Privacy Policy
Last updated: July 5, 2026
1. Introduction
BrightLayer Lab LLC ("we," "us," "our") operates the Return Wise application ("App"), a Shopify application that helps merchants manage product returns by offering customers store credit (with optional bonus incentives), a refund to their original payment method, or an exchange for a different item. Where the merchant enables it, the App can also generate a return shipping label for the customer. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our application.
2. Data Controller and Processor Roles
Under the General Data Protection Regulation (GDPR) and similar data protection laws:
- For merchant customer return data, the merchant who installs Return Wise is the data controller. They determine the purposes and means of processing their customers' personal data.
- BrightLayer Lab LLC (Return Wise) acts as a data processor for that merchant customer return data when we process it to provide the return management service.
- For merchant account, session, support, security, admin-activity (audit trail), and compliance-contact data relating to use of the App itself, BrightLayer Lab LLC acts as an independent data controller. Audit entries that document a specific customer's return are treated as part of that customer's return data and follow it (including deletion on erasure requests).
3. Data We Collect
3.1 From Merchants (via Shopify)
- Shop domain and Shopify store identifier
- Merchant/admin account information made available by Shopify, such as user email, first name, last name, locale, and account status
- Merchant notification email address (if configured)
- Merchant-designated compliance contact email address
- App configuration and settings
- Return policy text a merchant pastes into the optional AI policy assistant (Growth/Pro), to the extent it contains personal data
- Admin activity (audit trail): Actions taken in the app admin (for example approving a return, issuing a refund, or changing settings) are recorded with the acting staff member's email address and, for staff-initiated actions, the IP address and browser user-agent string of the request. BrightLayer Lab LLC acts as an independent controller for these staff-activity records (see Section 2); audit entries that document a specific customer's return are treated as that customer's return data and are deleted with it. The trail exists to give merchants an accountability record of money-touching actions and settings changes.
3.2 From Customers (via Merchant's Store)
When a customer looks up an order or initiates a return through a merchant's store — via the storefront return portal or, where the merchant enables it, the customer's Shopify customer account — we collect or process:
- Order lookup information: Order number and email address submitted in the return portal
- Order information: Order number, order ID, line items, product titles, variant details, item prices, and currency
- Customer contact information: Email address
- Customer identifier: Shopify customer ID (if available)
- Return details: Selected items, return reasons, reason notes, quantities, and — where the customer requests an exchange — the requested replacement variant(s)
- Item photos: Where the merchant's plan includes photo upload, customers may optionally attach photos of the items they are returning. Photos are stored in object storage (see Sections 6 and 11) and shown to the merchant to support return review. Customers are asked to photograph the item only; any personal data incidentally visible in a photo is processed only as part of the image.
- Return shipping address: Where the merchant enables return shipping labels, the customer's order shipping address — recipient name, street address, city, state/province, postal code, country, and any phone number on the order — is retrieved from the order and sent to the merchant's chosen shipping-label provider to generate the return label. For box-free drop-off, the postal code and country are also used to locate nearby drop-off points. This address is processed only when the merchant generates a label for the return.
- Fulfillment data: Fulfillment dates associated with returned items
- Customer tags: Retrieved from Shopify for rule evaluation (e.g., loyalty status)
- Security and request metadata: IP address and related request metadata used for rate limiting, abuse prevention, and operational security
3.3 Data We Generate
- Return request records (status, timestamps, idempotency keys)
- Native store credit references, including Shopify refund IDs, store credit account IDs, and bonus store credit transaction IDs
- Original-payment refund records, including Shopify refund IDs, the confirmation source, and completion timestamps
- Exchange records: the requested replacement item(s) and references to the Shopify draft or replacement order created to fulfill an exchange
- Return shipping label records (where the merchant enables labels): the carrier and tracking number, label and QR-code links, drop-off location context (postal code and country), and label cost
- Abuse detection flags
- Rule evaluation records and the audit trail described in Section 3.1
- Plan usage counters and overage charge records used for billing (return counts per billing period and per-return overage charge entries; see the Terms of Service for billing mechanics)
- Analytics aggregates (return volumes, savings metrics)
- AI policy-assistant drafts: suggested return rules, settings, and customer-facing copy generated from merchant-provided policy text, stored as draft records until the merchant applies or discards them
- AI return-reason classification results: for merchants who enable the optional classifier, a structured categorization of each return reason (return intent, likely root cause, an abuse-risk signal, and a confidence value), stored alongside the return item
- AI photo evaluations (where the merchant enables AI photo review on Pro): suggested product-condition tags, a descriptive severity, a confidence score, and usage/wear signals generated from a customer's return photo, stored alongside the photo record together with any tag corrections the merchant makes. These are suggestions to assist the merchant's review; they do not make or automate the refund decision
3.4 Data We Do NOT Collect
- Payment card numbers or bank account details
- Passwords or authentication credentials
- Customer browsing behavior or tracking cookies
We do not collect the customer's physical address for order lookup, return eligibility, refunds, or store credit. The only circumstance in which the App processes a customer's shipping address is when the merchant enables return shipping labels and generates a label for the return, as described in Section 3.2; in that case the address is retrieved from the order solely to produce the return label and is shared only with the merchant's chosen shipping-label provider (see Section 6). It is not used for marketing, profiling, or any other purpose.
