Returns Intelligence

Data Processing Addendum

This addendum describes the data-processing terms that apply when Returns Intelligence processes merchant and customer personal data for the app.

Last updated June 21, 2026.

Definitions And Roles

Returns Intelligence is provided by Pacdev Lab, a project and trade name used by Cecil Teran, an individual sole proprietor based in Ecuador. Legal, privacy, security, billing, and support questions can be sent to [email protected].

The merchant is the controller or business for its customer and order data. Returns Intelligence acts as a processor or service provider when processing that data to deliver the app.

Returns Intelligence follows merchant instructions expressed through app configuration, integration setup, uninstall events, support requests, and applicable law.

Merchant data includes Shopify and merchant-enabled integration records, app configuration, admin user records, support records, logs, diagnostics, and generated exports. Customer data means personal data about shoppers contained in those records.

Processing Instructions

Processing is limited to analytics, reporting, diagnostics, syncing, exports, billing, security, support, and service operations.

The app minimizes direct customer identity processing. v1 cohort analytics use order, product, SKU, return, refund, quantity, status, reason, timestamp, and amount fields.

Support access is controlled through merchant support requests, scoped grants, expirations, revocation, and audit events. Direct database access is not the ordinary support workflow.

Data-quality support requests should include concrete operational examples and redacted screenshots or export snippets when useful, not passwords, tokens, customer payment details, full customer message bodies, or unnecessary personal data.

Confidentiality And Security

Personnel and contractors with access to merchant data must use that access only for the app, support, security, reliability, and legal obligations.

Dashboard pages and APIs require authenticated tenant workspace authorization. Internal jobs require signed tenant-scoped operation credentials. Shopify compliance webhooks are public by design but require valid Shopify HMAC signatures before requests are accepted.

Tenant integration credentials are encrypted server-side, raw payloads are treated as sensitive replay evidence, and audit metadata is sanitized to avoid storing secrets, raw payloads, customer message bodies, and unnecessary personal data.

Subprocessors And Service Providers

Subprocessors are vendors we use to host, secure, transmit, support, or operate the app when they may process merchant or customer personal data on our behalf.

Core subprocessors and service providers include hosting, managed database, perimeter access, email, observability, and Shopify services needed to run the app. Optional integration providers are used only when enabled by the merchant.

Returns Intelligence remains responsible for subprocessor performance under this addendum and requires appropriate confidentiality, security, and data-protection obligations.

Where international transfers require transfer safeguards, the parties will rely on appropriate transfer mechanisms such as standard contractual clauses, the UK addendum when applicable, or another lawful transfer basis.

Subprocessors And Merchant-Enabled Integrations

This table separates always-on platform and infrastructure services from merchant-enabled integrations. Merchant-enabled integrations process data only when the merchant configures or asks Returns Intelligence to use that source.

Provider names may change as the app matures, but replacement providers must support the same purpose limits, confidentiality, security, retention, and data-minimization commitments described in this addendum.

Provider / SystemRelationshipPurposeData CategoriesDefaultRetention / Minimization Notes
ShopifyPlatform, API, billing, and app lifecycle providerInstall, OAuth, billing, source commerce records, and mandatory privacy webhooksShop, order, product, line item, return, refund, customer/order identifiers, billing status, app lifecycle, and webhook metadataYesProcessed server-side for the installed shop. Shopify privacy requests are verified, ledgered, deduplicated, audited, and assigned a 30-day target due date.
Railway / Railway PostgresInfrastructure and managed database subprocessorApplication hosting, database storage, background jobs, and operational persistenceTenant configuration, normalized analytics, raw payload evidence, credentials envelopes, ledgers, audit events, and generated artifact metadataYesData remains tenant-scoped. Retention follows this addendum and provider backup lifecycle controls.
Cloudflare Access or equivalent perimeter providerSecurity and access-control subprocessorProtected dashboard or internal route perimeter, abuse prevention, and security loggingAdmin identity metadata, authentication events, IP address, user agent, and request metadataWhere configuredUsed for access control and security evidence. Logs should avoid raw payloads, secrets, and unnecessary customer personal data.
WeSupplyMerchant-enabled return-data integrationReturn lifecycle reconciliation, RMA diagnostics, refund evidence, and return-rate reportingRMA, return, refund, status, reason, timestamp, SKU, order reference, product reference, and limited customer/order reference fields when presentNoRaw payloads may be retained for replayability and diagnostics with a default target of up to 24 months, then deleted or redacted according to retention rules.
Generic return-data provider uploadsMerchant or support-enabled import pathAssisted historical imports, migration support, and provider-neutral return evidenceUploaded return, refund, RMA, SKU, product, order, timestamp, reason, status, amount, and diagnostic fieldsNoFiles and rows are tenant-scoped. Merchants should remove unnecessary customer identity before upload where practical.
Amazon Seller CentralMerchant-enabled marketplace integrationMarketplace order, listing, return, and denominator metrics when configured by the merchantMarketplace order/report rows, ASIN, SKU, return and fulfillment status, condition, amount, timestamp, and limited buyer or shipping fields when included by source reportsNoBuyer and shipping identity should be excluded, redacted, or minimized where practical before storage or reporting.
ShipStationMerchant-enabled shipping integrationShipping allocation, outbound delivery diagnostics, and operational reconciliationShipment, tracking, carrier, service, cost, item, order reference, status, timestamp, and limited ship-to/contact fields when included by source recordsNoShipping identity fields should be excluded, redacted, or minimized where practical. Normalized reporting should use shipping evidence rather than unnecessary recipient identity.
Cin7Merchant-enabled inventory and order integrationInventory, sales, and order bridge diagnostics when configured by the merchantSale, order, item, inventory, SKU, quantity, status, timestamp, amount, warehouse, and limited customer/address fields when included by source recordsNoCustomer and address fields should be excluded, redacted, or minimized where practical before storage or reporting.
Email or support providerSupport and notification subprocessor if configuredSupport intake, notifications, app review communication, and merchant operationsMerchant/admin contact details, message metadata, support case content, and notification delivery metadataAs configuredSupport messages should not include passwords, tokens, payment data, full customer message bodies, or unnecessary personal data. Support retention applies.
Observability or logging providerSecurity and reliability subprocessor if configuredDiagnostics, uptime monitoring, error investigation, and incident responseApplication logs, error traces, request metadata, IP address, user agent, timing, and service health eventsAs configuredLogs should avoid secrets, raw payloads, and unnecessary customer personal data. Security and reliability retention applies.

