Return Guard — Privacy Policy
Return Guard is a Shopify application operated by Bifrost Tech (Private) Limited, Karachi, Pakistan ("Bifrost Tech", "we", "us").
This policy explains what data the Return Guard app accesses when a merchant installs it on their Shopify store, why we access it, where it is stored, and how it is deleted.
This policy covers Return Guard only
(returnguard.bifrosttech.io). Other Bifrost Tech applications are governed by
their own policies; where they differ, the app-specific policy applies.
1. Our role
When a Shopify merchant installs Return Guard, the merchant is the data controller for their customers' personal data. Bifrost Tech acts as a data processor on the merchant's behalf.
We do not obtain personal data directly from shoppers. All customer data reaches us from the merchant's Shopify store, through Shopify's official APIs and webhooks, with the merchant's authorisation.
2. Information we collect
2.1 Merchant and store data
- Shopify store domain and store ID
- Store owner name and email address
- Shopify OAuth access tokens (used to call Shopify APIs on the store's behalf)
- Subscription, plan and billing status
- Courier account credentials, where a merchant chooses to connect a courier
2.2 Customer data
Return Guard's purpose is to predict which orders are likely to be returned to origin. That prediction depends on order and delivery details, so the app does receive customer personal data:
| Data | Source |
|---|---|
| Customer name | Shopify order webhooks |
| Customer email address | Shopify order webhooks |
| Customer phone number | Shopify order webhooks |
| Shipping address (street, city, province, postal code) | Shopify order webhooks |
| Order contents, value and status | Shopify order webhooks |
| Fulfilment and delivery events (courier, dispatch and delivery timestamps) | Shopify fulfilment webhooks |
We do not collect customer notes, marketing preferences, browsing or session activity, or any payment instrument details. Return Guard never sees card or payment credentials.
3. How we use this data
| Purpose | What it involves |
|---|---|
| Return-to-origin risk scoring | Producing a per-order risk score the merchant uses to decide whether to verify an order before dispatch |
| Address normalisation ("City Fixer") | Correcting inconsistent or misspelled Pakistani city and area names so orders can be grouped reliably |
| Courier performance analysis | Aggregating delivery and return outcomes by courier and destination |
| Deletion request matching | Identifying the correct records when a customer asks the merchant to delete their data |
Specifically:
- Email addresses are used to link a customer's orders across time and to match deletion requests. They are never displayed in the app interface and never used to contact customers. Return Guard sends no marketing, no notifications and no messages of any kind to shoppers.
- Phone numbers are stored and checked for validity and formatting, because an invalid or malformed contact number is a strong predictor of a failed delivery.
- Shipping addresses are stored and assessed for completeness and quality, and are normalised for aggregate courier analysis.
- Customer names are shown to the merchant within their own order views for operational identification.
We do not sell personal data, share it for advertising, use it to train models for other merchants' benefit, or use it for any purpose beyond delivering the service described above.
3.1 Changes we write back to Shopify
Return Guard is read-mostly. Only two actions write to a merchant's Shopify store, and both require the merchant to click a button in the app:
- Verify — adds a verification tag to the order.
- Cancel — cancels the order (behind a confirmation step).
The app takes no automatic action on any order and never contacts a customer.
4. Where data is stored
Data is held in a PostgreSQL database on a Contabo VPS located in Germany (European Union), operated by Bifrost Tech.
5. Security
We are specific here rather than generic, because a privacy policy that overstates protection is worse than one that describes it accurately.
What we do:
- All data in transit is protected with HTTPS/TLS, between Shopify and the app and between the app and its database.
- Access is restricted to a single operator. There is no third-party analytics service, data warehouse or business-intelligence tool with access to merchant or customer data.
- Customer personal data is structurally excluded from application logs. Our logging layer removes personal fields before anything is written, so an engineering mistake cannot leak personal data into logs.
- All incoming Shopify webhooks are cryptographically verified (HMAC signature) before processing, so forged data cannot enter the system.