4. How We Use Data
We process personal data solely to provide the return management service:
- Processing returns: Creating and managing return requests, evaluating rules, issuing store credit
- Original-payment refunds: Creating a Shopify refund to the customer's original payment method when the merchant initiates one (the App never initiates a refund without explicit merchant action)
- Return review: Storing customer-submitted item photos and displaying them to the merchant so the merchant can assess the returned item's condition
- Exchanges: When a customer chooses an exchange, creating a Shopify draft or replacement order for the requested item, invoicing any price-up difference or issuing any price-down remainder as store credit
- Return shipping labels: When the merchant enables it, generating a return shipping label (and, where offered, a carrier QR code for box-free drop-off) by sending the return's addresses and parcel details to the merchant's chosen shipping-label provider, retrieving carrier tracking, and emailing the label or tracking link to the customer
- Fraud prevention: Detecting unusual return patterns to protect merchants from abuse
- Notifications: Sending transactional emails (return confirmation, credit issuance, rejection notices)
- Guest customer support: Creating or locating a minimal Shopify customer record and attaching it to an order when needed to issue native Shopify store credit
- Analytics: Providing merchants with aggregated return statistics (no individual customer profiling)
- Native store credit issuance: Creating Shopify store credit refunds for eligible return amounts and optional bonus store credit transactions
- AI-assisted setup: When a merchant chooses to use the optional AI policy assistant, drafting suggested return rules and customer-facing copy from the merchant-provided return policy text
- AI-assisted return analysis: When a merchant enables the optional AI return-reason classifier, categorizing return reasons to surface return intent, likely root cause, and abuse-risk signals that help merchants understand and triage returns (see Sections 6 and 9)
- Security and reliability: Rate limiting request flows, validating sessions, and monitoring the service
- Accountability: Maintaining an audit trail of actions taken in the app admin (see Section 3.1) so merchants have a reviewable record of money-touching actions and settings changes
- Billing administration: Counting processed returns against the merchant's plan allowance and, where the merchant has enabled it, submitting per-return overage charges through Shopify's billing system (no customer personal data is included in billing submissions)
- Compliance handling: Delivering privacy and data-rights communications to the merchant-designated compliance contact email on file
We do not use customer data for marketing, advertising, or cross-context behavioral profiling, or for any purpose unrelated to the return management service. We may use automated analysis of return history, refund values, return-pattern signals, and — where the merchant enables it — AI classification of return reasons, for fraud and abuse prevention and return triage, as described in Sections 6 and 9.
5. Legal Basis for Processing (GDPR)
For customer return data, the merchant — as the data controller — determines and documents the legal basis for processing under Article 6 of the GDPR. Common legal bases that may apply, depending on the merchant's policies and customer relationship, include:
- Performance of a contract (Art. 6(1)(b)) — for processing return requests and sending transactional emails about a return
- Legitimate interest of the merchant (Art. 6(1)(f)) — for fraud and abuse prevention and for aggregated return analytics
Merchants are responsible for confirming and documenting the legal basis applicable to their store and informing customers in their own privacy notice. The limited categories of data Return Wise processes as an independent controller (merchant account, support, security, admin-activity, and compliance-contact data) are described in Section 2.
6. Data Sharing
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising (within the meaning of the California Consumer Privacy Act, as amended by the California Privacy Rights Act). We disclose personal data only to the service providers and sub-processors listed below, who process data on our behalf to operate the return management service:
- Shopify: Data is read from and written to Shopify via their Admin API. Reads include order lookups, customer records, and customer tags (used as inputs to rule evaluation only). Writes include native store credit refunds, bonus store credit transactions, return summary details added to Shopify order notes, and order tags applied for merchant record-keeping (e.g., "ReturnWise-Credit"); for guest orders, the App may also create or locate a minimal customer record and attach it to the order so native store credit can be issued. The App does not write customer tags. Data written to Shopify's platform is governed by Shopify's own privacy policy and persists independently of Return Wise.
