope.

Live shared control

Railway-hosted Redis

BuyerProtection writes bounded request counters and expiry times to a shared limiter. No order body, email, card data or support content is required for the limiter.

Configured · delivery review

Resend

BuyerProtection sends transactional email instructions to Resend for delivery to the merchant. Transactional messages are addressed to one merchant and do not include card numbers or a copied order database.

Configured · delivery review

Zendesk

BuyerProtection can create a private support ticket from a submitted inquiry. Ticket copy instructs operators not to request passwords, card details or unrelated customer records.

Live connection

Shopify

The merchant authorises Shopify to supply read-only, field-minimised commerce evidence to BuyerProtection. BuyerProtection requests read_orders and read_fulfillments only; it does not retain raw customer identity, address, card data or raw webhook bodies in the source-event ledger.

Configured · acceptance review

Product-specific Item Check bridge

A separate private ownership check receives a user-entered email, item code and pseudonymous request key for that check only.

Same runtime

TrustedSite

BuyerProtection reads the bundled TrustedSite merchant and domain proof engine inside the same application runtime. TrustedSite Verified remains a public proof decision; it does not activate BuyerProtection Guaranteed.

Retention

Retention follows the record—not one blanket timer.

Transient data uses guarded expiry. Account, case, legal-hold, provider and backup deletion each keep a recorded owner and completion event.

Inspect the lifecycle register →

Data terms

Provider role. Data route. Retention owner.

Counterparty terms record controller and processor roles, Australian cross-border disclosure, retention periods, provider deletion and institutional duties.

Read the privacy policy →