Data Subject Assistance

Shopify customers/data_request, customers/redact, and shop/redact webhooks are verified, deduplicated, stored in the privacy request ledger, audited, and tracked against a 30-day target due date.

Data-request fulfillment prepares a scoped merchant-facing export summary. Customer redaction removes or anonymizes customer-identifying fields while preserving lawful analytics and business records where appropriate.

Correction requests are routed to reviewed support workflow because the source system may remain authoritative and reporting may need recomputation.

Retention Periods

Active merchant analytics data is retained while the merchant account is active because cohort reporting, historical return rates, and trend comparisons require historical order and return records.

Raw vendor payloads are retained while needed for replayability and diagnostics, with a target default of up to 24 months for active tenants unless a merchant plan or legal obligation requires a different period.

Support requests, support access grants, privacy request ledger rows, and related audit events are retained for up to 24 months after closure for dispute, security, compliance, and service-quality evidence unless a legal hold applies.

Generated privacy exports and report artifacts are tenant-scoped, audited, and short-lived by default. Expired generated artifacts are eligible for deletion by the protected retention cleanup job.

After uninstall, account termination, or verified deletion request, active tenant credentials are revoked promptly and merchant analytics data is deleted or anonymized after a 30-day operational recovery window unless a shorter legal obligation applies.

Security, audit, sync checkpoint, billing, and delivery logs are retained for up to 24 months unless needed longer for fraud prevention, dispute handling, tax, legal, or security obligations. Backups follow the hosting provider's backup lifecycle and are allowed to age out through normal rotation.

Incident Notice And Audit Help

Returns Intelligence will notify affected merchants of a confirmed personal data breach without undue delay and in any event within seventy-two (72) hours after becoming aware of the breach, to the extent reasonably possible. Notification will include: (a) the nature of the breach and, where possible, the categories and approximate number of data records concerned; (b) the likely consequences; (c) measures taken or proposed to address the breach; and (d) the contact point for further information. If full details are not available within 72 hours, initial notification will be provided with available information, and additional details will follow without undue delay as they become available.

On reasonable written request (no more than once per twelve-month period), Returns Intelligence will make available to the merchant information reasonably necessary to demonstrate compliance with this addendum. Audits will generally take the form of written questionnaires and documentation reviews. Remote or physical inspections are only supported if explicitly required by mandatory law and are subject to reasonable confidentiality safeguards, advance notice, and protection of other tenants' data.

On request, Returns Intelligence will provide reasonable assistance to help the merchant fulfill its obligations regarding data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to the operator.

US State Privacy Restrictions

Returns Intelligence does not sell or share customer personal data, does not use it for cross-context behavioral advertising, and does not combine it with data from other merchants except as permitted to provide, secure, support, or improve the app.

Returns Intelligence will not retain, use, or disclose customer personal data outside the merchant's documented instructions, this addendum, or applicable law.

Return or Deletion of Data on Termination

Upon termination of the service, and subject to the retention periods and legal holds described in this addendum, Returns Intelligence will delete or anonymize merchant personal data within the timelines stated. The merchant may request a data export before termination through the app's authenticated export features or by contacting support.