PRIVACY NOTICE
Data boundaries for prospective studies.
Last updated September 5, 2026. This notice describes the current development implementation.
Shopify data the app uses
ReturnTrace stores Shopify shop and server-side session data, granted scopes, selected product and variant references, complete catalog snapshots, approved change boundaries, study definitions, jobs, coverage states, aggregate evidence, and limited webhook delivery metadata.
For an active study, the app reads bounded order, fulfillment, line-item, and return facts needed to place fulfilled units and returns into the approved before-and-after windows. Raw normalized cohort evidence is encrypted at rest. The app does not query names, email addresses, postal addresses, payment details, or message content.
Purpose and limits
The data supports prospective observational studies around a merchant-approved catalog change. Findings report correlation and coverage. They do not identify a customer, attribute causation, reconstruct history before the baseline, or prove which catalog change produced an outcome.
Retention and export
Encrypted raw cohort evidence is purged after 120 days. Aggregate evidence and archived or otherwise inactive studies are removed after 365 days. Cleanup is bounded and requires the deployed worker to continue running, so an expired record can remain until a later cleanup pass.
The authenticated JSON export includes at most 100 studies and 512 KiB, reports truncation, and replaces Shopify resource identities with keyed references. It excludes customer data, raw cohort records, and raw order, fulfillment, return, product, variant, and line-item identifiers.
Access removal and erasure
Loss of required product, order, or return access pauses new collection and preserves existing evidence for review and export. Uninstall and Shopify shop-redaction handling erase app-owned shop records and server-side sessions. Customer-redaction handling removes any study whose normalized evidence includes an order Shopify identifies for redaction; ReturnTrace removes the whole study because subtracting a customer after aggregation could create a misleading result. An independent keyed erasure record prevents an older database backup from restoring erased app data. Keyed lifecycle receipts can remain for up to 35 days to reject delayed callbacks without retaining a plain shop domain, customer identity, order identity, or raw delivery identity. Exported copies remain under the merchant’s control.
Contact and release status
Email justinwalker4233@outlook.com for app data questions.