- Hosting provider: The application and database are hosted on Render (render.com), which acts as a sub-processor. Render's privacy policy and data processing terms apply to infrastructure-level data handling.
- Object storage (return photos): Customer-uploaded return photos are stored in Cloudflare R2 (cloudflare.com), an S3-compatible object storage service, which acts as a sub-processor for this data. Photos are uploaded by the customer's browser and read by the merchant's photo viewer via short-lived signed URLs; the storage buckets are not publicly listable. Photos for merchants established in the EU/EEA are stored in an EU-jurisdiction bucket (see Section 11). Photo files are deleted from storage when the associated return records are deleted (see Section 7).
- Email delivery: Transactional emails are sent via Resend (resend.com), a transactional email provider configured and operated by Return Wise. Resend receives recipient email addresses and message content (order numbers, return details, store credit amounts, and links) in order to deliver the email. Return Wise does not persist email body content after handoff, but Resend may retain message data, delivery events, and logs under its own privacy policy and Data Processing Addendum. GDPR data export payloads are deliberately excluded from email content — those snapshots are retrieved by the merchant from the authenticated app admin.
- Shipping-label provider (return labels): Where a merchant enables return shipping labels, Return Wise sends the return's addresses and parcel details to the merchant's chosen provider — Shippo, EasyPost, or ShipStation — to generate the return label and (where offered) a carrier QR code, and to retrieve carrier tracking. The merchant connects their own carrier/label account, so the provider also acts under the merchant's own agreement with that provider. The provider receives the ship-from (customer) and ship-to (merchant return location) addresses — recipient name, street address, city, state/province, postal code, country, and, where available, phone and email — plus parcel dimensions, and returns the label and tracking number. No order history, return reasons, store-credit amounts, abuse flags, or photos are sent, and data is sent only when a label is generated for a return.
- AI service provider: Return Wise uses OpenAI (openai.com) as a sub-processor for two optional, merchant-enabled features:
- AI policy assistant: Return Wise sends the merchant-provided return policy text and receives structured draft rules and customer-facing copy. No historical return records, order records, customer records, customer tags, abuse flags, or return photos are sent for this policy-drafting feature.
- AI return-reason classifier (a plan-dependent feature that is off unless the merchant enables it): to categorize why items are being returned, Return Wise sends, per returned item, the product and variant title, the selected return reason, and the customer's free-text reason note, and receives back a structured classification (return intent, likely root cause, and an abuse-risk signal). Before transmission, free-text reason notes are passed through an automated redaction step that removes email addresses and card-like or long numeric sequences, and are truncated to a short length. Order numbers, customer names, customer email addresses, customer tags, order or customer records, abuse flags, and return photos are not sent for this feature. Because reason notes are free text, a customer could include other personal details in them; the redaction step is automated and not guaranteed to catch every such detail.
- AI service provider (return photos): If a merchant enables AI photo review (an optional Pro feature, off by default), Return Wise asks OpenAI (openai.com) to evaluate the visible condition of items in customer return photos for the return reasons the merchant selects. To do this, Return Wise generates a short-lived signed link to the photo — valid for 10 minutes — which OpenAI's service fetches to perform the evaluation; the link expires shortly afterward and the image is not made publicly accessible. Return Wise sends only the photo and minimal product context (product title and the return reason code); it does not send customer names, email addresses, or the customer's free-text notes for this feature. The AI is instructed to describe only the product and its packaging and never to identify people or infer personal characteristics. This processing is governed by OpenAI's API data usage policies, including OpenAI's default policy that API inputs are not used to train OpenAI models unless the API customer explicitly opts in.
- As required by law: We may disclose data to comply with legal obligations, court orders, or government requests.
Website infrastructure (visitors to the public site): The public Return Wise marketing and legal pages on returnwise.app are served via Cloudflare (cloudflare.com), which provides edge delivery, DNS, and DDoS protection. Cloudflare processes standard request metadata for visitors to the public site (IP address, User-Agent, request timing) at the network edge. This edge-delivery role for the public website is separate from Cloudflare R2's role as the App's photo storage sub-processor described above; the App's data flows and complete sub-processor list are governed by Section 4.4 of the Data Processing Agreement.
