📋 Legal Document

Privacy Policy

Effective: June 20, 2026
Last Updated: June 20, 2026
GDPR Compliant
Table of Contents

Plain English Summary: Return Automator stores the minimum data needed to process returns for Shopify merchants. We never sell your data. Customer data is used only to process returns and send confirmation emails. Merchants control all their customer data and can request deletion at any time.

01 Overview & Who We Are

Return Automator ("we," "us," or "our") is a Shopify application that automates the customer return and refund process for e-commerce merchants. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service, whether as a Shopify merchant ("Merchant") or as an end customer of a Merchant ("Customer").

By installing or using Return Automator, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our Service.

Operator: Return Automator
Contact: privacy@returnautomator.com
Service URL: returnautomator.com

02 Information We Collect

From Merchants (Shopify Store Owners)

Data TypeWhat It IsWhy We Collect It
Shop domainyourstore.myshopify.comIdentify your store, route returns correctly
Shopify access tokenOAuth token from ShopifyMake API calls (refunds, gift cards, orders) on your behalf
Subscription statusActive / Trial / CancelledControl access based on billing status
App settingsReturn window, label fee, thresholdsApply your configured policies to returns
Shippo API tokenYour personal Shippo key (optional)Generate labels billed to your Shippo account

From Customers (End Shoppers)

Data TypeWhat It IsWhy We Collect It
Order numberShopify order ID / numberVerify return eligibility
Email addressUsed to look up the orderVerify identity, send confirmation email
Return reasonText selected or entered by customerRecord why the item was returned
Damage photosImages uploaded by customer (optional)Document item condition for the merchant
Refund method choiceCash / Store Credit / ExchangeProcess the appropriate refund type

Automatically Collected Technical Data

03 How We Use Your Information

We use the information collected for the following purposes only:

⚠️ We never sell, rent, or trade your personal information or your customers' personal information to any third party for marketing purposes.

04 Third-Party Services

Return Automator integrates with the following third-party services to deliver its functionality. Each operates under their own privacy policy:

ServicePurposeData SharedPrivacy Policy
Shopify Order lookup, refunds, gift cards, billing Shop domain, access token, order IDs shopify.com/legal/privacy
Shippo Prepaid return label generation Customer name, shipping address goshippo.com/privacy
Cloudinary Damage photo cloud storage Uploaded images only cloudinary.com/privacy
SendGrid (Twilio) Transactional confirmation emails Customer email address, order summary sendgrid.com/privacy
Railway Cloud hosting & infrastructure Application data (encrypted at rest) railway.app/legal/privacy

05 Data Storage & Security

Security Incident Notice: In the event of a data breach that affects your personal information, we will notify affected parties within 72 hours in accordance with GDPR Article 33 requirements.

06 GDPR — Your Rights

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights regarding your personal data:

Return Automator implements all mandatory Shopify GDPR webhooks:

To exercise any of these rights, contact us at privacy@returnautomator.com. We will respond within 30 days.

07 Data Retention

Data TypeRetention PeriodReason
Return records2 years from creationMerchant recordkeeping, dispute resolution
Damage photos2 years from uploadMerchant documentation and dispute resolution
Shopify access tokensUntil uninstallDeleted immediately on app/uninstalled webhook
Email logs90 daysDebugging and delivery confirmation
API access logs30 daysSecurity and debugging only
Customer email addresses2 years or until erasure requestAssociated with return records

After the retention period, data is permanently deleted and cannot be recovered.

08 Cookies

The Return Automator return portal uses minimal, functional cookies only:

09 Children's Privacy

Return Automator is a business tool intended for use by Shopify merchants and their adult customers. We do not knowingly collect personal information from anyone under the age of 13. If we become aware that we have inadvertently collected personal data from a child under 13, we will delete it immediately.

10 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

11 Contact Us

For any privacy-related questions, data requests, or to exercise your GDPR rights:

Privacy Questions?

We typically respond within 2 business days. For GDPR requests, we respond within 30 days as required by law.

privacy@returnautomator.com