Ordra - ReturnShield

Privacy Policy

Last updated: August 15, 2026

What ReturnShield processes

ReturnShield processes Shopify order, refund, customer, product and validation data only for the merchant store that installed the app. The app calculates return/refund risk measurements and lets authorized store administrators manage checkout enforcement.

Data minimization

ReturnShield stores Shopify resource identifiers, order references, normalized order and refund amounts, product and variant identifiers used for aggregate return insights, risk measurements, enforcement state, audit events, webhook identifiers and background-job metadata. Customer names and email addresses are requested live from Shopify for the current admin page and are not stored in ReturnShield's database. When a merchant enables a PO box, country/region, phone-required, or phone-country-code checkout rule, the required delivery-address or phone field is evaluated transiently inside Shopify's Checkout Validation Function. ReturnShield does not transmit, store, or log those checkout address or phone values. ReturnShield does not store IP addresses, payment details or full webhook payloads.

Purpose and legal role

The merchant determines why customer data is processed. ReturnShield acts as the merchant's service provider or processor and uses data only to provide the installed app, protect checkout according to merchant decisions, support the merchant and meet legal obligations.

Automated decisions

Risk scores are explainable recommendations based on the merchant's own fulfilled-order and refund history. Automatic blocking is disabled by default. Merchant decisions take priority, and the merchant can Allow, Watch or Block a customer at any time.

Sharing and international processing

Data is processed by Shopify and the infrastructure providers required to operate ReturnShield, including Railway-hosted application and database services. ReturnShield does not sell customer data, operate a shared blacklist or share risk scores between merchants.

Security and retention

Data is encrypted in transit and protected by the hosting provider at rest. Access is limited to operating and supporting the service. Operational data is retained while the app is installed and only as long as needed for the service. Shopify privacy webhooks are used for customer access, customer deletion and shop deletion requests. Temporary customer exports expire after seven days. Store data is deleted when Shopify sends the shop redaction request after uninstall.

Merchant and customer requests

Merchants can contact support@blinket.no. Customers should normally contact the merchant, who can submit Shopify's required customer data request or deletion workflow to ReturnShield.

Changes

Material changes to this policy will be published on this page with a new effective date.