← Back to home

Data Processing Agreement (DPA)

Last updated: July 30, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the merchant ("Data Controller," "you") and BrightLayer Lab LLC, a Virginia LLC that operates the Return Wise application ("Return Wise," "Data Processor," "we," "us"). This DPA governs the processing of personal data by the Data Processor on behalf of the Data Controller.


1. Definitions

2. Scope and Purpose

2.1 Subject Matter

The Data Processor processes personal data to provide the Return Wise return management service as described in the Terms of Service.

2.2 Duration

Processing continues for the duration of the merchant's use of the App, plus any retention period required to fulfill legal obligations or complete data deletion.

2.3 Nature and Purpose of Processing

Activity Purpose
Return request creation Process customer return requests on behalf of the merchant
Rule evaluation Determine return offer based on merchant-configured rules
Native store credit issuance Issue Shopify store credit refunds and optional bonus store credit transactions
Original-payment refund processing Create a Shopify refund to the customer's original payment method when the merchant or staff initiates it, or under a rule-driven automation the merchant has expressly enabled (including a capped returnless-refund offer accepted by the customer); apply configured review/approval controls and reconcile refund state via Shopify webhooks
Exchange processing When a customer chooses an exchange, create a Shopify draft/replacement order for the requested item(s), invoice any price-up difference to the customer, or issue any price-down remainder as store credit; where the merchant enables it, create the replacement before the returned item is received (instant exchange)
Return shipping label generation When the merchant enables return labels, generate a prepaid or pay-on-use return shipping label — and, where offered, a carrier QR code for box-free drop-off — by sending the return's ship-from (customer) and ship-to (merchant) addresses and parcel details to the merchant's configured shipping-label provider, and store the resulting label, tracking number, and drop-off context
Return tracking Retrieve or receive carrier tracking updates for a generated return label or for tracking-only carrier/number details the merchant enters independently (including for an uploaded external label), to drive customer/merchant status, optional transition notifications, and, where configured, time store-credit release. When a connected Shippo account is available for tracking-only registration, send Shippo only the merchant-entered carrier and tracking number — no customer address or contact details
Inventory restock When the merchant enables it, adjust Shopify inventory to restock returned items at a merchant-selected location
Return photo storage and display Store customer-uploaded photos of returned items in object storage and display them to the merchant for return review
Return-label file storage Where the merchant uploads a return-label file rather than generating one through a connected label provider, store that file in object storage and make it available through signed links (minutes when shown on screen, up to seven days when emailed to the customer)
Abuse detection Identify unusual return patterns to protect the merchant
Email notifications Send transactional emails related to return processing (available in the merchant's configured portal languages), and store each message — recipient, subject, headers, rendered body, and delivery state — to retry sends the mail provider does not accept, give the merchant a delivery history for a return, and let the merchant resend the original message
Outbound webhook delivery When the merchant configures a webhook endpoint, send signed return-event messages to the merchant's chosen destination URL and store each dispatch (destination, message body, delivery state) for retries, the merchant's delivery log, and merchant-initiated redelivery
Audit logging Record money-touching actions and settings changes in an audit trail for merchant accountability
Usage metering Count processed returns against the merchant's plan allowance and submit overage charge events to Shopify's billing system (no customer personal data is included in billing submissions)
Analytics Provide aggregated return metrics to the merchant
AI-assisted policy drafting When enabled by the merchant, draft suggested return rules and customer-facing copy from merchant-provided return policy text
AI return-reason classification When enabled by the merchant, categorize customer return reasons (intent, likely root cause, and an abuse-risk signal) to help the merchant understand and triage returns
AI photo review When enabled by the merchant (plan-dependent, off by default), send a short-lived signed link to a customer's return photo, plus product title, variant title, and return-reason code, to the AI provider to evaluate the visible condition of the returned item; the results are suggestions surfaced for the merchant's review and do not decide any refund
Return fee assessment Apply merchant-configured return fees and deduct them from the refund or store-credit amount
Approval workflow Route money-touching actions to a manager for approval based on merchant-configured thresholds, recording the requesting and deciding staff
Shopify Sidekick assistant (optional, merchant-invoked) When the merchant asks Shopify's built-in Sidekick assistant about returns, return read-only return data (order number, customer email, status, payout type, refund/credit amounts and currency, selected return reason codes — never free-text notes — item counts and return submission dates, and — on abuse-guardrail plans — abuse-flag risk score, reason, and blocked status) so Sidekick can answer; the data returns to the Shopify platform (Shopify's own tool) and no money-touching action is taken. This access is recorded in the protected-customer-data access log, except for aggregate-metrics queries, which return no customer-linked data

