← Back to RefundedOrder AutocleanerPrivacy Policy

Privacy Policy

Last updated & effective date: September 9, 2026


1. Introduction & Overview

This Privacy Policy describes how RefundedOrder Autocleaner ("the App", "we", "us", or "our") collects, uses, stores, and handles store and customer information when installed by merchants on their Shopify stores.

RefundedOrder Autocleaner is designed to automate the resolution of deadlocked refunded orders by automatically cancelling them, closing/archiving them, and restocking cancelled line items back into your store inventory according to your preferences.

We are committed to maintaining the confidentiality, integrity, and security of all data handled by the App in compliance with Shopify App Store requirements, the General Data Protection Regulation (GDPR), and applicable privacy laws.

2. Information We Collect

To provide automated order resolution and auditing features, the App collects and processes the following categories of information:

A. Merchant & Store Data

  • Shop Identification: Your Shopify store domain (e.g. your-shop.myshopify.com) and unique shop identifier.
  • App Configuration Preferences: Custom store settings saved in the App dashboard (automation enabled/disabled state, inventory restocking preference, customer email notification preference, and store owner notification preference).
  • OAuth Tokens & Session Credentials: Offline API access tokens provided through Shopify OAuth to authenticate administrative API requests made on your store's behalf.
  • Plan & Usage Metrics: Monthly store order volume retrieved via GraphQL to track billing quota limits, as well as subscription tier data retrieved from the Shopify Partner API.

B. Order & Customer Data (For Refund Processing)

When a refund occurs in your store (received via real-time refunds/create webhooks) or when you trigger an on-demand historical cleanup scan, the App accesses order details through the Shopify Admin API:

  • Order Details: Shopify Order ID, order name/number (e.g. #1042), creation date, financial status (REFUNDED), fulfillment status, and line items.
  • Customer Contact Information: Customer name and customer email address associated with the refunded order. This data is recorded exclusively in your store's Cleaned Orders Log so you can audit actions taken by the app, and is used to trigger Shopify's standard cancellation confirmation email if you enable customer notifications.
What We DO NOT Collect: We never collect, process, or store buyer credit card numbers, payment credentials, banking details, passwords, or personal identifying information unrelated to the refunded orders being processed.

3. Webhooks & How Information is Used

The App subscribes to automated Shopify webhooks and uses collected data strictly for the following operational purposes:

  • refunds/create Webhook: Listens for order refund events in real time. When an order is fully refunded and contains unfulfilled items, the App evaluates your settings, executes an orderCancel mutation, optionally restocks items back into inventory, and archives the order.
  • app/uninstalled Webhook: Notifies our system when you uninstall the App. Our server automatically deletes your store's OAuth session records and access tokens from our database upon receipt.
  • app/scopes_update Webhook: Ensures your store's access scopes remain synchronized with the permissions granted to the App.
  • Audit Logging (Cleaned Orders Log): Records a timestamped entry in your dashboard database detailing the order ID, order name, customer name, customer email, action taken, and success/failure status for your store's review.

4. Data Storage & Security

  • Database Security: Store preferences, session records, and cleaned order logs are stored in a private, encrypted PostgreSQL database with strict network access control.
  • Transit Encryption: All communications between Shopify, our backend servers, and your browser are encrypted using modern Transport Layer Security (HTTPS/TLS 1.2+).
  • Access Control: Only authorized background worker tasks and authenticated store sessions can query order records for your specific store. Data across different shops is partitioned and never accessible across stores.

5. Data Sharing & Third-Party Disclosure

We do not sell, rent, monetize, or trade your store or customer personal data to third parties, advertisers, or data brokers.

Data is shared exclusively with Shopify Inc. through its official Admin GraphQL API and Partner API to authenticate sessions, execute order cancellation/restock actions, and verify subscription billing.

6. Data Retention & Deletion (Your Rights)

Merchants and buyers have rights regarding their personal information under applicable data protection regulations:

  • Automatic Deletion on Uninstall: When you uninstall RefundedOrder Autocleaner, your OAuth tokens and active sessions are promptly deleted from our servers via the app/uninstalled webhook.
  • Log Retention: Cleaned order logs are maintained to allow merchants to audit their order cleanup history. Merchants may clear or request deletion of historical logs at any time.
  • Data Subject Rights (GDPR / CCPA): If you or a customer wish to request access to, correct, or completely delete any data associated with your store or orders, please submit a request to us using the contact details below.

7. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our app features, Shopify platform updates, or legal obligations. The "Last updated" date at the top of this page will indicate when the latest revisions took effect.

8. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:

RefundedOrder Autocleaner Support

Email: [email protected]

Response time: Within 24-48 business hours