Privacy policy
This policy is for stores using ReverseSignal Returns. It explains what data we hold, why, who else handles it and when we delete it.
Last updated: September 26, 2026
The short version
- ReverseSignal Returns applies your store's policy to every customer request, making returns easy and efficient for your customers and team.
- Your customers' data belongs to you. We use it only to run the app, following your instructions.
- We share data only with service providers we need, such as shipping carriers and messaging services, who may use it for nothing else.
- We never sell or rent personal data, or use it for advertising.
- When you uninstall, we delete your customers' personal details.
Who we are
ReverseSignal Returns is made by ReverseSignal, Inc., based in Austin, Texas. Our mailing address is 3571 Far West Blvd, Unit #6120, Austin, TX 78731.
In this policy, "you" means the store using the app, and its staff. "Your customer" means someone who bought from your store and is returning or exchanging an item.
Our role
We are your processor: you decide what happens to your customers' data, and we handle it only as you direct. US state privacy laws also call this a "service provider".
We follow the privacy laws for processors and the rules of each platform we support.
What we collect and why
We collect only what we need to run returns. The app works with Shopify today, so "your platform" below means Shopify.
About your store
| What | Why |
|---|---|
Your store's address (for example your-store.myshopify.com) |
To match each request to the right store. |
| The access key your platform issues when you install | To read orders and record returns. We encrypt it with a key unique to your store. |
| Your logo, square logo, cover image and brand colors, copied from your platform's brand settings | To match your returns portal to your brand. |
| The returns portal address you claim | To serve your portal there. |
About your staff
| What | Why |
|---|---|
| Each staff member's platform user ID, role (Owner, Admin or Agent) and when they last opened the app | To show each person the pages their role allows. We don't store their name or email. |
| Name and email of anyone using our web app | Held by WorkOS, our sign-in provider, to sign them in. |
About your customers
| What | Where it comes from | Why |
|---|---|---|
| Order number and email | Your customer, in your returns portal | To find their order. |
| Order details: items (SKU, title, quantity, price) and totals (subtotal, tax, refunds) | Your platform, at lookup | To show what can be returned and record each return. |
| Name, shipping address, email and phone | The order | To show your staff whose return it is, create shipping labels and send return updates. |
| Whether your customer agreed to get emails or texts from your store | Your platform | To message only those who opted in. |
| Your customer's ID on your platform | The order | To find all their data when they ask to see or delete it. |
| Items, reason, any comment your customer writes, return method, outcome (refund, exchange or store credit) and tracking number | Your customer and your staff | To process the return and record it in your store. |
About how the app is used
| What | Why |
|---|---|
| IP address, browser and device type, and the pages and actions your staff and customers use in the app and portal | To spot fraud and abuse, keep the app fast and fix problems. |
Cookies and logs
- Cookies and similar tools keep people signed in and a customer's return session open, and help us spot fraud and measure performance. Where the law requires consent, we ask first. We never use them for advertising.
- Logs record which page was requested, whether it worked and how long it took. We keep names, emails, phone numbers, addresses, access keys and payment details out of them.
What we don't collect
Payment card numbers or bank details. Refunds go through your platform.
How we use it
We use your customers' data only to:
- Let your customers find their order and start a return or exchange.
- Show your staff each return, so they can approve it and record the outcome.
- Create shipping labels and track packages.
- Send your customers return updates and your store's marketing by email or text, if you turn these on.
- Record the return in your store.
- Spot fraud and abuse, such as fake returns or repeated order lookups.
- Keep the app fast and reliable, and fix problems.
You're responsible for getting your customers' permission to email or text them. We send only the messages you turn on, to customers your records show have agreed, and stop as soon as anyone opts out.
We never use your customers' data to market our own products or to train AI models.
Who else handles it
We use service providers to run the app. Each gets only the data its job needs, must keep it safe and may not use it for anything else. AI providers may not keep your customers' data or train their models on it.
| Kind of provider | What they do for us | What they receive | Who we use today |
|---|---|---|---|
| Hosting | Runs the app and stores its data in the United States (N. Virginia) | All app data, encrypted | Amazon Web Services (AWS) |
| Sign-in | Signs people in to our web app | Name and email of each user | WorkOS |
| Monitoring and alerts | Watches performance and alerts our on-call engineer | App logs, timings and error counts, with no personal data | Grafana Cloud, PagerDuty |
| Websites | Hosts this website and our help site | Standard web requests only, with no sign-in or cookies | Vercel |
| Shipping | Creates return labels and tracks packages | Customer name, address and phone, and package details | None yet |
| Messaging | Sends emails and texts to your customers | Customer name, email or phone, and the message | None yet |
| Fraud and usage monitoring | Flags suspicious activity and measures app use | IP address, device and browser details, and activity in the app | None yet |
| AI services | Help with tasks such as reading a return comment or flagging likely fraud | Only the details the task needs | None yet |
Your platform also receives the returns we record in your store.
New providers. We add each one to this table at least 30 days before it receives any personal data. If you object, email privacy@reversesignal.com before then and we'll work with you to resolve it.
We may share data when the law requires it. If our company is sold, the buyer must keep the promises in this policy.
We never sell or rent personal data, or share it for advertising.
How long we keep it
| Data | How long |
|---|---|
| Customer name, address, email, phone and comments | While the app is installed, unless you or your customer ask us to delete them sooner. |
| Return records (items, reason, outcome, order number) | Kept. If a customer's data is deleted or you uninstall, their personal details are removed. |
| Usage data (IP address, device, pages and actions) | Up to 90 days. |
| Your access key | Deleted when you uninstall. |
| Your branding, portal address and store connection | Deleted 48 hours after you uninstall. If you reinstall, you start fresh. |
| App logs | Up to 30 days. |
| Database backups | 7 days. Deleted data is gone from backups within a week. |
When your customer asks about their data
Your customers can ask to see or delete their data. Because it belongs to you, they should contact you. You send the request through your platform, which passes it to us.
- Delete their data. We remove their name, address, email, phone and customer ID, and blank out their comments. The return record (items, reason and outcome) stays, without those details. We act as soon as the request arrives, always within 30 days.
- See their data. Within 30 days, we send you a copy of everything we hold about the customer, so you can pass it on.
- Stop messages. Your customers can opt out any time by replying STOP to a text or using the unsubscribe link in an email. We honor it right away.
If one of your customers writes to us directly, we pass the request to you and help you answer it.
Where the law requires us to keep data, we keep only what's required and delete it when the requirement ends.
How we protect it
- All connections, the database, its backups and its logs are encrypted.
- Your access key is encrypted again, with a key unique to your store.
- Each store's data is kept separate, so no store can see another's.
- The database isn't reachable from the internet.
- Test and live data are kept in separate AWS accounts.
- An on-call engineer is paged when something breaks.
If a security incident affects your data, we'll tell you promptly.
Where data is stored
The app is for US stores. All data is stored and processed in AWS's N. Virginia region, in the United States.
Data processing agreement
If you need a signed data processing agreement (DPA), email privacy@reversesignal.com.
Changes to this policy
We update the date at the top whenever we change this policy. If an update affects how we use your data, we post it here at least 30 days before it takes effect.
Contact us
Email privacy@reversesignal.com with privacy questions or to request a DPA. For help with the app, see Get help.