2.4 Categories of Data Subjects

2.5 Types of Personal Data Processed

3. Obligations of the Data Controller

The Data Controller shall:

  1. Ensure there is a lawful basis for processing personal data through the App
  2. Inform data subjects about the processing in accordance with Articles 13 and 14 of the GDPR
  3. Maintain an accurate compliance contact email address in the App settings for privacy and data-rights communications
  4. Respond to data subject requests within the timeframes required by applicable law
  5. Configure appropriate data retention periods in the App settings
  6. Ensure that any instructions given to the Data Processor comply with applicable data protection law
  7. Notify the Data Processor without undue delay if they become aware of any data breach involving data processed by the App

4. Obligations of the Data Processor

The Data Processor shall:

4.1 Processing Instructions

4.2 Confidentiality

4.3 Security (Article 32 GDPR)

Implement appropriate technical and organizational measures, including:

4.4 Sub-processors

Current sub-processors:

Sub-processor Purpose Data Processed
Shopify Platform provider, API services, native store credit refunds, original-payment refunds, bonus credit transactions, and subscription/usage billing Order data, customer data, store credit and refund transaction data, plan usage and overage charge events (no customer personal data in billing events)
Resend (resend.com) Transactional email delivery (merchant and customer notifications) Recipient email addresses, message subject and body content (order numbers, return details, store credit amounts)
Render (render.com) Application hosting and database storage All application data
Cloudflare R2 (cloudflare.com) Object storage for customer-uploaded return photos and for return-label files the merchant uploads (S3-compatible; EU-jurisdiction bucket for EU/EEA merchants) Return photo image files and storage metadata (file type, size, object key); return-label files uploaded by the merchant, which contain the customer's name and return shipping address as printed on the label
OpenAI (openai.com) Three optional, merchant-enabled features: (1) AI policy assistant — drafting suggested return rules and customer-facing copy; (2) AI return-reason classifier (plan-dependent) — categorizing return reasons into intent, root cause, and an abuse-risk signal; (3) AI photo review (plan-dependent, off by default) — evaluating the visible condition of items in customer return photos for the return reasons the merchant selects (1) Policy assistant: merchant-provided return policy text, the store's product types and product tags (catalog metadata retrieved from Shopify, used to ground the drafted rules in the merchant's real catalog — not customer data), and the structured AI draft output; no return, order, customer, customer-tag, abuse-flag, or photo data is sent for this feature. (2) Reason classifier: per returned item, the product and variant title, the selected return reason, and the customer's free-text reason note — automatically redacted to remove email addresses and card-like/long numeric sequences, then truncated. No order numbers, customer names or email addresses, customer tags, order or customer records, abuse flags, or photos are sent for this feature. (3) Photo review: a short-lived (10-minute) signed link to the customer's return photo, which OpenAI's service fetches, plus the product title, variant title, and the return-reason code; no customer name, email address, or free-text reason note is sent. OpenAI's API data is not used to train its models under OpenAI's default API data policy. Calls are sent with OpenAI storage/logging disabled (store=false); under OpenAI's standard API data policy OpenAI may retain inputs and outputs for up to 30 days to monitor abuse/misuse and then deletes them (longer only where legally required).
Shipping-label/tracking provider — Shippo (goshippo.com), EasyPost (easypost.com), or ShipStation (shipstation.com), whichever the merchant connects Optional, merchant-enabled: generate return shipping labels and, where offered, carrier QR codes for box-free drop-off, and retrieve carrier tracking. Shippo may also register a merchant-entered third-party tracking number, including one from an uploaded external label. The merchant connects their own carrier/label account, so the provider also processes this data under the merchant's own agreement with that provider Label generation: the return's ship-from (customer) and ship-to (merchant return location) addresses — recipient name, street address, city, state/province, postal code, country, and where available phone and email — plus parcel dimensions, resulting label URL, and carrier tracking number. Tracking-only Shippo registration: carrier name and tracking number only; no customer address/contact information. Neither path sends order history, return reasons, store-credit amounts, abuse flags, or photos