7. Data Retention
- Return request data is retained according to the merchant's configured retention period (default: 12 months, configurable from 1 to 60 months).
- Terminal return records (completed, rejected, or failed) older than the retention period are removed by our scheduled retention cleanup process, which is ordinarily run daily.
- Customer-uploaded return photos follow their return records: when a return record is deleted — by the retention cleanup, a customer erasure request (
customers/redact), or shop data deletion — the stored photo files are deleted from object storage as part of the same process. A daily reconciliation sweep additionally removes any stored photo file that no longer has (or never had) an associated return record, covering uploads abandoned before a return was submitted and rare transient deletion failures; such failures are also surfaced to our operations alerting. - Audit trail records are retained for 18 months by default and then removed by the scheduled cleanup; they are also deleted as part of shop data deletion, and audit entries tied to a specific customer's returns are deleted when that customer's data is erased.
- GDPR data export snapshots compiled in response to
customers/data_requestwebhooks are retained inside the authenticated app admin and auto-purged 30 days after the request is received, regardless of fulfillment status. - AI policy-assistant drafts: applied drafts are retained alongside the shop's settings and audit history; discarded or unused drafts are auto-purged 30 days after creation by the scheduled cleanup; all drafts are deleted when the shop's data is deleted (see below).
- Merchants can adjust their retention period at any time in the app settings.
- Upon app uninstallation, Shopify sends an
app/uninstalledwebhook and (ordinarily 48 hours later, under Shopify's compliance schedule) ashop/redactwebhook. Return Wise marks the shop onapp/uninstalledand preserves its configuration during a short reinstall grace period (approximately 48 hours), so a merchant who reinstalls within that window does not lose their settings. After the grace period elapses, Return Wise's scheduled cleanup permanently deletes all shop data. Ifshop/redactarrives, Return Wise deletes all shop data immediately, without waiting for the grace period. Note that data previously written to Shopify (such as order notes and order tags) is managed by Shopify and is not affected by this deletion.
8. Data Subject Rights (GDPR / UK GDPR / Australian Privacy Act / LGPD)
Customers may exercise the following rights by contacting the merchant (data controller):
Under GDPR / UK GDPR:
- Right of access: Request a copy of personal data we hold
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of personal data
- Right to data portability: Receive data in a structured, machine-readable format (JSON)
- Right to object: Object to processing based on legitimate interest
- Right to restrict processing: Request limitation of processing
- Right to lodge a complaint: File a complaint with a data protection supervisory authority in your country of residence
Under the Australian Privacy Act 1988:
- Right of access: Request access to personal information we hold about you (APP 12)
- Right to correction: Request correction of inaccurate, out-of-date, incomplete, or misleading personal information (APP 13)
- Right to complain: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached
Under the Brazilian Lei Geral de Proteção de Dados (LGPD):
- Confirmation and access (Art. 18, I–II): Confirm whether we process your personal data and access it
- Correction (Art. 18, III): Request correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion (Art. 18, IV): Request anonymization, blocking, or deletion of unnecessary or excessive data
- Portability (Art. 18, V): Receive your data in a structured, machine-readable format
- Information about sharing (Art. 18, VII): Be informed of the public and private entities with which your data has been shared (see Section 6)
- Right to petition: Lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD)
When a merchant receives a data subject request, we support them by:
- Data export: Upon Shopify's
customers/data_requestwebhook, Return Wise automatically compiles the customer's data and stores the snapshot inside the authenticated app admin (the Compliance page). A short notification email is sent to the merchant-designated compliance contact with a link to the admin; the customer's identifying details and the compiled payload are never included in the email subject or body. Snapshot access is logged for compliance review, and snapshots are auto-purged 30 days after the request is received, regardless of fulfillment status. - Data deletion: Fully deleting all customer data stored by Return Wise — including return requests and items, uploaded photos (with their stored image files), and related evaluation, abuse, and audit records — upon Shopify's
customers/redactwebhook. Section 5.3 of the Data Processing Agreement carries the authoritative enumeration. Note that data previously written to Shopify's own systems (such as order notes and tags) is not affected by this deletion and is managed by Shopify.
9. Automated Decision-Making
Return Wise includes an optional abuse detection feature that may automatically flag a customer, hold their return for manual merchant review, or block them from submitting further returns through the self-service portal. The merchant (data controller) configures this feature and can disable it. The decision may draw on:
- Threshold signals — the number of returns, and the cumulative return value, per customer within merchant-configured rolling time windows.
