This Privacy Policy describes how FairReturns ("we," "us," "our," "the App") collects, uses, and shares information when a merchant installs and uses the FairReturns Shopify app, and when that merchant's customers use the FairReturns self-service return portal.
If you have questions about this policy or want to exercise your data rights, contact us at the email address shown above.
1Who this policy applies to
This policy covers two groups of people:
- Merchants: Shopify store owners who install FairReturns.
- End customers: shoppers who use a merchant's self-service return portal, powered by FairReturns.
2What information we collect
From merchants (via Shopify, when the app is installed)
- Shop name, domain, and Shopify store ID
- Store owner contact email (via Shopify's standard app installation data)
- Settings the merchant configures in the app (return window, restocking fee, allowed resolutions, support email, etc.)
- Billing and subscription plan information, processed through Shopify's App Pricing platform
From end customers (via the return portal)
- Order number and email address, used to verify a legitimate order
- Order and line item details already stored in the merchant's Shopify store (e.g. items purchased, order date, fulfillment status), as needed to determine return eligibility and process the requested resolution
- The reason for the return and any notes the customer enters
- The resolution chosen (refund, store credit, or exchange)
Return requests themselves are created as native Shopify returns on the merchant's own order. Shopify is the system of record for a return's status, items, reasons, fees, refunds and inventory. We keep a limited copy of this information in order to show the merchant a dashboard, apply their return rules, operate the customer portal and calculate app usage for billing.
We do not collect payment card details. All payment and refund processing is handled directly by Shopify's payment infrastructure; we never see or store card numbers.
3How we use this information
We use the information described above only to:
- Verify that a return request belongs to a real, existing order
- Apply the merchant's return rules (return window, excluded products, restocking fee) to determine eligibility
- Process the requested resolution (refund via Shopify's Admin API, store credit via Shopify's native store credit feature, or exchange tracking)
- Send status update emails to the customer (e.g., "return received," "return approved," "refund issued")
- Send the merchant a notification when a new return request comes in
- Show the merchant a dashboard of return activity (counts, reasons, amounts) — in aggregate, without export to third parties
- Calculate and report app usage to Shopify's billing system, strictly as required for the merchant's chosen subscription plan and any usage-based overage charges
We do not use this information for advertising, and we do not sell personal data to any third party.
4Who we share information with
We share data only with the following service providers, strictly to operate the app:
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | Core platform: order lookup, refunds, store credit, billing | Order, customer, and shop data, as permitted by the merchant's granted API scopes |
| Resend | Sending status update emails to customers and merchants | Recipient email address, order/return reference, email content |
We do not share data with advertisers, data brokers, or any party outside of running the core return process.
5Data retention
- The return itself lives on the merchant's Shopify order and is retained by Shopify under the merchant's own data retention terms, not ours. Our copy of it (including customer email, order reference, and resolution) is retained for as long as the merchant has the app installed, so the merchant can track return history and reporting.
- If a merchant uninstalls the app, we permanently delete the shop's stored data (settings, return requests and their line items, events, and billing usage records) within 48 hours, as required by Shopify's
shop/redactcompliance webhook. - If a customer or merchant submits a verified data erasure request for a specific customer (
customers/redact), we anonymize that customer's personal fields (email address, customer notes, and free-text return reasons) within Shopify's required timeframe. Refund amounts and refund/transaction IDs are retained without personal identifiers, as they are needed for the merchant's accounting records; the change is logged for traceability. - If a customer or merchant submits a verified data access request (
customers/data_request), we compile that customer's return request history and provide it to the merchant for onward disclosure, within Shopify's required timeframe. - Email delivery logs are retained only as long as necessary for delivery troubleshooting, and are not used for any other purpose.
6Your rights (GDPR and equivalent regional laws)
If you are located in the EU/EEA, UK, or a jurisdiction with similar data protection laws, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten"), subject to the merchant's legitimate business records requirements (e.g., financial/refund records that must be retained for accounting or legal reasons)
- Object to or restrict certain processing
- Data portability, where technically feasible
Because FairReturns processes end-customer data on behalf of the merchant (the merchant is the data controller for their store; we act as a data processor), requests about a specific order are usually best directed to the merchant first. You may also contact us directly at lxostudio.dev@gmail.com, and we will route the request appropriately or act on it directly where we control the data.
7Mandatory Shopify compliance webhooks
As required by Shopify for all public apps, FairReturns implements the mandatory compliance webhooks:
- customers/data_request — compiles a verified customer's return request history (email, order reference, items, reasons, notes) and provides it to the merchant for onward disclosure
- customers/redact — anonymizes a specific customer's personal fields (email, notes, free-text reasons) on their return requests, while retaining non-personal financial records for accounting purposes
- shop/redact — permanently deletes all of a shop's data (settings, return requests, events, billing records) 48 hours after app uninstallation
Every request is logged with its receipt date and a 30-day processing deadline, and is monitored for completion; requests are never silently dropped.
8Data security
We apply reasonable technical and organizational measures to protect stored data, including encrypted connections (TLS) between the app, Shopify, and our infrastructure. Database encryption at rest is a planned improvement not yet implemented in this early-access version. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9Children's data
FairReturns is a business-to-business tool intended for use by Shopify merchants and their adult customers. We do not knowingly collect data from children under 16. The return portal only processes data already tied to a real, adult-placed Shopify order.
10International data transfers
Our service providers (Shopify, Resend) may process data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, as provided by these vendors' own data processing agreements.
11Changes to this policy
We may update this Privacy Policy as the app evolves. Material changes will be reflected by updating the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
12Contact us
For any privacy-related question, request, or concern:
Email: lxostudio.dev@gmail.com Operator: Jochen Krippl, 4600 Wels, Austria