Merchant-configured webhook endpoints are not sub-processors. Where the Data Controller enables outbound webhooks (an optional, plan-dependent feature that is inactive unless the Data Controller configures a destination and a signing secret), the Data Processor sends signed return-event messages to a destination URL the Data Controller chooses. Those messages carry the shop domain, the return request and order identifiers, the order number, the return status, the chosen payout type, and the refund or store credit amount and currency; no customer name, email address, shipping address, return reason, reason note, or photo is included. The Data Processor does not select, control, or contract with the destination — the Data Controller instructs the disclosure and is the controller of any onward processing at that endpoint.

The public marketing website is outside this DPA. The Return Wise marketing and legal pages at returnwise.app are served through Cloudflare's edge delivery, DNS, and DDoS protection, and use a cookieless website-analytics measurement that sets no identifier on the visitor's device. Those services process ordinary request metadata of website visitors (such as IP address, user-agent, and request timing) and never receive the Data Controller's customer return data. They are therefore not sub-processors of the processing governed by this DPA, and are not listed above; they are described in the Privacy Policy, where the Data Processor acts as an independent controller. This role is distinct from Cloudflare R2's role as the App's object-storage sub-processor, which is listed above.

The Data Processor shall:

4.5 Data Subject Requests

4.6 Data Breach Notification

4.7 Data Protection Impact Assessments

5. Data Retention and Deletion

5.1 Retention Period

5.2 Deletion or Return on Termination

In accordance with Article 28(3)(g) of the GDPR, the Data Controller may choose either deletion or return of personal data at the end of the provision of services. At any time during the term of the service or before uninstalling the App, the Data Controller may self-serve a data export from the authenticated Return Wise admin (Settings → Compliance → "Export all shop data"; this export is available to the store owner), which produces a structured, commonly used, and machine-readable JSON archive of the personal data processed on behalf of the Data Controller. Because the archive is JSON, uploaded return-photo and shipping-label files are referenced by their metadata (and remain individually downloadable from each return's detail page until deletion) rather than embedded as binaries, and the rendered bodies of stored transactional emails are represented by their metadata (recipient, subject, and delivery state). The archive includes the carrier tracking-registration and notification-decision records and the protected-customer-data access log, alongside the other collections listed in the deletion list below (excluding only the authentication session data, which is the Data Processor's own controller-side record of the merchant account rather than data processed on the Data Controller's behalf). An individual customer's data-subject export handled under Section 4.5 likewise includes that customer's carrier tracking records. If the Data Controller is unable to access the admin, the Data Processor will, on written request to support@returnwise.app, use commercially reasonable efforts to provide an equivalent export by an alternative secure channel within 30 days. In the absence of a return request before the deletion timelines below take effect, the Data Processor will delete the personal data as the default. The Data Processor shall delete existing copies of personal data after deletion or return is complete, unless retention is required by applicable law.

Upon termination of the service (app uninstallation):

5.3 Customer-Level Deletion

Upon receiving Shopify's customers/redact webhook:

6. International Transfers

The application and database are hosted on Render (render.com) with servers located in the United States. Personal data from Data Subjects in the European Economic Area (EEA), the United Kingdom, or Switzerland will be transferred to and processed in the United States.

