ReturnSort

Data handling

ReturnSort Privacy

Who operates ReturnSort

ReturnSort, 150 North State Street, Concord, NH 03301, United States, provides this app to Shopify merchants. The merchant is responsible for its customer relationship and for handling the underlying return, refund, or exchange.

Information we process

The app reads the store domain and selected order and order-line details needed to create a return case, including order number, product title, and quantity. It stores merchant-entered case reasons, requested outcomes, policy decisions, status, assignment, history, and optional evidence. It also stores app subscription and usage records and operational logs. The app does not request customer name, email, phone, or address fields through its current Shopify access scope. Merchants may nevertheless enter personal information in free-text case notes or uploaded evidence.

Why and where

We use this information to operate merchant-directed return case management, apply policies and plan allowances, maintain service security, and respond to privacy requests. The app is hosted on DigitalOcean in its NYC1 region. Shopify provides app authentication and subscription approval. If a merchant requests an AI draft, a reduced case description is sent to the configured external AI provider. It omits order number and evidence files, but merchant-entered text could still include personal data. The AI draft feature may be unavailable when the provider is rate-limited.

Retention and requests

Evidence is encrypted by the app and expires after 30 days. Resolved or closed return cases, including their case history, are deleted 180 days after their most recent resolution or closure. Open cases remain available while the merchant is handling them. Operational audit records are removed after one year; unresolved privacy requests and failed deliveries remain until handled. Shopify customer-redaction requests remove identified order cases; shop-redaction requests remove the shop's app records. Data-access requests are recorded for manual follow-up, not fulfilled automatically. Customers should contact the merchant about a return or their personal data. Merchants can request access or deletion by contacting [email protected].