Privacy Policy. This page is ready
SimplyReturns · Last updated August 20, 2026
SimplyReturns (“we”, “us”) is a Shopify embedded app that helps merchants create and manage product returns, repairs, exchanges, and return shipments. This policy describes how we handle information when merchants install and use the app.
Merchants who install SimplyReturns, their staff users, and shoppers whose order data is processed so a return can be completed. This page is public and does not require a Shopify login.
Through Shopify APIs we may access shop and order information needed for returns, including shop domain, staff session, order and line-item details, customer name, email, phone, and shipping address, return and fulfillment status, and configuration you save in the app (for example carrier credentials and return settings).
Carrier credentials (such as MyParcel or DHL Parcel API keys) are stored so the app can create return labels. Do not share live keys in public listings; use sandbox keys for App Store review.
We use this information only to operate SimplyReturns: authenticate the merchant in Shopify Admin, create and approve returns, generate reverse shipments and labels, and send customer phone to the selected carrier as shipper contact so the rider can reach the customer if pickup or the address is unclear. We also store app settings and respond to Shopify mandatory webhooks (including uninstall and GDPR requests).
We share data with Shopify (platform APIs) and with the shipping providers you enable (MyParcel and/or DHL Parcel) so labels and tracking can be created. Label files may be uploaded to Cloudinary so they can be downloaded. Hosting and database providers process data on our behalf to run the app. We do not sell personal information.
We keep shop data while the app is installed and as needed to provide the service. Shopify sends mandatory compliance webhooks when a customer or shop requests data or deletion. We receive:
customers/data_request, customers/redact, and shop/redact at /api/gdpr/ on this same host. After uninstall we stop processing that shop’s data except as needed to complete deletion.
Access is limited to authenticated Shopify Admin sessions for embedded app pages. Session tokens and stored credentials are handled over HTTPS. No method of transmission or storage is fully secure.
Questions about this policy, a data request, or merchant support: support@oux.works.