Geographic availability. The App is not currently offered to Data Controllers established in the EEA, the United Kingdom, or Switzerland (Terms of Service, Section 3 — a limitation the App enforces technically at the store level). The mechanisms in this Section 6 accordingly govern (a) any processing of personal data of Data Subjects located in those jurisdictions carried out on behalf of a Data Controller established elsewhere, and (b) transfers from Data Controllers established in those jurisdictions if and when the App becomes available to them.

EU data residency for stored files: Customer-uploaded return photos, and any return-label file uploaded by the merchant, for Data Controllers established in the EU/EEA are stored in an EU-jurisdiction object storage bucket (Cloudflare R2) rather than the default United States bucket. All other application data is processed in the United States under the transfer mechanisms below. Because the App is not currently offered to Data Controllers established in the EEA (Section 6, Geographic availability), this residency path is not in use today: a served Data Controller's stored files are held in the United States regardless of where that Data Controller's own customer is located.

6.1 EU Standard Contractual Clauses (Controller-to-Processor Transfers)

For transfers of personal data from the EEA to a third country that lacks an adequacy decision under Article 45 of the GDPR, the parties incorporate by reference the Standard Contractual Clauses (Module Two — Controller to Processor) adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (the "EU SCCs"). The Data Controller is the data exporter and the Data Processor (BrightLayer Lab LLC) is the data importer. The optional and modular elements of the EU SCCs are completed as follows:

6.2 UK International Data Transfer Addendum

For transfers of personal data from the United Kingdom, the parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner's Office under section 119A of the UK Data Protection Act 2018 (the "UK Addendum"), read together with the EU SCCs in Section 6.1. Tables 1, 2, and 3 of the UK Addendum are completed by reference to the EU SCCs and the corresponding sections and annexes of this DPA. In Table 4, neither party objects to changes to the Approved Addendum issued by the ICO from time to time.

6.3 Swiss Transfers

For transfers of personal data subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs in Section 6.1 apply with the following adaptations: references to the "GDPR" are read as references to the FADP where the FADP applies; the supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and Swiss law governs transfers concerning Swiss-only data subjects.

6.4 Sub-processor Onward Transfers

Where the Data Processor's sub-processors transfer personal data outside the EEA, the United Kingdom, or Switzerland, those onward transfers are governed by the Standard Contractual Clauses, UK Addendum, and Data Processing Addenda published by each sub-processor listed in Section 4.4.

6.5 Adequacy

Where an adequacy decision under Article 45 of the GDPR or an equivalent UK or Swiss adequacy mechanism covers the destination country, the parties may rely on that adequacy decision in lieu of the SCCs and the UK Addendum.

7. Audit and Compliance Information

On reasonable written notice, and no more than once per calendar year (except where required by a supervisory authority or following a confirmed security incident affecting the Data Controller's data), the Data Controller may request:

The Data Controller acknowledges that, as a small software operator, the Data Processor's ordinary means of demonstrating compliance are the questionnaire responses and the sub-processor and technical-and-organizational-measures documentation described above, and that the Data Processor does not maintain the infrastructure to provide direct, unsupervised access to production systems or personnel; any independent audit will be limited as set out above. Where an audit or inspection is compelled by a supervisory authority or required by applicable law, the Data Processor will cooperate in good faith with the Data Controller and the authority to respond to the specific request.

8. Liability

Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service, except where applicable data protection law does not permit such limitations.

9. Governing Law

This DPA is governed by the same law that governs the Terms of Service between the parties, except for Section 6 (International Transfers), where the EU SCCs and the UK Addendum carry their own governing law and choice of forum as set out in Sections 6.1 and 6.2.

10. Contact

Data Processor contact for data protection matters:

The Data Processor's registered legal address is published in the Return Wise Privacy Policy.


By installing and using Return Wise, the Data Controller accepts this Data Processing Agreement as part of the Terms of Service.