Privacy Policy
UnReturns is a returns management platform for Shopify stores, built by Alforeo Private Limited. It runs a store's returns — the request, the refund, exchange or store credit, and whatever comes back. This Privacy Policy explains how we collect, use, and protect your information when you install and use our app on your Shopify store.
01
What data we collect
When you install UnReturns, we collect your Shopify store domain and basic store information. From your Shopify store we collect order data, return and refund data, and customer names, email addresses and postal addresses.
When a customer opens the returns portal, we also collect what they give us there: the reason they select and anything they type to describe the problem, their phone number if they ask to be texted about the return, and — where the return is checked on camera — the photographs and video frames described in section 02. We record technical identifiers alongside each return: a hashed device identifier and a hashed IP address, used to recognise the same device or network across return requests.
We generate and store our own records about each return: a fraud score from 0 to 100, the reasons our model gave for it, the outcome of each camera step, and the decisions you or the app took. If a warehouse or 3PL inspects a returned item, we store their condition grade, notes and photographs too.
02
The camera check
Depending on the store’s settings and how a return is assessed, a customer may be asked to complete a live camera check in their browser. This is the central mechanism of the product, and it collects images of people and their surroundings.
During a check we capture still photographs and a sequence of video frames from the customer’s camera. These show the returned item and whatever else is in shot — which in practice can include the customer, their home interior, their packaging, their shipping label and their mailbox or doorstep. Where a store uses the pack-and-seal step, we capture a further set of frames of the item being boxed, together with a single-use seal code. Where a single-use challenge code is issued, we capture the customer displaying it. Frames are sent to our model provider for assessment while the session is running, at roughly one image every two seconds for the duration of the session.
These images are stored against the return and are visible to the merchant whose store the return belongs to. They may be included in a chargeback evidence pack that the merchant sends onward to their bank or card scheme if the customer disputes the payment. We record a SHA-256 hash of captured video at the point of capture so that a later copy can be shown not to have been altered.
We do not ask customers to show identity documents. Our instructions to the model explicitly forbid requesting a passport, driving licence, national ID card, or any other government-issued or official identity credential, and forbid requesting bank cards, statements or utility bills.
03
Why we collect this data
We use this data to assess return requests for fraud, and to carry out the return itself. Our AI analyses order history, return frequency, customer behaviour, timing and the camera evidence to produce a fraud score from 0 to 100. This helps you decide which returns to approve, decline, or review, and — where you have configured it to — lets the app take that decision automatically. We also use contact details to send the customer email or SMS updates about their return, and postal details to buy return shipping labels.
04
Third-party services
We use the following processors. Each receives only what it needs to do its job, and each processes that data on our instructions rather than for its own purposes.
- Google (Gemini API) — the model that assesses returns. It receives order and return data and the camera images themselves, including the still photographs and video frames described in section 02. This is the highest-volume outbound call the app makes.
- Supabase — our database and file storage. It holds everything described in section 01, including the images.
- Vercel — our hosting and serverless compute. Requests to the app pass through it.
- Resend— email delivery. It receives the recipient’s email address and the full contents of the message.
- Twilio— SMS and WhatsApp delivery, where a store has enabled it. It receives the recipient’s phone number and the full contents of the message.
- The shipping provider a store connects(for example Shippo) — return shipping labels and tracking, where a store has enabled them. A store uses its own account with its own provider. The provider receives the customer’s name and postal address.
- Browser push services — where a merchant or customer turns on web push notifications, the notification is delivered through the push service operated by their browser vendor (for example Google, Mozilla or Apple), which receives a per-device endpoint identifier.
We do not sell your data, and we do not share it with third parties for their own marketing or profiling.
05
Fraud signals across stores
UnReturns maintains a shared fraud-signal record. When a return is declined for fraud, or a chargeback is lost, or a warehouse inspection contradicts what was claimed, we record that signal against identifiers derived from the customer — their email address and the hashed device and network identifiers described in section 01. Those signals can raise the risk score of a later return by the same customer at a differentmerchant’s store using UnReturns.
A merchant sees that a signal exists and how severe it is. They do not see the other merchants’ identities, order contents or customer records.
06
What we do not collect
We do not store customer credit card numbers, payment details, or any sensitive financial instrument data. We do not ask for or knowingly store identity documents. We do not sell your data to third parties.
We do store photographs and video frames of customers and their surroundings, as set out in section 02. That is stated here because this is the section a reader checks to find out whether images are kept.
07
Data retention
We retain return-related data, including camera images, for as long as your merchant account is active. If you uninstall UnReturns from your Shopify store, associated data is deleted from our systems within 30 days.
One deliberate exception: a retired web-push subscription row is kept rather than deleted, so that a device which has been unsubscribed is not silently re-enrolled. If you want such a record removed, ask us using the contact details below and we will remove it.
08
Your rights (GDPR)
If you are located in the European Economic Area, you have the right to request a copy of your data or ask us to delete it. To exercise these rights, please email us at the address below and we will respond within 30 days. Requests for a copy are assembled by hand today; we will tell you what we hold and send it to you within that period.
09
Contact
If you have any questions about this Privacy Policy or would like to request data export or deletion, please reach out to us at support@unreturns.com.