Last updated: 30 July 2026
Returnhub, operated by Suksessklubb AS (org. nr. 932 684 306), Tangen 24, Kristiansand S, Norway ("we", "us"), provides a returns-management application for Shopify stores. This policy explains what data the app processes, why, and how long we keep it.
For data belonging to a merchant's customers, the merchant (the Shopify store owner) is the data controller and Returnhub acts as a data processor on their behalf. For a merchant's own account information, we act as controller.
Contact: hello@returnhub.io
myshopify.com store domainWhen a customer submits a return request through your store, we store:
| Data | Why it is needed |
|---|---|
| Email address | To verify the order belongs to the requester, and to send status emails |
| Order number and Shopify order ID | To link the request to the correct order |
| Items requested, quantities, and product IDs | To record what is being returned |
| Return reason and chosen resolution | To let the merchant review the request |
| Request status, refund amount, currency, and any rejection reason | To track the outcome |
| Language preference | To send emails in the customer's language |
We do not collect or store payment card details, passwords, or full shipping addresses. Refunds are processed entirely by Shopify; we never handle card data.
The app requests permission to read orders, write orders, and read products. Order data is read from Shopify when a customer looks up an order and when a merchant reviews a request. Write access is used only to create a refund after a merchant explicitly approves one.
We share data only with the service providers needed to run the app:
| Provider | Purpose |
|---|---|
| Shopify | Source of order and product data; processes refunds |
| Railway | Application hosting and database storage |
| Resend | Delivery of transactional return-status emails |
We do not sell personal data, and we do not use it for advertising or profiling.
Return request data is kept for as long as the app is installed, so merchants retain a record of past returns. We implement Shopify's mandatory privacy webhooks:
If you are in the EU/EEA or UK, you have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. Customers should contact the store they shopped with, since that merchant controls the data. Merchants can contact us directly at hello@returnhub.io.
All traffic is encrypted in transit over HTTPS. Requests to the customer return portal are verified using Shopify's signed proxy signatures, so requests cannot be forged. Access tokens are stored in our database and are never exposed to browsers.
Our hosting and email providers may process data outside the EU/EEA, including in the United States. Where that happens, transfers rely on the providers' standard contractual clauses.
We may update this policy as the app changes. The "last updated" date above reflects the most recent revision.
Questions about this policy: hello@returnhub.io