Privacy Policy

Roundtrip for Shopify  ·  Last updated Aug 17, 2026

This policy explains how Merqio App (“we”, “us”) handles personal information in connection with Roundtrip, our returns, exchanges and shipping protection app for Shopify stores. It covers information we process when a merchant installs Roundtrip, and when that merchant’s customers use the returns and claims portal Roundtrip provides.

1. Our role

When we process personal information about a merchant’s customers, we do so on that merchant’s instructions and on their behalf. The merchant is the data controller (or “business” under US state privacy laws) and we are their processor (or “service provider”). If you are a shopper, the privacy policy of the store you bought from governs how your information is used, and that store is your first point of contact.

When we process information about a merchant’s own account — their store details, settings and billing records — we act as a controller.

2. Information we collect

2.1 From the Shopify store

When a merchant installs Roundtrip, Shopify grants us access to store data through its API and webhooks. We access only what the app’s approved permissions allow, which is:

         •        Store profile — store name, myshopify domain, contact email, business address, currency, plan and timezone.

         •        Orders — order numbers and dates, line items, product and variant details, quantities, prices, discounts, taxes, financial and fulfillment status, and transaction records needed to issue refunds.

         •        Customers — name, email address, phone number, and shipping and billing addresses.

         •        Fulfillments — carrier, tracking numbers and delivery status.

         •        Products, variants and inventory locations — used to offer exchanges and to route returns.

         •        Draft orders — created when a shopper chooses an exchange.

         •        Gift cards and store credit accounts — used when a refund is issued as store credit.

2.2 Directly from shoppers

Shoppers provide information to us when they use the returns portal, the customer account extension, or the claims form:

         •        Return, exchange and claim requests, including the items involved, the reason selected, and whether an order was lost, stolen or damaged.

         •        Written descriptions and any messages exchanged with the merchant or with our claims team, including attachments.

         •        Photographs and other files uploaded as evidence supporting a claim or return.

         •        Answers to any additional questions the merchant has configured on their return or claim form.

2.3 Generated by the app

         •        Shipping protection records — the premium paid, the retail value protected, and coverage status for each protected order.

         •        Billing records — usage statements, ledger entries, credits and revenue share owed to the merchant.

         •        Notification logs — the recipient email address, which message was sent, and whether it was delivered, so that we and the merchant can answer whether a customer was notified.

         •        Technical logs — standard application and error logs generated in the course of running the service.

2.4 What we do not collect

We do not collect or store payment card numbers or bank details. Payments, refunds and store credit are executed by Shopify against the merchant’s existing payment records; we never see the underlying instrument. We do not use tracking cookies or advertising pixels, and we do not build profiles of shoppers for marketing.

3. How we use information

         •        To let shoppers request returns, exchanges and store credit, and to let merchants review, approve, deny and process them.

         •        To generate and send prepaid return shipping labels, and to track returning parcels.

         •        To offer shipping protection at checkout, and to receive, assess and resolve claims for orders that are lost, stolen or damaged.

         •        To issue refunds, replacements, gift cards or store credit through Shopify.

         •        To send transactional emails about a return or claim, such as approvals, label delivery and status updates.

         •        To calculate what a merchant owes and what revenue share they have earned, and to bill through Shopify.

         •        To detect and prevent fraud and abuse, including preventing an item that has already been refunded from being returned a second time.

         •        To provide support, and to comply with legal obligations.

4. Who we share information with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share information only with the service providers below, each of which processes it solely to perform its function for us:

Provider

Purpose

Information shared

Shopify

The platform the store runs on; source of order data and the system that executes refunds, returns and store credit

Order, customer, product and return data

Gadget

Application hosting, database and file storage

All data described in this policy, including uploaded photographs

EasyPost

Purchasing return shipping labels and receiving tracking updates

Shopper name and address, merchant return address, parcel details

Resend

Sending transactional email and receiving replies

Recipient email address and message content

Where a merchant connects their own carrier account, return labels are purchased on that account and the merchant’s own agreement with the carrier also applies.

We may also disclose information if required by law, to enforce our agreements, or in connection with a merger, acquisition or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.

5. International transfers

We and our service providers process information in the United States. If you are located in the European Economic Area, the United Kingdom or Switzerland, your information may be transferred outside your country. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism to protect it.

6. How long we keep information

We keep information for as long as the merchant’s store has Roundtrip installed, and afterwards only as long as needed for the purposes described here or to meet legal, tax and accounting obligations.

We support Shopify’s mandatory privacy webhooks. When a merchant or Shopify sends us a customer data request, we compile the information we hold about that shopper and provide it to the merchant. When we receive a redaction request, we erase the shopper’s personal information — including their name, email address, phone number, postal address, everything they wrote on a return or claim, and any photographs they uploaded, which are permanently destroyed.

We keep the underlying transaction records themselves, with the personal identifiers removed. We do this for two reasons: those records are what a merchant has already been invoiced against, so deleting them would rewrite billing history that both parties rely on; and they record which items on an order have already been returned or refunded, without which an item could be claimed twice. What remains after redaction cannot be used to identify the shopper.

When a merchant uninstalls Roundtrip, Shopify notifies us and we erase the store’s data on the schedule Shopify requires.

7. Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent. You also have the right not to be discriminated against for exercising these rights.

If you are a shopper, please contact the store you purchased from. Because we act on that merchant’s behalf, they are the ones who can verify your identity and instruct us. We respond promptly to every request a merchant passes on to us. You may also write to us at the address below and we will route your request to the right merchant.

If you are a merchant, you can reach us directly using the contact details below.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

8. Security

We protect information with measures appropriate to its sensitivity. Data is encrypted in transit. Credentials a merchant gives us, such as a carrier API key, are encrypted at rest. Each store’s data is isolated so that one merchant cannot access another’s, and access by our staff is limited to those who need it to operate the service and support claims. No system can be guaranteed completely secure, but we work to protect information and to address issues promptly.

9. Children

Roundtrip is a tool for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When we do, we will revise the date at the top of this page, and if the changes are significant we will notify merchants through the app or by email.

11. Contact us

Questions about this policy or about how we handle information:

Merqio App
support@merqio.app