Skip to document

Privacy Policy

Last updated: May 2026

What data is collected

Unauth collects order, support, claim, outcome, and related commerce data provided by merchants through connected systems or legacy imports. This typically includes customer names, email addresses, delivery addresses, phone numbers, order identifiers, order values, support tickets, refund records, and chargeback records. Where merchants provide them, we also process partial card identifiers (last 4 digits and BIN prefix) as pseudonymous matching signals - we never receive, store, or process full card numbers, CVV codes, or complete card credentials. We also collect standard account information for registered merchants (name, email, billing details) and usage logs for the platform itself.

How it is used

Merchant-provided data is used to operate Unauth claim review workflows: normalising customer identifiers, linking claims to orders and support cases, generating evidence packages, applying merchant-owned rules, tracking recovery work, and reporting payout outcomes. Data is never used for advertising, sold to third parties, or processed for any purpose unrelated to the Unauth service.

Who it is shared with

Raw order data - including customer names, emails, and addresses - is never shared with other merchants. Each merchant’s data is isolated in a separate database partition protected by row-level security that cannot be overridden by application code.

What is processed for reporting: aggregate payout-control statistics such as case counts, payout exposure, evidence status, recovery value, and outcomes. These aggregates do not reveal customer names or another merchant’s order details. This is described in detail in our data handling guide.

Retention

Personal data in your merchant silo is retained for 24 months from the date it is provided, or until you request deletion, whichever comes first. Operational payout-case and recovery records are retained according to the same account policy unless a longer legal retention requirement applies. All deletable data is deleted within 30 days of account closure.

Your rights

Under the UK GDPR you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data; object to or restrict processing; and data portability. To exercise any of these rights, contact us at privacy@unauth.co or use the deletion request option in Settings.

Cookies and tracking

Unauth uses session cookies strictly necessary for authentication. No third-party advertising trackers or analytics cookies are set. We use privacy-preserving server-side analytics only.

Contact

Data controller: privacy@unauth.co. For DPA enquiries: dpa@unauth.co.