Legal
Privacy Policy
This policy explains what personal data the Encore app collects when it is installed on a Shopify store, why we collect it, who we share it with, how long we keep it, and how you can exercise your privacy rights. It applies to Shopify merchants who install Encore and to the shoppers who use an Encore-powered returns or claims portal.
Last updated: August 21, 2026
1. Who we are
Encore (“Encore”, “we”, “us”, “our”) provides a post-purchase product guarantee, returns, and claims application for Shopify merchants. The app is distributed through the Shopify App Store and is hosted at www.encorereturns.com.
You can reach us about anything in this policy at jack@conspireagency.com.
2. Our role: processor for merchants, controller for our own records
When a merchant installs Encore, the merchant decides what data enters the app and why. For shopper personal data — order details, claim submissions, portal logins — the merchant is the data controller (or “business” under US state privacy laws) and Encore acts as a processor (or “service provider”) acting on the merchant’s instructions. We do not sell shopper data, and we do not use it to build cross-merchant profiles or advertising audiences.
For the limited data we hold about the merchant relationship itself — the store domain, install and OAuth records, app usage and error logs, billing and support correspondence — we act as a controller.
3. What we collect
We collect only what the app needs to price, process, and audit a guarantee claim.
| Category | Examples | Source |
|---|---|---|
| Merchant account data | Shopify store domain, install date, granted API scopes, encrypted Shopify access and refresh tokens, dashboard session token hashes | Shopify OAuth at install |
| Merchant configuration | Refund policy and tier settings, workflow rules, branding assets, return address, connected integration credentials (encrypted) | Entered by the merchant in the Encore dashboard |
| Order data | Shopify order ID and name, order date, line items, product and variant titles, quantities, prices, taxes, currency, subtotals, refunds, and the customer ID associated with the order | Shopify Admin API and order webhooks |
| Shopper claim data | Email address, order reference, claim reason and category, free-text notes, item condition, return-flow and fit-quiz answers, uploaded return photos, refund or store-credit amounts, claim status and decision history | Submitted by the shopper in the claims portal; enriched from Shopify |
| Claims risk data | Per-store aggregate counts for a shopper email: lifetime claims, lifetime refund value, order count, claim rate, distinct claim reasons, distinct shipping addresses, and a derived risk score and signals | Computed by Encore from the merchant's own order and claim history |
| Portal session data | Shopper email, hashed magic-link token, expiry and verification timestamps, IP address, and browser user agent | Created when a shopper signs in to the returns portal |
| Communications data | Recipient email address, template name, delivery status, provider message ID, bounce/complaint/unsubscribe records | Generated when Encore sends a transactional email |
| Technical and diagnostic data | API request and error logs, webhook delivery records, rate-limit counters, and application exception reports | Generated automatically as the app runs |
Encore does not collect payment card numbers or bank details. Payments, refunds, and store credit are executed inside Shopify; Encore only records the resulting amounts and identifiers.
4. Data we receive from Shopify
With the merchant’s authorization at install, Encore requests the Shopify API scopes needed to read orders, products, customers, returns, draft orders, fulfillment orders, and store credit accounts, and to write returns, draft orders, store credit transactions, and cart transforms. Scopes are shown to the merchant on the Shopify permission screen before install and can be reviewed at any time in the Shopify admin.
Encore subscribes to the orders/create, orders/updated, and returns/update webhooks to keep claim eligibility current, and to Shopify’s mandatory compliance webhooks — app/uninstalled, shop/redact, customers/redact, and customers/data_request — which we handle as described in section 12. Every incoming webhook is HMAC-verified against our Shopify app secret before it is processed.
5. How we use data
- Operate the app — check order and claim eligibility, run the shopper claim flow, apply the merchant’s policy and workflow rules, and issue refunds, store credit, exchanges, replacements, or return labels through Shopify.
- Authenticate access — issue and verify merchant dashboard sessions and shopper magic-link portal sessions.
- Send transactional email — claim confirmations, decisions, portal sign-in links, and follow-ups. These are service messages tied to a claim, not marketing.
- Prevent abuse — score claims for fraud and abuse risk on behalf of the merchant, and rate-limit and deduplicate requests.
- Report to the merchant — produce claim, product, and returns analytics for the merchant’s own store.
- Meet safety and audit obligations — where a merchant sells products subject to adverse-event reporting, retain the records that obligation requires.
- Maintain and secure the service — debug errors, monitor reliability, and investigate security incidents.
- Comply with law — respond to lawful requests and enforce our terms.
Where GDPR or UK GDPR applies, our merchant customers rely on contract and legitimate interests as their lawful bases, and Encore processes shopper data only under the merchant’s documented instructions. For our own controller data we rely on legitimate interests in operating, securing, and improving the app, and on legal obligation where applicable.
6. Automated decision-making and AI
Encore uses automated logic in two places. First, merchant-configured workflow rules and risk scoring can auto-approve or route a claim based on the merchant’s own thresholds. Every automated decision is recorded with the rule evaluation and risk signals that produced it, and a merchant can review, reverse, or override any claim decision in the dashboard.
