Privacy Policy

Where’s My Refund · a Shopify app for support teams

Where’s My Refund shows a Shopify order’s return and refund status inside a support helpdesk sidebar for the merchant’s own agents. It is read-only and stores no customer data.

Data we access

With the merchant’s authorization, when a support ticket is viewed we read from the merchant’s Shopify store: order details (number, date, totals, fulfillment status), refund records (amount, status), return status, and the customer email tied to the ticket — used only to look up that customer’s order.

Data we store

None. Each card is fetched on demand for a single ticket view, rendered, and discarded. We keep no database of customer or order records. The only credentials we retain are the merchant’s own API tokens, stored encrypted, isolated per merchant, and deleted on uninstall.

How data is used

Solely to render return and refund status to the merchant’s support agents. We never sell, rent, share, or use customer data for advertising, profiling, or model training.

Sub-processors

Data subject requests

Because we store no customer personal data, there is nothing to export or delete per customer. We honor Shopify’s mandatory customers/data_request, customers/redact, and shop/redact webhooks; each is acknowledged as a verified no-op since no data is retained.

Security

All traffic is encrypted in transit (TLS 1.2+). Merchant API credentials are encrypted at rest, isolated per merchant, and removed on uninstall. Logs exclude customer personal data.

Contact

Questions: support@wheresmyrefund.app