← Back to home

Privacy Policy

Last updated: August 11, 2026

1. Introduction

BrightLayer Lab LLC ("we," "us," "our") operates the Return Wise application ("App"), a Shopify application that helps merchants manage product returns by offering customers store credit (with optional bonus incentives), a refund to their original payment method, or an exchange for a different item. The App can also show return-package tracking and, where the merchant enables it, generate a return shipping label for the customer. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our application.

2. Data Controller and Processor Roles

Under the General Data Protection Regulation (GDPR) and similar data protection laws:

3. Data We Collect

3.1 From Merchants (via Shopify)

3.2 From Customers (via Merchant's Store)

When a customer looks up an order or initiates a return through a merchant's store — via the storefront return portal or, where the merchant enables it, the customer's Shopify customer account — we collect or process:

3.3 Data We Generate

3.4 Data We Do NOT Collect

We do not collect the customer's physical address for order lookup, return eligibility, refunds, or store credit. The App processes a customer's shipping address only in connection with return shipping labels (Section 3.2): when the merchant generates a label, the address is retrieved from the order and shared with the merchant's chosen shipping-label provider to produce it (see Section 6); the street address and contact details are then discarded — the label record keeps only tracking identifiers plus the address's postal code and country, retained as drop-off context (to locate nearby drop-off points and for carrier-aware copy); when the merchant instead uploads a return-label file, that file shows the customer's name and return address and is stored in object storage until the return is deleted (see Sections 6, 7, and 11). The address is not used for marketing, profiling, or any other purpose.

4. How We Use Data

We process personal data solely to provide the return management service:

We do not use customer data for marketing, advertising, or cross-context behavioral profiling, or for any purpose unrelated to the return management service. We may use automated analysis of return history, refund values, return-pattern signals, and — where the merchant enables it — AI classification of return reasons, for fraud and abuse prevention and return triage, as described in Sections 6 and 9.

5. Legal Basis for Processing (GDPR)

For customer return data, the merchant — as the data controller — determines and documents the legal basis for processing under Article 6 of the GDPR. Common legal bases that may apply, depending on the merchant's policies and customer relationship, include:

Merchants are responsible for confirming and documenting the legal basis applicable to their store and informing customers in their own privacy notice. The limited categories of data Return Wise processes as an independent controller (merchant account, support, security, admin-activity, and compliance-contact data) are described in Section 2.

For those independent-controller categories, BrightLayer Lab LLC relies on its legitimate interests (Art. 6(1)(f)) in operating, securing, supporting, and maintaining the accountability of the App (including its audit trail and protected-data access logs), and on the performance of its contract with the merchant (Art. 6(1)(b)) for account and support administration. We retain that data as described in Section 7 — for example, audit-trail records for 18 months by default and data-subject-export access logs for the duration of the installation — and delete it on those schedules and on shop data deletion. If you are a merchant user or staff member and wish to exercise your data-subject rights (such as access, correction, or deletion) in respect of data we hold as controller, contact us directly at support@returnwise.app.

6. Data Sharing

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising (within the meaning of the California Consumer Privacy Act, as amended by the California Privacy Rights Act). We disclose personal data only to the service providers and sub-processors listed below, who process data on our behalf to operate the return management service:

Website infrastructure (visitors to the public site): The public Return Wise marketing and legal pages on returnwise.app are served via Cloudflare (cloudflare.com), which provides edge delivery, DNS, and DDoS protection. Cloudflare processes standard request metadata for visitors to the public site (IP address, User-Agent, request timing) at the network edge. This edge-delivery role for the public website is separate from Cloudflare R2's role as the App's object storage sub-processor described above; the App's data flows and complete sub-processor list are governed by Section 4.4 of the Data Processing Agreement.

7. Data Retention

8. Data Subject Rights (GDPR / UK GDPR / Australian Privacy Act)

Customers may exercise the following rights by contacting the merchant (data controller):

Under GDPR / UK GDPR:

Under the Australian Privacy Act 1988:

When a merchant receives a data subject request, we support them by:

9. Automated Decision-Making

Return Wise includes an optional abuse detection feature that may automatically flag a customer, hold their return for manual merchant review, or block them from submitting further returns through the self-service portal. The merchant (data controller) configures this feature and can disable it. The decision may draw on:

The optional AI return-reason classifier is not an input to this automated decision. Where enabled, it produces an abuse-risk signal that is displayed to the merchant to help them triage returns manually (see Section 6); it does not feed the behavioral risk score and does not itself flag, hold, or block any return.

