Terms

Terms of Service and Data Processing Agreement

Version 1.1 · Effective 8 October 2026

These terms are between ABANG MUHAMMAD HIQAL BIN ABG HAMIZAM, an individual of Malaysia trading as ReturnThread ("we", "us"), and the person or business operating the Shopify store that accepts them ("you").

By selecting "Agree and continue" in ReturnThread, you agree to these terms for your store and confirm that you are authorized to do so. The Data Processing Agreement below forms part of these terms. Our Privacy Policy explains our data practices. It is a notice and does not give us permission for unrelated uses of your data.

1. What ReturnThread does

ReturnThread helps you collect and review evidence for Shopify returns. You can send a question yourself or switch on automatic requests for the return reasons you select. Customers can provide a photo, a short answer and an optional note in their Shopify customer account. The service can send a request notification and up to two reminders.

You review the evidence and decide the return in Shopify. ReturnThread does not approve, decline, refund or block a return. It does not replace your return policy or your legal obligations to customers.

We are solely responsible for ReturnThread, its development, distribution and support, our handling of merchant data, and liability arising from your access to or use of the app. Shopify is not liable for faults in ReturnThread or resulting harm. Unless Shopify expressly offers help, Shopify does not provide installation or use support for ReturnThread.

2. Your responsibilities

Use ReturnThread for your own store's returns and only where you have authority to process the information involved. Give customers the notices required by law, establish an appropriate lawful basis and obtain consent when required.

You instruct us through your settings, rules, questions and authorized requests. By sending a question or switching on a rule, you authorize us to send the related service emails on your behalf. They are return-related messages, not advertising.

Ask only for information reasonably needed for the return. Do not request passwords, payment-card details, government identity documents, or unnecessary health or other sensitive information. Review customer material carefully and contact us if information needs to be removed or corrected.

Keep questions, return decisions and customer communications lawful and fair. Do not treat an AI note as proof of fraud or as a reason to disregard a customer's rights. Evidence collection does not extend a legal deadline or make a statutory remedy conditional on unnecessary evidence.

Protect access to your Shopify account and tell us if you suspect misuse. You keep ownership of your content and give us permission to handle it only to provide the agreed service.

3. Optional AI features

AI evidence notes are off by default. When you switch them on, selected evidence is sent to our AI provider to draft a description or suggest that a return reason needs review. The rule assistant sends selected store information and what you type to draft rule wording. Its drafts do not switch on rules by themselves.

AI can produce inaccurate or incomplete results. A person must review its output. It does not decide returns or change your rules without your action.

We do not send dedicated customer identity fields. Text and photos can still contain personal information. Email addresses and phone numbers we can recognize in evidence text are removed first, on a best-effort basis; this is not complete anonymization.

We do not use your data to train AI models, and our agreements for these features do not allow the AI provider or the model's developer to do so. The AI provider processes requests in the United States and, as we have configured it, does not store a request or its reply after answering. AI notes on photos are offered only where the app shows them as available. Where a photo is sent, the provider's automated child-safety check applies: if it flags a photo, the provider may keep and review that photo and report it as the law requires, and we may be unable to have that copy deleted. The Privacy Policy and the private supplier information explain the processing that applies.

The app shows the current feature limits. Requests may be limited or unavailable when those limits are reached. Switching on AI is separate from accepting these terms and does not itself authorize a payment.

4. Fees and cancellation

Any paid plan, price, billing period, trial and usage allowance is shown through Shopify before you approve a subscription. Installing the app or accepting these terms alone does not approve a charge.

Approved fees are billed through Shopify, under the approved plan and Shopify's billing process. Price changes go through Shopify's approval process. Taxes and any refunds are handled according to the approved plan, Shopify's process and applicable law.

You can cancel through Shopify's subscription controls or by uninstalling the app. Cancelling does not cancel charges already incurred under an approved plan. Contact support if you believe a charge is wrong.

5. Acceptable use and service availability

Do not use ReturnThread unlawfully, access another store's data, upload malicious content, or interfere with the service. We may restrict access where reasonably necessary for security, unlawful use or a material breach of these terms. We will explain the restriction where practicable and lawful.

