- Home
- Privacy policy
Privacy policy
What personal data Returo processes in the Shopify app and on returo.io, why, for how long, where it is stored, who we share it with, and how to exercise your rights.
Returo is a returns app for Shopify stores and the websites returo.io and support.returo.io. It is operated by Returo Labs, a product of Flowett AB, Sweden (“Returo”, “we”). This policy explains what personal data we process, why, and what rights you have. Questions and requests: support@returo.io.
Who is responsible for your data
If you are a customer of a store that uses Returo, the store is the data controller and we process your data on the store’s behalf to handle your return. Send requests about your data to the store first; Shopify’s standard data request and deletion mechanisms reach us automatically and we act on them.
If you are a merchant, a visitor to our websites, or someone we contact about Returo, we are the controller for the data described below.
The Returo app: data we process for a store’s customers
| Data | Why | How long |
|---|---|---|
| Email address and Shopify customer ID | Find your order, identify your return, send return updates | Kept with the return record for the store’s accounting; identifiers are anonymised when the store or Shopify asks us to erase you, and deleted when the store uninstalls Returo |
| Order details (order number, items, amounts) | Build and process the return, exchange, gift card or refund | Same as above |
| Name, phone number and address | Create the return shipping label with the carrier the store uses | Passed to the carrier at label time only; not stored by Returo |
| Draft return in progress | Let you finish a return you started | Deleted when you submit it, or automatically when abandoned |
| IP address (rate limiting only) | Protect the order lookup from abuse | Deleted within one hour |
We use this data only to process returns and exchanges. No profiling, no advertising, no selling of data. Customer identifiers are excluded from our logs.
Legal basis (GDPR art. 6): performance of the contract between you and the store, and the store’s legitimate interest in handling returns efficiently.
Merchants: data we process about you
Your name, work email, store domain and the settings you configure in the app, so the app can run and we can support you. Support conversations at support.returo.io are kept so we can follow up. Legal basis: the contract with you, and our legitimate interest in supporting the product.
Website visitors
- Early access form and calculator: the email, store URL and the numbers you enter are stored so we can contact you about early access. Legal basis: your request (contract preparation). We delete them when you ask or when they are no longer needed.
- Support chat: messages and the email you leave are kept so we can reply.
- Cookies: the websites use only what is needed to work (for example a session for the chat widget). No advertising trackers.
Business outreach
We sometimes contact people in their professional role at online stores that may benefit from Returo. Contact details come from public sources and business databases (for example the store’s own website, company registries such as allabolag.se, LinkedIn, Store Leads and Apollo). Legal basis: our legitimate interest in marketing to businesses (GDPR art. 6.1.f). Every message tells you how to opt out, and one reply is enough; we then stop and keep only a suppression entry so we do not contact you again. We do not email sole traders without consent.
Where data is stored and who receives it
- Shopify: the app runs inside Shopify and reads and writes order, customer, gift card and return data through Shopify’s APIs under Shopify’s terms.
- Hosting: our servers run on Google Cloud in the EU (Stockholm region). The websites run on Cloudflare.
- Carriers: PostNord, Shipmondo and Shopify Shipping receive the name, address and phone number needed to produce a return label, under the store’s own carrier agreement.
- Email and calendar: Google Workspace for correspondence; Calendly if you book a call.
We do not sell personal data. We share it only with the processors above, or when the law requires.
Security
All traffic is encrypted in transit. Databases are encrypted at rest and backed up. Access to production data is limited to the founders and logged. We have an incident response procedure and will notify affected stores without undue delay if a breach affects their customers’ data.
Your rights
You can ask for access to your data, correction, erasure, restriction, portability, or object to processing based on legitimate interest. Write to support@returo.io. If you are a store’s customer, contact the store; we act on the store’s instructions. You can also complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
Changes
We update this page when our processing changes. The date at the top tells you when it was last revised.