- A behavioral risk score — a weighted score computed from return-pattern signals such as rapid repeat submissions, repeated returns of the same product, a first-time customer requesting a high-value return, and (where the merchant requires photos) missing photo evidence. The merchant sets the score thresholds at which a return is held for manual review or blocked, and may turn the score-based behavior off.
- AI reason analysis — where the optional AI return-reason classifier is enabled, the classification may contribute an abuse-risk signal (see Section 6).
These thresholds and risk settings are configured by the merchant (data controller). Merchants can review flagged customers and the risk factors that contributed, manually unblock them, and adjust or disable the automatic behavior at any time in the app settings.
In accordance with Article 22(3) of the GDPR, customers affected by this automated decision-making have the right to:
- Obtain human intervention — request that a human, rather than the automated system, review the block decision
- Express their point of view — provide context or information the merchant should consider
- Contest the decision — dispute the block and request it be reversed
These rights are exercised by contacting the merchant (data controller) directly, using the support contact information the merchant provides. Merchants are required to review and respond to such requests, and can reverse an automatic block at any time from the app settings.
The optional AI return-reason analysis and AI photo review features are not automated decision-making within the meaning of Article 22: they produce suggestions (intent/risk signals, condition tags, severity) that surface to the merchant for review. They do not approve, reject, refund, or block any return on their own — a human merchant makes every refund decision and can override or dismiss any AI suggestion.
10. Data Security
We implement the following security measures:
- Encryption in transit: All data is transmitted over HTTPS/TLS
- Authentication: Customer portal sessions use signed session tokens; merchant admin endpoints require Shopify session authentication
- Rate limiting: Customer-facing endpoints are rate-limited to prevent abuse
- Input validation and output encoding: User inputs are validated and sanitized, and user-supplied content is encoded to prevent XSS
- Duplicate-prevention controls: Return creation includes controls to prevent duplicate processing of the same request
11. International Data Transfers
Return Wise is hosted on Render (render.com) with servers located in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, your data will be transferred to and processed in the United States. We rely on appropriate safeguards under Chapter V of the GDPR for such transfers, including:
- The European Commission's Standard Contractual Clauses (Module Two — Controller to Processor) and the UK International Data Transfer Addendum (where data is transferred from the United Kingdom), incorporated into our Data Processing Agreement with each merchant
- The Standard Contractual Clauses and Data Processing Addenda published by our sub-processors (listed in Section 4.4 of the Data Processing Agreement) for transfers to and from those providers
EU data residency for return photos: Customer-uploaded return photos for merchants established in the EU/EEA are stored in an EU-jurisdiction object storage bucket rather than the default (US) bucket. Other application data (return records, settings) remains hosted in the United States under the safeguards above.
12. Cookies and Tracking
Return Wise does not use advertising or cross-context behavioral tracking cookies, tracking pixels, or third-party analytics technologies. The Shopify OAuth installation flow may set essential cookies required to complete authentication; these are not used for advertising or analytics. Customer portal sessions are managed via JWT tokens transmitted in form data, not stored in cookies.
Where the optional partner referral program is active, the merchant-facing installation flow may set a single first-party, strictly functional attribution cookie (rw_partner) when a merchant arrives via a partner referral link. It stores only a partner identifier, is read once at installation to credit the referring partner, expires after 30 days, is HTTP-only, and is never used for advertising, customer tracking, or cross-site profiling. It is not set in the customer-facing return portal.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected.
- Right to delete: Request deletion of your personal information.
- Right to opt out of sale/sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, California residents should contact the merchant (data controller) directly. Merchants may contact us for assistance in fulfilling these requests.
14. Children's Privacy
Return Wise is a B2B service provided to Shopify merchants. We do not knowingly collect personal data from children under 16. If a merchant's store serves minors, the merchant is responsible for ensuring compliance with applicable children's privacy laws.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the effective date above when changes are posted. Where required by law, we will provide additional notice through the Shopify App Store listing, email, the app interface, or another appropriate channel. Continued use of the app after changes take effect constitutes acceptance of the revised policy.
16. Contact
For privacy-related inquiries:
- Email: support@returnwise.app
- Website: https://www.returnwise.app/
BrightLayer Lab LLC · 8401 Mayland Dr #10685, Richmond, VA 23294
For data subject requests, customers should contact the merchant (data controller) directly. Merchants can reach us at the email above for assistance with data requests.