Effective 28 August 2026 · Clarified 7 September 2026

Privacy notice

We operate Shipping Contract Guard from Belgium. Send questions and data requests to hello@shippingcontractguard.com.

What the service processes

The WordPress plugin keeps your saved correct results, local test runs, private signing key, Operator checkout activation secret, and a small copy of the latest Operator alert on your WordPress site. If you activate Operator, the plugin sends a one-way store reference, a public signing key, references for your saved checks, test results, the kinds of amounts or postcodes checked, times, one-way settings references, and a short list of changed settings. If a manager follows up a failed check, the plugin also sends that it was acknowledged, the label for the responsible person or role, and a short note. Do not put customer data, passwords, or secrets in those fields. The plugin does not send customer names or addresses, orders, full cart contents, card data, store payment details, carrier passwords, full test addresses, product IDs, or the private signing key.

For billing, we keep the Stripe references for the customer, subscription, price, and billing event, along with the subscription status, event times, and one-way codes used to detect duplicate or changed events. Stripe separately processes the billing, contact, and tax information entered during checkout.

Shipping-rate providers used by your store

A Local or Operator check asks enabled WooCommerce shipping methods for a result. A live-rate method may send the made-up destination, measurements, or product attributes to its own provider to obtain a quote. Review that provider’s privacy terms before approving the test. This is separate from the limited information sent to Shipping Contract Guard Operator.

Magento Open Source extension

The Magento descriptions below refer to earlier preview work. A verified installation package is not currently available. See the Magento preview status before using the historical guides.

Shipping Contract Guard Local for Magento Open Source stores approved check definitions, temporary-quote recovery details, check results, history settings, and extension permissions in Magento. A check can use an existing product, quantity, destination, coupon code, and expected shipping method or amount, but the local report and export leave out the complete definition, product identifier, destination, coupon, and shipping response.

Local requires no account, contains no tracking, and makes no outside request. It creates no order, customer, payment, name, street, telephone number, or email address. Completed history is kept for 90 days by default. You can choose 7 to 365 days, up to 500 completed checks. An administrator can export the short report or delete extension data through separate Magento permissions.

The optional Magento Operator connection is off by default. If an administrator enables Operator requests and connects the installation, it sends a one-way installation reference, public signing key, fingerprints for the saved test and test case, short results and reason codes, configuration fingerprints, times, and a record of how a scheduled check started to api.shippingcontractguard.com. It does not send complete test definitions, product identifiers, destinations, coupons, shipping responses, customer data, orders, payments, carrier credentials, or private signing keys. Scheduled checks require a separate opt-in and an active subscription confirmed by the service.

Why and how long

We use service data to run checks, keep history, send alerts, secure the service, prevent misuse, provide support, manage billing, and meet legal duties. Operator keeps test results for 90 days. Operator normally keeps security and audit records for up to 365 days. After you request account deletion, you can cancel that request for 24 hours. We then delete the organization’s service records. We may keep the minimum billing, security, or deletion record needed to meet legal duties or prevent the same request from being processed twice.

Providers and location

OVHcloud hosts the application and encrypted backups in Gravelines, France. The operator also keeps an encrypted working copy. Stripe processes subscription payments and automatic tax. Email providers process messages you choose to send and service alerts you configure. We do not sell personal data. This website uses no analytics, advertising scripts, or tracking cookies.

Your choices and rights

You can use all Local features without Operator. A WooCommerce manager or Magento administrator must agree before the extension contacts Operator. You may ask to access, correct, export, limit, object to, or delete your data by emailing hello@shippingcontractguard.com. You may also complain to the Belgian data-protection authority responsible for your request.