For participating Shopify merchants
Merchant terms and data protection addendum
Effective August 29, 2026
Agreement and scope
These terms apply when a merchant installs, authorizes, or uses the ReturnRadar Shopify integration. The merchant instructs ReturnRadar to process the minimum Shopify order and return information needed to help an authenticated customer prepare, submit, and track a return. These terms supplement the merchant’s agreement with Shopify and ReturnRadar’s privacy notice.
Installation or continued authorized use of the integration constitutes acceptance of these terms. A merchant that does not accept them must not install the integration and may uninstall or revoke access at any time.
Current availability
The current verified Shopify workflow is limited to ReturnRadar’s development store and test data. Production merchant processing is not available until an authorized merchant accepts these terms, installs the app, required protected-customer-data access is approved, credentials and signed webhooks pass health checks, and an owner-authorized verification run is complete.
Processing instructions and purpose
ReturnRadar processes Shopify data only to authenticate the connection, match an authenticated customer to eligible orders and line items, calculate retailer-provided return choices and fees, submit a customer-confirmed request, receive signed return and refund events, provide support, prevent abuse, and maintain a limited security and compliance audit.
ReturnRadar does not use merchant customer data for targeted advertising, unrelated marketing, data brokerage, credit decisions, employment decisions, insurance decisions, or other automated decisions with legal or similarly significant effects.
Data categories and people
The integration may process shop and installation identifiers; order, line-item, SKU, quantity, and return-eligibility identifiers; retailer return reasons and methods; fees and expected refund calculations; return authorization, label, tracking, lifecycle, and refund evidence; short-lived encrypted credentials; and hashed references supplied in Shopify privacy requests.
ReturnRadar does not request the optional Shopify protected fields for customer name, postal address, or phone number. It does not receive merchant or customer passwords, MFA secrets, browser cookies, full payment-card numbers, or banking credentials.
Merchant responsibilities
The merchant is responsible for having authority to connect ReturnRadar, providing lawful instructions, maintaining accurate customer-facing return policies, responding to return requests, and using Shopify’s privacy tools when a customer exercises a data right. The merchant must not instruct ReturnRadar to process data for an unlawful or unrelated purpose.
Confidentiality, security, and subprocessors
ReturnRadar limits production access to authorized operations, uses user-scoped database controls and private storage, verifies Shopify webhook signatures, encrypts provider credentials and sensitive label references with AES-256-GCM, and uses HTTPS for data in transit. ReturnRadar will take reasonable steps to contain and investigate a confirmed security incident and notify affected merchants when legally required.
ReturnRadar relies on service providers such as Shopify, Vercel, Supabase, Resend when email forwarding is enabled, and an approved carrier-tracking provider when that feature is enabled. They process data only to provide their contracted infrastructure or integration services.
Retention and deletion
Expired one-time OAuth state is removed after a one-day operational grace period. Shopify webhook delivery metadata is retained for up to 90 days. Hashed Shopify privacy-request audit records are retained for up to 365 days. Imported-message evidence follows the user-selected period of 7 to 365 days. Expired encrypted label references are erased when the retention job runs.
Active purchase and return records are kept while needed to provide the customer’s account history. Customer account deletion removes associated records and private files. Disconnect, uninstall, customer-redaction, and shop-redaction events revoke or erase applicable credentials and mapped provider records. ReturnRadar does not retain raw Shopify webhook payloads.
Customer rights and merchant assistance
ReturnRadar receives Shopify’s required customer-data access, customer-redaction, and shop-redaction notices. It erases mapped records for deletion notices and places access requests into a restricted owner-review queue so responsive information can be provided to the merchant. ReturnRadar will reasonably assist a merchant with a verified request concerning data processed by the integration.
No sale of customer data
ReturnRadar does not sell merchant customer personal data, share it for cross-context behavioral advertising, or retain it for an independent commercial purpose. Infrastructure providers are used to operate the service and are not authorized by ReturnRadar to sell the data.
Changes, termination, and contact
ReturnRadar may update these terms when the integration or legal requirements change. Material changes will be communicated through the app or Shopify listing before they take effect when reasonably possible. Either party may end the integration at any time by uninstalling it or revoking access.
Privacy and data-protection questions can be sent to privacy@getreturnradar.com or through the support channel in ReturnRadar’s Shopify listing.