We work to keep the service available, but do not guarantee uninterrupted operation, delivery of every email, recovery of every record, or an AI result. Shopify and other necessary services can affect availability. You remain responsible for monitoring returns and meeting customer obligations in Shopify.

We may improve or change the service. We will give reasonable advance notice of material reductions where practicable, except where an urgent security, legal or platform requirement prevents this.

Data Processing Agreement

6. Roles, purpose and instructions

For customer return information, you are the controller and we are your processor. If you act for another controller, you confirm that you have authority to appoint us as a subprocessor.

We process information to operate return evidence requests, display answers and photos, send related notifications, provide the AI features you choose, and maintain the security and operation of that service. Processing includes receiving, organizing, storing, retrieving, transmitting and deleting information.

The people concerned are your customers and others whose information appears in submitted material. The data includes Shopify identifiers, return status and items, selected reasons and return notes, questions, answers, photos and relevant operational records. The customer's email address is used to send notifications. Dedicated customer name, phone and address fields are not requested for this workflow; submitted content may contain them.

Processing continues while needed for the service and its stated retention periods, or until an earlier valid deletion instruction or the end of the agreement. The Privacy Policy gives the retention details.

We act only on your documented instructions, including instructions about international transfers: these terms, the features you switch on and your authorized written requests. We will tell you if we believe an instruction conflicts with applicable data-protection law. Where law requires different processing, we will inform you before acting unless that law prohibits us from doing so.

Our own necessary handling of merchant contact, support and agreement records is described separately in the Privacy Policy. It does not authorize unrelated use of customer evidence.

7. Confidentiality and security

We limit access to people and suppliers who need it for the service or authorized support, and ensure appropriate confidentiality duties apply.

We use appropriate technical and organizational safeguards for the risks involved. These include encrypted connections, protected storage, authenticated store and customer access, private photo storage, removal of embedded photo metadata and relevant access records. The Privacy Policy and the security information available from our privacy contact explain the current measures.

We review the safeguards as the service changes. No system eliminates every security risk.

8. Suppliers and international processing

We use suppliers for hosting, database services, photo storage, email delivery, support communications and optional AI processing. You authorize the suppliers in our current private subprocessor list, available from privacy@returnthread.cloud before you accept.

We require appropriate written data-protection obligations from subprocessors and remain responsible for their performance as required by applicable law. We will notify you in advance of proposed additions or replacements, normally at least 30 days before the change, so you can raise a reasonable data-protection objection. Contact us within the notice period. We will seek a workable resolution before the disputed supplier processes your data; if none is available, the affected feature or this agreement may need to end.

Processing may involve countries outside your country. We will use the transfer safeguards required for the relevant processing and provide information on destinations and arrangements privately. Where additional transfer terms are required, they must be completed before the affected processing starts.

9. Help with privacy obligations

Taking account of the processing and the information available to us, we will assist you with applicable customer rights requests, security obligations, breach assessments, data-protection impact assessments and related regulator consultations.

Send requests to privacy@returnthread.cloud. We verify authority and keep access limited to the relevant store or person. We support the applicable Shopify privacy requests, and will provide or help you obtain relevant information in a structured, commonly used, machine-readable form and make necessary corrections.

We will refer customer requests concerning your store to you where appropriate, unless law requires us to respond directly. You remain responsible for your customer-facing controller obligations; this does not remove our own legal duties.

10. Personal data incidents

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you. We will share available details about the incident, the affected information, likely consequences and response measures, and provide further information as it becomes available.

We will cooperate with your investigation and required notifications. We will also meet our separate reporting obligations to Shopify and any duties that apply to us.

11. Return and deletion

You can instruct us to return or delete personal data processed for you. Contact privacy@returnthread.cloud for a secure export before uninstalling if you want a copy.

Uninstalling instructs us to stop the service and delete store data. Data may no longer be available for export once deletion begins. We delete active records promptly and complete deletion of remaining copies within the applicable deadline. We manage backups and failed object deletions so that removed data is not returned to ordinary use.

