Privacy Policy
Last updated: March 17, 2026
What data we collect
ReturnSense collects the minimum data needed to monitor delivery exceptions and returns-prevention workflows for your Shopify store:
- Store information: Your Shopify store domain, name, email, timezone, and currency (provided during OAuth installation).
- Fulfillment data: Order names, tracking numbers, carrier names, and shipping method labels from your Shopify fulfillments.
- Customer contact info: Customer name, email, and phone number associated with fulfilled orders — used solely to send proactive delivery notifications on your behalf.
- Tracking events: Carrier status updates from EasyPost, including timestamps, status codes, and exception details.
How we use your data
- Detect and surface delivery exceptions (delays, failed deliveries, lost packages).
- Send proactive customer emails and Slack alerts that you configure.
- Generate carrier performance reports, lane insights, and risk scoring.
- Power the exceptions inbox, returns-prevention workflow, and daily digests.
Data sharing
We do not sell or share your data with third parties. Data is shared only with the services you configure:
- EasyPost — tracking numbers are sent to create tracker webhooks.
- Postmark or SendGrid — customer emails are sent through your configured email provider.
- Slack — exception alerts are sent to your configured Slack webhook.
Where your data is stored (sub-processors)
ReturnSense runs on Vercel (application hosting) and stores data in a Neon PostgreSQL database, both located in the United States. Tracking is performed by EasyPost, and, where you configure them, email is delivered by Postmark or SendGrid and alerts by Slack. Your data is shared with these processors only to provide the service described above.
Data retention and deletion
Store and shipment records are retained for as long as the app is installed. Operational logs are pruned automatically: processed webhook records after 30 days and completed background jobs after 14 days.
When you uninstall ReturnSense, your access token is immediately revoked. If Shopify sends a shop/redact request, all data for that shop — including shipments, status events, templates, notifications, notes, queued jobs, and stored webhook payloads — is permanently deleted.
When Shopify sends a customers/redact request, that customer’s personal information is scrubbed everywhere we hold it: shipment records, notification logs (recipient, subject, and body), and stored tracking event payloads.
Data security
Your Shopify offline access token is encrypted at rest (AES-256-GCM). All API communication uses HTTPS. Inbound webhook payloads are verified using HMAC signatures, and signature headers are not retained. Write operations require a verified Shopify session token (JWT), and every query is scoped to your store.
Your rights
You may request a copy of your data or request deletion at any time by contacting us. Uninstalling the app triggers automatic data cleanup.
Contact
For privacy questions or data requests, contact us at support@delayradar.io.