Who we are
representments.com is operated by Andamento Advisors LLC, a Delaware limited liability company. We provide chargeback rebuttal letter services to merchants. This policy explains what personal and business data we collect when you use the service, how we use it, and how long we keep it.
You can reach us about anything in this policy at hello@representments.com.
What we collect
Account information. Business name, business email address, payment processor name, and any context you give us at signup or in support correspondence.
Forwarded chargeback notifications. When you forward a dispute notification to your dedicated address, we receive the email body and any attachments. These typically contain the dispute amount, transaction date, reason code, the last four digits of the card, the dispute deadline, the issuing bank identification number (the first six to eight digits of the card, used to identify the issuing bank, never the full card number), and the cardholder claim narrative.
Connected platform accounts. If you install our app from the Stripe App Marketplace or the Shopify App Store, you grant it access to your account on that platform, and we store the access and refresh tokens the platform issues so the app can keep working. We read only what is needed to draft and file a rebuttal: your account's business name and, on Stripe, the email address of the team member using the app so we can send you deadline reminders and billing notices; and for each dispute you choose to work, the disputed charge or order, the customer on that charge, and the dispute's reason code, amount and response deadline. We write only when you authorize it, uploading the letter and any documents you attach and updating that dispute's evidence. We do not read your wider transaction history, your payouts, or customers unconnected to a dispute you are answering. When you uninstall, the platform tells us and we delete the stored tokens.
Generated letters and case metadata. The .docx letter we draft for you, plus the metadata of the case (reason code, issuer, business type, outcome if you report it).
Operational logs. Email delivery logs, webhook traces, error logs, IP address at signup, and timestamps. Used for debugging and abuse prevention.
Attribution data. When you arrive at the site, a first-party cookie records the campaign parameters in your URL (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the referring page if any, and the page you landed on. We use this to understand which channels reach merchants who become customers. The cookie is HttpOnly, expires in 30 days, and is never shared with third-party advertising or analytics platforms. If you sign up, we snapshot the values into your merchant record so we keep the attribution context after the cookie expires.
Advertising click identifiers. When you arrive from an advertisement, the platform that showed it usually adds an identifier to the URL naming that click (Google's gclid, Meta's fbclid, LinkedIn's li_fat_id, Reddit's rdt_cid and their equivalents). We record it against the visit so we can tell paid traffic from traffic that arrived on its own, which a campaign parameter alone does not tell us. We also record the browser identification string your browser sends with every request, which is how we separate automated crawlers from readers. If you decline measurement, or have not yet answered in a region where we ask first, the click identifier is discarded and only the fact that the visit was paid is kept.
Billing data. Stripe is our payment processor. We do not store full card numbers, CVVs, or bank account numbers. Stripe holds that data under its own privacy policy and PCI DSS compliance.
What we do not collect
We never store full primary account numbers (PANs), CVV codes, bank account numbers, or cardholder Social Security numbers. If a forwarded notification contains an apparent full card number, our intake quarantines and rejects it before storage. This keeps the service outside PCI DSS scope.
We do not knowingly collect data from anyone under 18. The service is for businesses, not consumers, and is not directed to children.
How we use your data
To draft your rebuttal letters and run the service.
To improve the drafting logic that powers letter generation. We anonymize case metadata (reason code, issuer, outcome) and aggregate it across customers; we do not share identifiable customer data with anyone.
To send you transactional emails (welcome, letter delivery, outcome reminders, quarterly reports, billing notices). We do not send marketing emails.
To detect and prevent abuse of the free-first-letter offer and of the subscription tier caps.
To comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
Who we share data with
We do not sell your data. We use a small set of trusted service providers to run the service, for example to host the application, send transactional email, process payments, and measure how the site is used. Each handles data only to provide its function to us and is bound by its own contractual and security obligations. Where we run paid advertising, the conversion tags described under Cookies report to the advertising platform that a signup or a subscription happened; you can stop that by declining measurement.
We may also disclose data when required by law, to enforce our agreements, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy.
How long we keep your data
- Forwarded chargeback notifications: 30 days
- Generated letters: 90 days
- Identifiable case metadata: 12 months, then anonymized
- Customer profile: while your subscription is active, plus 30 days
- Connected platform access tokens: deleted when you uninstall the app
- Anonymized outcome data: indefinitely
- Email and webhook logs: 30 days
- Stripe billing records: per Stripe's policy
Your rights
You can ask us to access, correct, or delete the personal data we hold about you. Email hello@representments.com with the request. We respond within 30 days.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect, to request deletion, to request correction, to opt out of sharing for cross-context behavioral advertising, and to be free from discrimination for exercising these rights. We do not sell personal information. When we run paid advertising, the conversion tags described under Cookies may constitute sharing for cross-context behavioral advertising; declining measurement in the notice on the site, or writing to us, stops it.
Security
Data is encrypted in transit (TLS) and at rest. Secrets are stored in the encrypted environment-variable store of our hosting provider. Accounts that can view the internal dashboards of the service use two-factor authentication. We do not handle PCI-scoped cardholder data.
Cookies
The site sets a small number of first-party cookies. Most are unremarkable: they serve the pages, remember the language you chose, and hold your session. One records the campaign parameters described above. One holds a random identifier that means nothing outside this site and exists so that several page views in one sitting read as a single visit rather than several strangers. One remembers your answer to the question below, so that we ask it only once.
We do run third-party measurement, and this policy used to say otherwise. Our hosting provider counts page views and page-load speed without cookies and without identifying anyone. A product-analytics service records which pages a visit touched and how it arrived, and on the marketing pages it may record a replay of the session in which every form field and every piece of on-screen text is masked in your browser before anything is sent. Replay is switched off entirely on the pages where disputes, orders and charges appear, so no recording can reach that data. If we are running paid campaigns, conversion tags from the advertising platforms we buy from also load. Write to hello@representments.com if you want the current list of the providers involved.
In the European Economic Area, the United Kingdom and Switzerland, none of the measurement above loads until you agree to it, and the site works the same whether you agree or not. Everywhere else it runs unless you decline, which you can do from the same notice or by writing to us at any time. Declining stops the analytics and advertising cookies; the cookies that serve the pages and hold your session remain, because without them the site cannot answer you.
We also record the country the request came from, which our hosting provider resolves at the network edge, and where a visit comes from a corporate network we may resolve that network to the organisation that owns it. We do this to understand which kinds of business read which pages. Your IP address is used for that resolution and is then discarded; it is not written to our records.
Changes to this policy
When we make a material change, we will email active customers and update the effective date at the top of this page. The current version always lives at this URL.
Contact
Questions or requests about this policy: hello@representments.com.
See also: Terms of service.