Second, Encore uses the Anthropic (Claude) API to generate product recommendations and product education copy. The prompts we send contain the merchant’s product catalog data, the stated claim reason, and the shopper’s fit-quiz answers and notes; they do not include the shopper’s email address, name, or address. Anthropic does not use data submitted through its API to train its models.
Neither path produces a decision with legal or similarly significant effects on a shopper: the outcome is a refund, store credit, exchange, or product suggestion within the merchant’s own returns policy. If you want a claim decision reviewed by a person, contact the merchant you purchased from, or write to us and we will route it to them.
8. Sub-processors
Encore relies on the following providers to deliver the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | Source of order data and the system of record for refunds, returns, and store credit | Merchant, order, and customer data |
| Vercel | Application hosting and delivery | All request traffic; server logs |
| Neon | Managed PostgreSQL database | All stored application data |
| Cloudflare R2 | Object storage for shopper-uploaded return photos and merchant branding assets | Claim images; brand assets |
| Resend | Transactional email delivery | Recipient email address and message content |
| Inngest | Background job and scheduled task processing | Job payloads, including claim and email identifiers |
| Anthropic | AI product recommendations and product education copy | Catalog data, claim reason, quiz answers and notes — no direct shopper identifiers |
| Sentry | Error monitoring and diagnostics | Exception data and limited request context |
We require each sub-processor to provide appropriate confidentiality and security commitments and to process data only on our instructions. This list may change as the service evolves; the current list always appears on this page.
9. How long we keep data
- Claims, orders, and settings are kept for as long as the merchant keeps Encore installed, so the merchant retains their returns history.
- On uninstall, we immediately invalidate the store’s access tokens and disable outbound integrations. Shopify then sends a shop/redact request 48 hours later, at which point we hard-delete the store’s claims, claim images, orders, settings, risk profiles, portal sessions, integration connections, and the store record itself.
- On a customer redaction request, we remove the shopper’s portal sessions, risk profile, and any adverse-event alert, and strip their email address and Shopify customer ID from their claims. The de-identified claim record is retained for the merchant’s financial reporting and, where applicable, product-safety audit obligations.
- Portal sessions expire automatically and are pruned after expiry.
- Operational logs are pruned on a rolling schedule — application error records after 30 days and processed-webhook records after 14 days.
10. How we protect data
- All traffic is served over TLS, with HSTS and baseline security headers enforced at the edge.
- Shopify access and refresh tokens and merchant integration credentials are encrypted at rest with a dedicated application key; database storage is encrypted at rest by our provider.
- Session tokens are stored only as hashes — merchant dashboard tokens and shopper magic-link tokens alike — and portal links are short-lived and single-purpose.
- Every Shopify webhook is HMAC-verified, and internal and cron endpoints require separate shared secrets.
- Shopper return photos live in a private, non-public bucket and are served only through short-lived signed URLs.
- Application queries are scoped by store domain so one merchant’s data cannot be reached from another merchant’s session.
- Access to production systems is limited to personnel who need it to operate the service.
No system is perfectly secure. If we become aware of a breach affecting personal data, we will notify affected merchants without undue delay and support their own notification obligations.
11. Your privacy rights
Depending on where you live, you may have the right to access the personal data held about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, to withdraw consent, and to appeal a refused request. Residents of California and other US states with comprehensive privacy laws also have the right not to be discriminated against for exercising these rights. As stated above, Encore does not sell personal data or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.
If you are a shopper, the merchant you purchased from controls your data. Please direct your request to that merchant — they can action it through Shopify, which relays it to Encore automatically. If you are not sure who to contact, write to us and we will identify the merchant and pass the request on.
If you are a merchant, you can contact us directly using the details below.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
12. Making a data request
Encore implements Shopify’s mandatory compliance webhooks, which is the fastest route for a request that originates in a Shopify store:
- customers/data_request — we log the request and provide the merchant with the relevant Encore records so they can fulfil the shopper’s access request.
- customers/redact — we erase or de-identify that shopper’s data as described in section 9.
- shop/redact — we erase the store’s data as described in section 9.
You can also email us directly at jack@conspireagency.com. We respond to verifiable requests within the timeframe required by applicable law, and within 30 days where no specific deadline applies. We may need to verify your identity, or confirm your request with the merchant whose store the data belongs to, before we act. An authorized agent may submit a request on your behalf with proof of authorization.
13. International transfers
Encore and its sub-processors operate in the United States and other countries. If you are located in the EEA, the UK, or Switzerland, your personal data may be transferred to and processed in a country whose data protection laws differ from your own. Where such a transfer takes place, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with the safeguards our providers maintain, to protect that data.
15. Children's data
Encore is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us through a claim, contact us and we will delete it.
16. Changes to this policy
We may update this policy as the app changes or as the law requires. The “last updated” date at the top of this page always reflects the current version. For material changes affecting merchants, we will provide notice in the app or by email before the change takes effect.
17. Contact us
For any question about this policy, or to make a privacy request, email jack@conspireagency.com.
If you are a shopper, please also tell us which store you purchased from so we can route your request to the right merchant.
