This Privacy Policy describes how Leonix ("we", "us", or "our") collects, uses, and handles data when you use the Leonix fraud and identity intelligence platform — whether through our API, our CDN widget, or one of our platform integrations such as our Shopify app.

1. What Data We Collect

Device & Session Data (via FingerprintJS Pro)

  • Browser fingerprint (name, version, OS)
  • IP address and approximate geolocation
  • VPN / proxy / Tor usage indicators
  • Bot detection signals, incognito mode detection

Application & Account Data

  • Email address, account identifier
  • Transaction or order ID, amount, currency (where applicable)
  • Billing and shipping country (where applicable)

Additional data collected via our Shopify App integration

  • Your Shopify store domain
  • Cart token and Shopify customer ID
  • OAuth access token (used only to inject the fingerprinting widget into your theme)

2. How We Use This Data

Solely to score transactions for fraud risk and display results in your dashboard. We do not sell or share your data or your customers' data with any third party for marketing or advertising purposes.


3. Third-Party Services

ServicePurposePolicy
FingerprintJS ProDevice fingerprinting and bot detectionfingerprint.com ↗
Google Cloud PlatformHosting and database (Cloud Run, Cloud SQL)cloud.google.com ↗
Google GeminiAI-powered analyst chat featureai.google.dev ↗

4. Data Retention

  • Transaction and fraud data — retained while your account or integration is active, plus 30 days after closure or app uninstallation.
  • Device fingerprint data — 90 days.
  • OAuth tokens (Shopify integration) — deleted immediately upon uninstallation.

5. Data Deletion (GDPR)

  • Customer data request — We acknowledge receipt. Email info@leonix.io to request a copy of data held about a specific customer.
  • Customer data erasure — All records deleted within 30 days of request.
  • Shopify store data erasure — All store data deleted within 48 hours of uninstallation (triggered automatically).

6. Data Security

All data stored in Google Cloud SQL, encrypted at rest and in transit. Access is restricted to authenticated services within our GCP project. We never store raw payment card data.


7. Customer Responsibilities

  • Inform your end users that device fingerprinting is used on your site or app for fraud prevention.
  • Include a reference to this in your own privacy policy.

8. Changes & Contact

We may update this policy from time to time. Customers will be notified of significant changes via the Leonix dashboard.

Questions or deletion requests: info@leonix.io