ReverseSignal

Privacy policy

This policy is for stores using ReverseSignal Returns. It explains what data we hold, why, who else handles it and when we delete it.

Last updated: September 26, 2026

The short version

Who we are

ReverseSignal Returns is made by ReverseSignal, Inc., based in Austin, Texas. Our mailing address is 3571 Far West Blvd, Unit #6120, Austin, TX 78731.

In this policy, "you" means the store using the app, and its staff. "Your customer" means someone who bought from your store and is returning or exchanging an item.

Our role

We are your processor: you decide what happens to your customers' data, and we handle it only as you direct. US state privacy laws also call this a "service provider".

We follow the privacy laws for processors and the rules of each platform we support.

What we collect and why

We collect only what we need to run returns. The app works with Shopify today, so "your platform" below means Shopify.

About your store

What Why
Your store's address (for example your-store.myshopify.com) To match each request to the right store.
The access key your platform issues when you install To read orders and record returns. We encrypt it with a key unique to your store.
Your logo, square logo, cover image and brand colors, copied from your platform's brand settings To match your returns portal to your brand.
The returns portal address you claim To serve your portal there.

About your staff

What Why
Each staff member's platform user ID, role (Owner, Admin or Agent) and when they last opened the app To show each person the pages their role allows. We don't store their name or email.
Name and email of anyone using our web app Held by WorkOS, our sign-in provider, to sign them in.

About your customers

What Where it comes from Why
Order number and email Your customer, in your returns portal To find their order.
Order details: items (SKU, title, quantity, price) and totals (subtotal, tax, refunds) Your platform, at lookup To show what can be returned and record each return.
Name, shipping address, email and phone The order To show your staff whose return it is, create shipping labels and send return updates.
Whether your customer agreed to get emails or texts from your store Your platform To message only those who opted in.
Your customer's ID on your platform The order To find all their data when they ask to see or delete it.
Items, reason, any comment your customer writes, return method, outcome (refund, exchange or store credit) and tracking number Your customer and your staff To process the return and record it in your store.

About how the app is used

What Why
IP address, browser and device type, and the pages and actions your staff and customers use in the app and portal To spot fraud and abuse, keep the app fast and fix problems.

Cookies and logs

What we don't collect

Payment card numbers or bank details. Refunds go through your platform.

How we use it

We use your customers' data only to:

  1. Let your customers find their order and start a return or exchange.
  2. Show your staff each return, so they can approve it and record the outcome.
  3. Create shipping labels and track packages.
  4. Send your customers return updates and your store's marketing by email or text, if you turn these on.
  5. Record the return in your store.
  6. Spot fraud and abuse, such as fake returns or repeated order lookups.
  7. Keep the app fast and reliable, and fix problems.

You're responsible for getting your customers' permission to email or text them. We send only the messages you turn on, to customers your records show have agreed, and stop as soon as anyone opts out.

We never use your customers' data to market our own products or to train AI models.

Who else handles it

We use service providers to run the app. Each gets only the data its job needs, must keep it safe and may not use it for anything else. AI providers may not keep your customers' data or train their models on it.

Kind of provider What they do for us What they receive Who we use today
Hosting Runs the app and stores its data in the United States (N. Virginia) All app data, encrypted Amazon Web Services (AWS)
Sign-in Signs people in to our web app Name and email of each user WorkOS
Monitoring and alerts Watches performance and alerts our on-call engineer App logs, timings and error counts, with no personal data Grafana Cloud, PagerDuty
Websites Hosts this website and our help site Standard web requests only, with no sign-in or cookies Vercel
Shipping Creates return labels and tracks packages Customer name, address and phone, and package details None yet
Messaging Sends emails and texts to your customers Customer name, email or phone, and the message None yet
Fraud and usage monitoring Flags suspicious activity and measures app use IP address, device and browser details, and activity in the app None yet
AI services Help with tasks such as reading a return comment or flagging likely fraud Only the details the task needs None yet

Your platform also receives the returns we record in your store.

New providers. We add each one to this table at least 30 days before it receives any personal data. If you object, email privacy@reversesignal.com before then and we'll work with you to resolve it.

We may share data when the law requires it. If our company is sold, the buyer must keep the promises in this policy.

We never sell or rent personal data, or share it for advertising.

How long we keep it

Data How long
Customer name, address, email, phone and comments While the app is installed, unless you or your customer ask us to delete them sooner.
Return records (items, reason, outcome, order number) Kept. If a customer's data is deleted or you uninstall, their personal details are removed.
Usage data (IP address, device, pages and actions) Up to 90 days.
Your access key Deleted when you uninstall.
Your branding, portal address and store connection Deleted 48 hours after you uninstall. If you reinstall, you start fresh.
App logs Up to 30 days.
Database backups 7 days. Deleted data is gone from backups within a week.

When your customer asks about their data

Your customers can ask to see or delete their data. Because it belongs to you, they should contact you. You send the request through your platform, which passes it to us.

If one of your customers writes to us directly, we pass the request to you and help you answer it.

Where the law requires us to keep data, we keep only what's required and delete it when the requirement ends.

How we protect it

If a security incident affects your data, we'll tell you promptly.

Where data is stored

The app is for US stores. All data is stored and processed in AWS's N. Virginia region, in the United States.

Data processing agreement

If you need a signed data processing agreement (DPA), email privacy@reversesignal.com.

Changes to this policy

We update the date at the top whenever we change this policy. If an update affects how we use your data, we post it here at least 30 days before it takes effect.

Contact us

Email privacy@reversesignal.com with privacy questions or to request a DPA. For help with the app, see Get help.