We keep information only where applicable law requires storage or provides a relevant exception, with access and use restricted accordingly. We do not use retained evidence for another purpose. Copies already delivered to you or your customers are under the recipient's control.

12. Demonstrating compliance

We will provide information reasonably needed to demonstrate compliance with this Data Processing Agreement. Where required by applicable law, we will allow and contribute to audits and inspections by you or an independent auditor you appoint.

We can arrange reasonable notice, confidentiality and scope to protect security and other stores' information. These arrangements will not prevent a legally necessary audit, inspection or regulator request.

If we can no longer meet a required processing obligation, we will tell you promptly and cooperate in stopping or remedying the affected processing.

13. California service-provider processing

Where the CCPA applies to data you disclose to us, we act as your service provider or authorized subprocessor for the specific return evidence, notification and selected assistance purposes described in section 6.

We will not sell or share that personal information, use it for unrelated commercial purposes, use it outside our direct service relationship, or combine it with other sources except where the CCPA expressly permits this. We will provide the protection and assistance required by the CCPA, including applicable rights requests, security audits and risk assessments.

You may take reasonable steps to verify and, on notice, stop or remedy unauthorized use. We will notify you if we can no longer meet these duties, and we require applicable obligations from further subprocessors.

14. Malaysian personal data law

This section applies where Malaysia's Personal Data Protection Act 2010 applies to data you ask us to process. It adds to the sections above and does not replace them. For that data you normally act as the data controller and we act as your data processor, as described in section 6. We comply with the security duties the Act places directly on data processors.

We will tell you of a personal data breach without undue delay, so that you can meet your own duties to notify the Commissioner and affected people within the times the Act sets. We transfer personal data out of Malaysia only as the Act allows, and will give you the information you need about destinations and safeguards.

Where the Act requires you to give your customers a written notice, in the national language and in English, and to have a lawful basis to collect their information, that remains your responsibility. Our own notice is published in both languages: the Privacy Policy and the Notis Privasi.

Other agreement terms

15. Responsibility and liability

Each party is responsible for its own actions and obligations. We do not promise a particular return outcome, the elimination of disputes, or that AI output is correct.

Nothing in these terms excludes responsibility that cannot lawfully be excluded, or limits statutory data-protection rights or mandatory transfer protections.

To the extent the law allows, our total liability to you arising from these terms or the service is limited to the greater of the fees you paid for ReturnThread in the 12 months before the event that gave rise to the claim and 100 US dollars. To the same extent, neither party is liable to the other for indirect or consequential loss, or for loss of profit, revenue, business or goodwill. These limits do not apply to liability that cannot lawfully be limited, including for fraud, or to your obligation to pay fees.

16. Ending the service

You can end the agreement by uninstalling ReturnThread. We may end it for a material breach that is not remedied after reasonable notice, or sooner where security, law or Shopify's requirements make that necessary. We may discontinue the service with reasonable notice where practicable.

Ending the service does not remove accrued obligations or the duties needed to handle data return, deletion and confidentiality. Returns in Shopify remain under your control.

17. Changes to these terms

We will identify the version and effective date of any changes. We will give reasonable advance notice of material changes and ask for renewed agreement where the change requires it. We will not rely on an undisclosed page edit to change your agreed obligations.

You can review the terms before accepting or stop using the service. Existing data-protection duties continue while we hold data for you.

18. Law, disputes and contact

These terms are governed by the laws of Malaysia. Disputes will be heard in the courts of Malaysia, subject to any mandatory law or transfer terms that require otherwise.

Contact support@returnthread.cloud for service or billing questions and privacy@returnthread.cloud for data-protection questions, supplier information or rights requests.

Legal notices to us must be sent by email to privacy@returnthread.cloud, addressed to ABANG MUHAMMAD HIQAL BIN ABG HAMIZAM. We do not publish a postal address; we will give one on request where the law requires it. We send notices to you at your store's contact email in Shopify.