SwapBack

Privacy

SwapBack processes only the order, product, customer name/email, return-document, and replacement-choice data needed for merchant return operations. Customer email is hashed for lookup; customer names and notes are encrypted where stored; manual PDFs are private R2 objects served through signed URLs. Shopify customer data requests appear in the merchant's Privacy Requests page. Scoped archives include retained return records, related activity, uploaded PDF files and matching portal-session data. The merchant must verify the requester and securely provide the archive within the displayed 30-day deadline; a Ready status does not mean it was delivered to the customer. Archive downloads expire 30 days after preparation, and customer redaction revokes access. SwapBack does not sell customer data, does not use it for ads, and does not make legally significant automated decisions.