Privacy Policy

Last updated: September 23, 2026

Why and who?

RefundShield cares about privacy and protecting the Personal Data handled by us. This means that we care about your personal integrity and actively work to protect it.

In this Policy we describe how and for what purposes we use your Personal Data, the lawful basis we use, and the measures we take to protect it. We also provide information on how you can exercise your rights related to our Processing of your Personal Data.

OMGL LTD ("RefundShield", "we", "us", "our") is the Controller of all Personal Data listed in this Privacy Policy (the "Policy").

This Policy provides information on how we handle Personal Data when you communicate with us, use the Services, or visit our website.

Definitions

  • "Applicable Law" refers to the legislation applicable to the Processing of Personal Data, including the GDPR and supplementary national legislation.
  • "Controller" is the company/organisation that decides for what purposes and in what way personal data is to be processed.
  • "Personal Data" is all information relating, directly or indirectly, to an identifiable natural person.
  • "Processing" means any operation performed on Personal Data, e.g. storage, modification, or reading.
  • "Processor" is the company/organisation that processes Personal Data on behalf of the Controller.
  • "The Services" is our platform for handling App Store and Google Play refund notifications, monitoring consumption data, and managing refund statuses.

Our Role as a Controller

This Policy covers Personal Data Processing for which RefundShield is the Controller. The Policy does not describe how we Process Personal Data in the role of a Processor, i.e. when we process data on behalf of our customers as part of the Services.

When you register for RefundShield, we collect your name and email address. To provide our core service, we process and store App Store Server Notifications sent by Apple and Google Play Real-time Developer Notifications sent by Google on your behalf. This includes transaction and order IDs, product IDs (SKUs), purchase tokens, and dates, but does not include your end-users' personal names, emails, or payment details.

We use your information exclusively to:

  • Provide, maintain, and improve the Service.
  • Process transactions and send related information (e.g., invoices).
  • Authenticate with Apple and Google APIs on your behalf.
  • Send technical notices, security alerts, and support messages.

Data Storage and Retention

We will keep your Personal Data as long as it is necessary for the purpose for which it was collected. We never store your Personal Data longer than necessary and delete Personal Data regularly. If you delete your account or an app, all associated data and keys are permanently removed from our systems.

Your Rights

You are in control of your Personal Data. You have the following rights:

  • Access: You have the right to receive information about the Processing of data that concerns you.
  • Rectification: If you find that the Personal Data we process about you is incorrect, let us know and we will fix it.
  • Erasure: You have the right to be forgotten and request deletion of your Personal Data when the Processing is no longer necessary.
  • Restriction: You can ask us to restrict our Processing of your Personal Data in certain circumstances.
  • Data Portability: We may provide you with the data that you have submitted to us in a commonly used and machine-readable format.

To exercise your rights, please contact us at [email protected].

Transfer of Personal Data

In order to run our business, we may need help from others who will process Personal Data on our behalf, so-called Processors (e.g., cloud hosting providers and payment processors). In cases where our Processors transfer Personal Data outside the UK/EEA, we have ensured that the level of protection is adequate and in compliance with Applicable Law. We have entered into Data Processing Agreements (DPA) with all our Processors.

Security Measures

We take security seriously and have taken technical and organizational measures to ensure that your Personal Data is processed securely and protected from loss, abuse, and unauthorized access. These measures include:

  • Encryption: All sensitive credentials (such as Apple .p8 keys and Google service account JSON keys) are encrypted at rest.
  • Secure Network: Communications between your browser, our servers, Apple's servers, and Google's servers are strictly transmitted over HTTPS.
  • Access Control: We enforce strict login and password management internally.

Complaints

If you think that we are not Processing your Personal Data correctly, you are entitled to submit your complaint to the Information Commissioner's Office (ICO) in the United Kingdom.

Changes to this Policy

We reserve the right to make changes to this Policy. In the event that the change affects our obligations or your rights, we will inform you about the changes in advance.


If you have any questions about this Privacy Policy, please contact us at [email protected].