Security Overview
UnReturns is a returns management platform for Shopify stores, operated by Alforeo Private Limited. It handles return requests, refunds, exchanges and store credit on a merchant's behalf, and it holds the customer identifiers and captured media that go with them. This page describes how that data is protected, exactly what the cross-store risk network shares, and what we do if something goes wrong.
What the risk network shares
Cross-store risk signals are stored as salted SHA-256 digests of a customer identifier — an email address, phone number, address or device. The value is lowercased and trimmed before hashing so the same person matches across stores, and the digest is salted with an application secret, so the stored value cannot be reversed by hashing a list of candidate email addresses.
No email address, no customer name and no order contents are shared between stores. Another merchant can learn that a digest they are also seeing has a history; they cannot learn who it belongs to.
IP addresses score zero toward risk, deliberately. Shared office networks and mobile carrier NAT put large numbers of unrelated people behind one address, so an IP match is surfaced to a merchant as a weak link and is never used to decline anyone.
Credentials and data at rest
Shopify access tokens and third-party API keys are encrypted at rest with AES-256-GCM before being stored. Application data is held in Supabase (Postgres) and served through Vercel.
Webhook authenticity
Every Shopify webhook we accept is verified by recomputing its HMAC signature over the raw, unparsed request body and comparing it with a constant-time comparison, so a near-miss signature cannot be discovered by timing the response. A request that fails verification is rejected and nothing is written.
Shopify's three mandatory privacy topics — customers/data_request, customers/redact and shop/redact — are authenticated the same way, and the two redaction topics erase the data they name. The data-request topic is acknowledged and recorded, but does not yet assemble the response automatically: we answer subject-access requests by hand, within the 30 days our Privacy Policy commits to.
Evidence integrity
Camera frames and warehouse photos are stored against the return they belong to. Chargeback evidence packs record a SHA-256 hash of the frames taken at the moment of capture, alongside the algorithm used, so the file submitted to a card network can be shown to be the file that was recorded. Any modification produces a different hash.
Incident response
The sections below describe how we respond to a security incident involving personal data processed on behalf of merchants.
1.Scope
A security incident is any unauthorized access, disclosure, loss, or alteration of personal data processed by UnReturns.
2.Detection
We monitor application logs and alerts from our infrastructure providers (Vercel, Supabase) for unauthorized access or unusual activity.
3.Containment
On discovering an incident, we act immediately to contain it — revoking compromised credentials, rotating API keys and access tokens, and restricting access to affected systems.
4.Assessment
We determine what data was affected, which merchants and customers are impacted, and the cause.
5.Notification
We notify affected merchants without undue delay and within 72 hours of becoming aware of a personal data breach, and notify Shopify as required. Where legally required, we assist merchants in notifying affected individuals and regulators.
6.Remediation
We fix the root cause, restore from secure backups if needed, and document the incident and the steps taken to prevent recurrence.
7.Contact
Report security concerns to: support@unreturns.com