Data Security

Your Data is Safe with ChargeMate

Merchants trust us with sensitive dispute evidence. Here is exactly how we protect it — what we store, where it lives, and what we will never do with it.

Encryption in transit

TLS 1.3

Encryption at rest

AES-256

Database infrastructure

SOC 2 Type II

AI data retention

Zero

What data we handle

When you use ChargeMate, we process only what is necessary to generate your dispute response.

Dispute details

  • Reason code
  • Transaction amount
  • Payment processor
  • Dispute description you write

Evidence files

  • Screenshots
  • Invoices and receipts
  • Order confirmations
  • Delivery tracking records

Account data

  • Email address
  • Business name (optional)
  • Subscription plan
  • Usage count

We never handle, request, or store full card numbers (PAN), CVV codes, or any raw payment credentials. Stripe handles all payment processing and we receive only subscription status.

How we protect your data

Encryption in transit and at rest

All data between your browser and our servers is encrypted with TLS 1.3. Data stored in our database is encrypted at rest using AES-256 — the same standard used by financial institutions.

SOC 2 Type II certified infrastructure

Our database and file storage run on Supabase, which holds SOC 2 Type II certification. This means an independent auditor has verified their security controls against the trust service criteria for availability, confidentiality, and security.

Row-level security on all data

Every query to our database enforces row-level security policies. No user can ever access another merchant's disputes, evidence files, or account data — it is enforced at the database layer, not just in application code.

Evidence files stored in Supabase Storage

Files you upload are stored in Supabase Storage — not on our own servers and not transmitted to any third party except Anthropic's Claude API for the sole purpose of generating your dispute response.

AI processing — zero data retention

We use Anthropic's Claude API to generate dispute responses. Anthropic's API has a zero data retention policy: your dispute content and uploaded files are not stored by Anthropic and are not used to train AI models. Data is processed in memory and discarded immediately after the response is generated.

What we never do

  • Store CVV codes, full card numbers (PAN), or any raw payment credential
  • Sell, share, or rent your merchant data to third parties for any commercial purpose
  • Use your uploaded evidence files for any purpose other than generating your dispute response
  • Allow Anthropic to retain or train on your dispute content (covered by their zero retention API policy)
  • Access your evidence files without your action triggering a generation request

Third-party services

ProviderRoleCertificationLocation
SupabaseDatabase, authentication, and file storageSOC 2 Type IIEU / US
AnthropicAI response generation (Claude API)Zero data retentionUS
StripeSubscription billing only — no dispute dataPCI DSS Level 1US
VercelApplication hosting and CDNSOC 2 Type IIUS / EU

Data retention

  • Dispute response data and evidence files are retained for as long as your account is active.
  • AI-generated drafts are stored per case and can be deleted by you at any time from the dashboard.
  • Usage logs are retained for up to 12 months for billing verification.
  • If you close your account, all personal data and uploaded files are permanently deleted within 30 days of your written request to security@chargemate.tech.

Security questions or concerns?

If you have questions about how we handle your data, want to request deletion of your account, or need to report a security concern, contact us directly. We respond within one business day.

security@chargemate.tech

ChargeMate is operated by Fincoro Limited, registered in England and Wales. Registered office: 61 Bridge Street, Kington, HR5 3DJ. See also our Privacy Policy and Terms of Service.