Your Data is Safe with ChargeMate
Merchants trust us with sensitive dispute evidence. Here is exactly how we protect it — what we store, where it lives, and what we will never do with it.
Encryption in transit
TLS 1.3
Encryption at rest
AES-256
Database infrastructure
SOC 2 Type II
AI data retention
Zero
What data we handle
When you use ChargeMate, we process only what is necessary to generate your dispute response.
Dispute details
- Reason code
- Transaction amount
- Payment processor
- Dispute description you write
Evidence files
- Screenshots
- Invoices and receipts
- Order confirmations
- Delivery tracking records
Account data
- Email address
- Business name (optional)
- Subscription plan
- Usage count
We never handle, request, or store full card numbers (PAN), CVV codes, or any raw payment credentials. Stripe handles all payment processing and we receive only subscription status.
How we protect your data
Encryption in transit and at rest
All data between your browser and our servers is encrypted with TLS 1.3. Data stored in our database is encrypted at rest using AES-256 — the same standard used by financial institutions.
SOC 2 Type II certified infrastructure
Our database and file storage run on Supabase, which holds SOC 2 Type II certification. This means an independent auditor has verified their security controls against the trust service criteria for availability, confidentiality, and security.
Row-level security on all data
Every query to our database enforces row-level security policies. No user can ever access another merchant's disputes, evidence files, or account data — it is enforced at the database layer, not just in application code.
Evidence files stored in Supabase Storage
Files you upload are stored in Supabase Storage — not on our own servers and not transmitted to any third party except Anthropic's Claude API for the sole purpose of generating your dispute response.
AI processing — zero data retention
We use Anthropic's Claude API to generate dispute responses. Anthropic's API has a zero data retention policy: your dispute content and uploaded files are not stored by Anthropic and are not used to train AI models. Data is processed in memory and discarded immediately after the response is generated.
What we never do
- Store CVV codes, full card numbers (PAN), or any raw payment credential
- Sell, share, or rent your merchant data to third parties for any commercial purpose
- Use your uploaded evidence files for any purpose other than generating your dispute response
- Allow Anthropic to retain or train on your dispute content (covered by their zero retention API policy)
- Access your evidence files without your action triggering a generation request
Third-party services
Data retention
- Dispute response data and evidence files are retained for as long as your account is active.
- AI-generated drafts are stored per case and can be deleted by you at any time from the dashboard.
- Usage logs are retained for up to 12 months for billing verification.
- If you close your account, all personal data and uploaded files are permanently deleted within 30 days of your written request to security@chargemate.tech.
Security questions or concerns?
If you have questions about how we handle your data, want to request deletion of your account, or need to report a security concern, contact us directly. We respond within one business day.
ChargeMate is operated by Fincoro Limited, registered in England and Wales. Registered office: 61 Bridge Street, Kington, HR5 3DJ. See also our Privacy Policy and Terms of Service.