ReturnThread privacy policy
Last updated: 30 September 2026
ReturnThread is a Shopify app that lets a store ask a customer a question about a specific item in a return, and lets the customer answer (with text and, when requested, one photo) from their Shopify customer account. This policy explains what data ReturnThread handles for the stores that install it.
What we read from Shopify
- The return’s status and line items, the order’s identifier, and the customer’s Shopify customer identifier, used to confirm that the person answering owns the return.
- The customer’s email address, read at the moment a question notification is sent and used only to send it. It is not stored.
- The store’s contact email, used to tell the store that a customer answered or that a customer data request was received.
We do not read or store customers’ names, phone numbers, or addresses.
What we store
- The questions the store asks and the customer’s answers.
- Photos the customer uploads when a photo is requested. Each photo is re-encoded on upload, which removes embedded metadata such as location, and is kept in private storage that only the store’s authenticated staff can view through the app.
- Operational records (webhook deliveries, notification attempts, audit events) that contain identifiers but no message content.
How long we keep it
- Questions, answers and photos: 90 days after the case is closed.
- Photos uploaded but never sent with an answer: 30 days.
- Operational records: 180 days.
- Everything for a store is deleted when the store uninstalls ReturnThread or Shopify sends a shop redaction request. A customer’s cases and photos are deleted when Shopify sends a customer redaction request.
Customer data requests
When Shopify forwards a customer’s data request, ReturnThread compiles every record it holds for that customer and sends it to the store’s contact email so the store can provide it to the customer.
Service providers
ReturnThread runs on the following providers, which process data only to operate the app: Fly.io (application hosting), Neon (database), Cloudflare R2 (photo storage), and Resend (email delivery).
What we don’t do
We don’t sell data, use it for advertising, or use it to train AI models. ReturnThread never approves or declines returns; the store does that in Shopify.
Contact
Questions or requests: privacy@returnthread.cloud. Stores can also reach support@returnthread.cloud.