COD Shield

Privacy policy

What the COD Shield service receives from a connected WooCommerce store, why, and for how long. Last updated 6 October 2026.

Who we are

The service is operated by Devsnest (kismet@devsnest.net). For data about a store's customers, the store is the controller and we process that data on the store's instructions, which it gives by enabling features in the plugin.

What we receive, and when

What we do not do

We do not sell data, use it for advertising, or share raw customer data between stores. Network data is only ever exchanged as hashes.

Retention

Site records are kept while the site is connected and for 12 months after disconnection for billing records. Courier results expire after 24 hours. Fraud-network records are kept for 24 months from the last report. Usage counters are kept per billing month for 24 months.

Your rights

A store can disconnect at any time from the plugin. Customers of a store should contact that store; a store can ask us to delete the hashes it reported by emailing us with its site id. Where the GDPR or a similar law applies, you may also request access to or erasure of data we hold about you by emailing us.

Security

Traffic is encrypted in transit; site keys are stored only as hashes; tokens are stored encrypted at rest. Access to production data is limited to the people operating the service.