Plain-language notice
Privacy at ReturnRadar
Effective August 29, 2026
What we store
ReturnRadar stores the purchase information, settings, receipts, and product images you choose to provide. It does not collect full payment-card numbers or banking credentials.
Product lookup
Barcode decoding happens on your device. When you start a lookup, the barcode may be sent to the Open Facts product database. ReturnRadar uses the entered retailer, item, category, country, purchase method, purchase year, and optional product domain to construct a policy search. It may send the retailer name to Wikidata, check a retailer-derived website to verify its homepage branding and same-domain policy links, then send a site-restricted query to DuckDuckGo. It does not send the item price, full purchase date, receipt, or lookup to a generative-AI provider. Suggested details are not saved until you apply them and submit the form.
On-device receipt recognition
When you choose Read Receipt, Tesseract OCR runs in your browser. Its engine and language files may be downloaded on first use, but the receipt image stays on your device until you confirm and save. Unconfirmed recognized text stays in the current browser session. The private image and corrected details are stored in Supabase only after you review, confirm, and save.
Who can access stored purchases
Account protections and private file storage are designed so signed-in users can access only their own saved information.
ReturnRadar does not sell personal data, share it for cross-context behavioral advertising, or use Shopify customer information for unrelated marketing. It does not use personal data to make automated decisions with legal or similarly significant effects.
Closed beta and development data
ReturnRadar is operating as a small closed beta. Clearly labeled development-store, sandbox, fixture, and demo records are kept separate from real purchase and refund metrics. Manual tracking is available at no charge; paid carrier automation is disabled unless it is separately configured and disclosed.
Connected automation
A source marked unavailable or not configured does not access that account. If you enable an available source, ReturnRadar stores the structured fields, short evidence snippets, source references, and review history needed for your Action Inbox. You can pause processing, unlink findings, choose an imported-message retention period, and disconnect an available source from Settings.
Retailer return connections
If you explicitly connect a supported Shopify customer account, the retailer authenticates you and gives ReturnRadar a short-lived access token. ReturnRadar encrypts that token and, only when the provider supplies one, an encrypted refresh token. It may read the connected account’s orders, eligible line items, retailer return reasons, methods, and fee/refund calculation for the return you are reviewing. It stores the selected provider order and line identifiers, your confirmation, execution audit, connection health timestamps, and any real return authorization, label, QR code, or tracking evidence the retailer returns.
ReturnRadar never receives or stores the retailer password, MFA secret, or browser cookie. Nothing is submitted until you confirm the exact item, quantity, reason, condition, calculated refund, and fees. If the provider does not issue a refresh token, ReturnRadar asks you to reconnect after access expires. Disconnecting immediately deletes stored access and refresh tokens while retaining a redacted connection-status audit; account deletion removes connections and execution records. Audit records for a return already requested may remain until the ReturnRadar account is deleted.
A Shopify merchant connection is separate from a customer connection. During a production pilot, an explicitly participating merchant authorizes a minimal, encrypted Admin API token so ReturnRadar can receive signed return, reverse-delivery, processing, and refund webhooks. Merchant uninstall and Shopify privacy-deletion notices revoke stored access. ReturnRadar does not automatically approve a return, restock inventory, purchase a label, process a return, or issue a refund.
Participating merchants can review the categories, purposes, security commitments, subprocessors, and deletion assistance in the merchant terms and data protection addendum.
Forwarded email through Resend
When you enable your private forwarding address, Resend receives messages sent to that address and notifies ReturnRadar through a signed webhook. ReturnRadar retrieves the sender, recipients, subject, received time, plain text or sanitized HTML text, authentication results, and attachment metadata. It stores structured findings and a plain-text evidence excerpt until your selected retention period expires. Message HTML and attachment files are not retained in this release, and no generative-AI provider processes the message.
You can disable the address, rotate it, or delete retained imported messages and findings from Settings. Rotating or revoking an address invalidates the previous token without deleting audit summaries for actions you already confirmed.
Retention
Imported-message evidence is retained for the user-selected period of 7 to 365 days. Expired one-time OAuth state is removed after a one-day operational grace period. Shopify webhook delivery metadata is kept for up to 90 days, hashed Shopify privacy-request audit records for up to 365 days, and expired encrypted label references are erased when scheduled retention runs.
Purchase and return history remains while needed to provide an active account. Disconnecting or uninstalling revokes applicable access; verified Shopify deletion notices remove mapped provider records; deleting the ReturnRadar account removes its associated database records and private files.
Security and service providers
ReturnRadar uses HTTPS in transit, hosted encryption at rest, AES-256-GCM for provider credentials and sensitive label references, signed webhook verification, user-scoped database controls, and private file storage. It uses Shopify, Vercel, Supabase, Resend when forwarding is enabled, and an approved carrier provider when carrier tracking is enabled to operate the service.
Deadlines
Return dates are calculated from information you enter or suggestions you explicitly apply. OCR and policy-page extraction can be incomplete or outdated. Policies may have exclusions or change, so you remain responsible for checking the cited retailer sources and your receipt.
Control
You can delete an attached receipt and its recognized text from the purchase details, export purchase data, and request account deletion from Settings. Account deletion removes associated database records and stored files when the Supabase service role is configured.
Privacy questions can be sent to privacy@getreturnradar.com.