Privacy policy
Last updated September 28, 2026
Mint Returns is a Shopify app made by Mint Labs ("we", "us"). It adds a returns and exchanges page to a merchant's Shopify store. This policy explains what information the app handles — about merchants and about the merchant's customers who use the returns page — why, and how it's deleted. For customer data we act as a service provider (processor) to the merchant, who remains responsible for their own customers' data.
The short version
- We read a customer's order only when they (or the merchant) use the returns feature, and only to process that return.
- We never store customer names, email addresses, phone numbers or postal addresses.
- We never sell or share data, use it for advertising, or combine it across stores.
- When a merchant uninstalls, everything we hold about their store is deleted within 48 hours of Shopify's request.
Information about merchants
| Information | Why |
|---|---|
| Store domain and a Shopify access token | To connect to the store when the app is used. |
| Return settings (return window, reasons, options, colours and text) | To run the returns page the way the merchant configured it. |
| Monthly count of return requests | To apply the Free plan's monthly limit. |
| Plan and subscription status | Read from Shopify to decide which features apply. Payments are handled entirely by Shopify. |
Information about the merchant's customers
When a customer uses the returns page, the app handles:
| Information | How it's used | Stored? |
|---|---|---|
| Order number and email address the customer types in | Compared with the order's email in Shopify to confirm the customer placed the order. If the customer is signed in, Shopify tells us their customer ID instead. | No — used for that request only |
| The order's items, prices, fulfilment dates and what has already been returned | To show which items can be returned and to check the return window and quantities. | Only for the items the customer returns |
| The return request: order ID and number, Shopify customer ID, items, quantities, reason, chosen outcome and an optional note | So the merchant can review, approve or decline the request, and to issue store credit to the right account. | Yes, until deleted (see below) |
| Failed order lookups (order number and time) | To slow down anyone guessing order numbers. | Yes, for one hour |
Return requests are also created as returns in the merchant's Shopify admin, where Shopify's own privacy policy applies. We don't use cookies or tracking on the returns page.
Customer privacy requests
- Access requests (Shopify's
customers/data_request): we look up every return request linked to that customer or their orders and provide it to the merchant within 30 days. Merchants can also see all requests in the app at any time. - Erasure requests (
customers/redact): we permanently delete every return request linked to that customer or the orders Shopify lists. - Store deletion (
shop/redact, sent 48 hours after a merchant uninstalls): we permanently delete all settings, return requests, usage counts and access tokens for that store.
Customers should contact the store they bought from; we'll help the merchant respond.
Where data is stored and how it's protected
The app runs on Cloudflare (hosting and database, United States) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers.
Retention
Return requests are kept while the app is installed so merchants can refer back to them, and deleted on request, on a customer erasure request, or when the store is deleted after uninstall. Failed lookup records are deleted after one hour. Access tokens are deleted as soon as the app is uninstalled.
Your rights
Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly; customers should contact the store, or email us and we'll pass the request to the store. We respond within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com