These thresholds and risk settings are configured by the merchant (data controller). Merchants can review flagged customers and the risk factors that contributed, manually unblock them, and adjust or disable the automatic behavior at any time in the app settings.

In accordance with Article 22(3) of the GDPR, customers affected by this automated decision-making have the right to:

These rights are exercised by contacting the merchant (data controller) directly, using the support contact information the merchant provides. Merchants are required to review and respond to such requests, and can reverse an automatic block at any time from the app settings.

The optional AI return-reason analysis and AI photo review features are not automated decision-making within the meaning of Article 22: they produce suggestions (intent/risk signals, condition tags, severity) that surface to the merchant for review. Those AI outputs do not approve, reject, refund, or block any return on their own and can be overridden or dismissed by the merchant. Any automated refund is instead governed by a separate rule and safety controls that the merchant expressly configures, as described above.

10. Data Security

We implement the following security measures:

11. International Data Transfers

Return Wise is hosted on Render (render.com) with servers located in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, your data will be transferred to and processed in the United States. We rely on appropriate safeguards under Chapter V of the GDPR for such transfers, including:

Geographic availability. Return Wise is not yet offered to merchants established in the EEA, the United Kingdom, or Switzerland (see the Geographic limitation section of our Terms of Service, which the App enforces technically at the store level). The safeguards in this section therefore currently operate for the processing that can still involve those jurisdictions — for example, where a merchant established elsewhere processes a return for its own customer located in the EEA or the United Kingdom — and will govern transfers from merchants established in those jurisdictions if and when availability opens.

EU data residency for stored files: Customer-uploaded return photos, and any return-label file a merchant uploads, for merchants established in the EU/EEA are stored in an EU-jurisdiction object storage bucket rather than the default (US) bucket. Other application data (return records, settings) remains hosted in the United States under the safeguards above. Because Return Wise is not currently offered to merchants established in the EEA (see Geographic availability above), this residency path is not in use today: a served merchant's stored files are held in the United States regardless of where their customer is located.

12. Cookies and Tracking

Within the Return Wise app — the merchant admin and the customer return portal — Return Wise does not use advertising or cross-context behavioral tracking cookies, tracking pixels, or third-party analytics technologies. The Shopify OAuth installation flow may set essential cookies required to complete authentication; these are not used for advertising or analytics. Customer portal sessions are managed via JWT tokens transmitted in form data rather than session cookies; the customer portal sets no cookie other than strictly functional ones, and at present that is only the language cookie described below.

Our public marketing and legal website (returnwise.app) uses Cloudflare Web Analytics to measure aggregate site traffic (for example page views and referrers). It is cookieless, sets no client-side identifiers, performs no cross-site tracking, and does not identify individual visitors; it is not used inside the app or the customer return portal. Cloudflare processes this data as described in its own privacy policy, and we rely on our legitimate interest in understanding and improving the public website.

When a customer selects a language in the return portal, Return Wise stores that choice in a single first-party, strictly functional cookie (rw_lang) so the portal — and any follow-up emails about the return — stay in that language. It holds only a language code, expires after one year, and is never used for advertising, customer tracking, or cross-site profiling. The customer's selected language is also stored alongside their return record so later emails match the language they chose; that stored preference follows the return record for retention and deletion (see Section 7).

Where the optional partner referral program is active, the merchant-facing installation flow may set a single first-party, strictly functional attribution cookie (rw_partner) when a merchant arrives via a partner referral link. It stores only a partner identifier, is read once at installation to credit the referring partner, expires after 30 days, is HTTP-only, and is never used for advertising, customer tracking, or cross-site profiling. It is not set in the customer-facing return portal.

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

To exercise these rights, California residents should contact the merchant (data controller) directly. Merchants may contact us for assistance in fulfilling these requests.

14. Children's Privacy

Return Wise is a B2B service provided to Shopify merchants. We do not knowingly collect personal data from children under 16. If a merchant's store serves minors, the merchant is responsible for ensuring compliance with applicable children's privacy laws.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the effective date above when changes are posted. Where required by law, we will provide additional notice through the Shopify App Store listing, email, the app interface, or another appropriate channel. Continued use of the app after changes take effect constitutes acceptance of the revised policy.

16. Contact

For privacy-related inquiries:

For data subject requests, customers should contact the merchant (data controller) directly. Merchants can reach us at the email above for assistance with data requests.