Retørn

Privacy Policy — Retørn

Sambeso ApS (CVR 38654209, Lauritz Sørensens Vej 10, 4. th, 2000 Frederiksberg, Denmark), operator of the Retørn app ("Retørn", "we", "us"), takes the security of your data seriously and is committed to a safe, secure service for all users.

Retørn processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish law. Merchants using Retørn remain responsible for their own compliance with data-protection law.

Last updated: 8 July 2026

1. Introduction

This Privacy Policy explains how we collect and process personal data and your rights in relation to it. Questions or requests: support@retorn.io (our preferred contact method).

We may update this Policy to reflect changes in law or our service. If a change materially affects your rights we will take reasonable steps to notify you; otherwise please review this page periodically.

Our two roles. Retørn is a Shopify app installed by a merchant (a "store") to run its returns, exchanges and claims:

Retørn is not intended for children and we do not knowingly collect children's data.

2. What personal data we process, and from whom

End-customer (shopper) data — we act as processor. When a shopper starts a return in a merchant's Retørn portal, or when the merchant's Shopify store shares order data with us, we process:

We do not process payment-card data — payments and refunds are handled by Shopify.

Merchant account data — we act as controller. Business contact details, the store domain, app settings, and billing/usage records (billing itself runs through Shopify).

Data we collect automatically. Basic technical/usage data needed to run and secure the service (e.g. IP address for rate-limiting and abuse prevention, request logs, timestamps). We keep this to a minimum and do not use it to build advertising profiles.

3. Lawful basis

We process personal data only where we have a lawful basis:

For end-customer data, the merchant is the controller and determines the lawful basis; we act on their instructions.

4. Who we share data with — sub-processors

We use a small set of carefully selected sub-processors, each only with the data they need:

Sub-processor Purpose Data
Shopify Source of order/customer data; billing Order, customer, fulfillment, return data
Fly.io Application hosting + database (EU region) All app data at rest
Resend Delivery of transactional emails (return confirmations, labels, refunds) Recipient email, message content
Shipmondo Return-label generation + carrier hand-off Name, return address, parcel details

We require each sub-processor to protect personal data to a standard no lower than this Policy and applicable law. We may update this list; material changes are reflected here and in our DPA.

We may also disclose personal data where required by law, or in connection with a merger, acquisition or restructuring (with notice to affected users where required).

5. Where we process data & international transfers

We host data in the EU (Fly.io Frankfurt, Germany). Where any processing or sub-processor involves a transfer outside the EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses.

6. Security

We use appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and accidental loss — including encryption in transit, access controls, tenant isolation (each store's data is segregated), and least-privilege API scopes. No system is perfectly secure; in the event of a personal-data breach we will act promptly to contain it and will notify affected controllers without undue delay (see our DPA for the 72-hour term).

7. Your rights

Under the GDPR you have the right of access, rectification, portability, restriction, erasure ("right to be forgotten"), and to object. Exercise them via support@retorn.io.

Where we act as processor (end-customer data), please direct your request to the merchant (the controller) whose store you shopped with — Shopify and Retørn provide the merchant tools to fulfil it. If you contact us directly we will notify and assist the merchant. Shopify's mandatory data-request / redaction webhooks are honoured: on a verified request we surface or erase the relevant data, and all of a store's data is deleted when the app is uninstalled (see Retention).

We aim to respond within one month.

8. Retention

We may retain anonymized/aggregated data (no longer identifying anyone) indefinitely for statistics and service improvement.

9. Cookies

The Retørn admin runs embedded in Shopify and uses Shopify session tokens (not third-party cookies). The shopper portal uses a single functional cookie to carry a return through the wizard (no advertising or cross-site tracking). We do not run third-party advertising cookies.

10. Contact

Sambeso ApSsupport@retorn.iohttps://retorn.io