- Merchant courier credentials are encrypted in the database using PostgreSQL's pgcrypto with a server-held key.
- Audit records use keyed one-way hashes instead of plain identifiers, so compliance logs cannot be reversed into personal data.
What we do not currently do:
- Customer personal data columns are not individually encrypted in the database, and the underlying disk is not encrypted at rest. Protection for customer data rests on restricted access, transport encryption, log redaction and the deletion guarantees in section 6.
No system is completely secure. We do not claim protection we have not implemented.
6. Data retention and deletion
Data is retained for as long as the app is installed on the merchant's store. There is no fixed retention period and no automatic time-based deletion.
Data is deleted when one of the following happens:
| Event | What happens | Timeframe |
|---|---|---|
| Merchant uninstalls the app | Shopify notifies us. Customer personal fields are irreversibly anonymised and operational records for that store are deleted. | Within 48 hours of Shopify's notification |
| A customer requests deletion | The merchant passes the request through Shopify. We irreversibly anonymise that customer's personal fields — name, email, phone and street address — across all their orders. | Within 30 days of the request |
| A customer requests their data | We record the request. Under Shopify's process, the merchant provides the export to the customer. | On receipt |
Anonymisation is irreversible. Once a customer's personal fields are removed, the remaining order record cannot be linked back to that individual. We retain non-identifying aggregate information — such as city-level delivery success rates — because it is no longer personal data once the link is severed.
We keep a minimal compliance log recording that a deletion request was received and completed. This contains no plain personal data; identifiers within it are stored as one-way hashes. It is retained as evidence that we met our obligations.
7. Who else processes this data
| Party | Role | Location |
|---|---|---|
| Shopify | Source of the data; the platform the merchant's store runs on | Per Shopify's own policy |
| Contabo | Hosting provider — servers and database | Germany (EU) |
| Hostinger | Email delivery for operational alerts sent to the merchant (e.g. delivery-deadline warnings). These messages contain order and courier references. | EU |
We use no other sub-processors. We do not share personal data with advertisers, data brokers or analytics providers.
8. International transfers
Merchants and their customers are typically located in Pakistan, while data is stored in Germany (European Union). This means personal data is transferred outside Pakistan for processing. EU hosting places the data within a jurisdiction that applies GDPR-standard protections.
9. Your rights
Shoppers whose data we process on a merchant's behalf may request:
- Access to the personal data held about them
- Deletion of that data
- Correction of inaccurate data
- A copy of their data in portable form
Because the merchant is the data controller, requests should go to the store you purchased from. Shopify forwards such requests to us automatically, and we act on them as described in section 6.
You may also contact us directly at info@bifrosttech.io and we will coordinate with the relevant merchant.
Merchants may exercise the same rights over their own store data by contacting us or by uninstalling the app, which triggers deletion.
10. Compliance with Shopify's data-protection requirements
Return Guard implements Shopify's mandatory privacy webhooks:
customers/data_request— customer data-access requestscustomers/redact— customer deletion requestsshop/redact— store data deletion after uninstall
11. Cookies
Return Guard uses functional cookies only — the session cookie required to keep a merchant signed in inside the Shopify admin, and a security cookie protecting that session. We use no advertising, tracking or third-party analytics cookies. We do not place any cookie on a shopper's browser; the app runs only inside the merchant's Shopify admin.
12. Children's data
Return Guard is a business tool for merchants and is not directed at children. We do not knowingly collect data relating to children. Any personal data we process is incidental to an order the merchant received.
13. Changes to this policy
We may update this policy as the app changes. The effective date at the top will be revised, and material changes affecting how customer data is handled will be communicated to merchants through the app or by email.
14. Contact
Bifrost Tech (Private) Limited
Karachi, Pakistan
Email: info@bifrosttech.io
For app-specific technical matters:
tech@payfiniti.co
15. Governing law
This policy is governed by the laws of the Islamic Republic of Pakistan. Where we process personal data of individuals protected by the EU General Data Protection Regulation, we apply that regulation's standards to that processing.