Compliance
Last updated: August 12, 2026
Eturns treats compliance as an operational substrate, not a marketing checkbox. This page summarizes our posture across GDPR, CCPA, the Indian DPDP Act, and the Shopify App Store privacy requirements.
GDPR (European Union & UK)
Eturns acts as a data processor on behalf of the installing merchant. The merchant is the controller of their store’s customer data. We process personal data only for the after-sales purposes the merchant configured Eturns to handle.
- Mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) are implemented with HMAC verification and idempotency.
- Right to erasure is satisfied via the customers/redact webhook cascading through return requests, tickets, embeddings, and photo storage within 48 hours.
- Article 22 (automated decision-making): every agent decision has a merchant override path; the audit trail records it.
- AI disclosure is present on every AI-generated customer email and on the DSR portal.
CCPA (California)
California residents have the right to know, access, delete, correct, opt out of certain sales or sharing, and not be discriminated against for exercising privacy rights. We do not sell personal information for money. Where required, we honor Global Privacy Control signals.
DPDP Act (India)
For Indian data principals, Eturns acts as a Significant Data Fiduciary for the after-sales processing it performs. Consent is collected at merchant onboarding. A Grievance Officer is available per the DPDP Act — see /policy/india-grievance.
Shopify App Store privacy (PCD)
Our Protected Customer Data (PCD) questionnaire answers are filed in Shopify Partners and mirrored in our internal compliance binder. In summary:
- We access order, customer, and product data via the Shopify Admin API to resolve after-sales cases.
- We do not sell merchant or customer data.
- Customer PII is minimized in our database; emails are sha256-hashed where persisted.
- No raw PII is sent to language models — case facts use sentinel IDs and structured fields.
- All model traffic goes through the Vercel AI Gateway. Sub-processors are disclosed at /policy/subprocessors.
- Mandatory GDPR webhooks are implemented with HMAC + idempotency; payloads are encrypted at rest when a key is configured.
EU AI Act transparency
AI involvement is disclosed on every AI-generated customer email and on every AI-mediated customer surface. The disclosure is never removed by white-labeling; merchants can adjust the wording but cannot remove it.
Tax compliance
Shopify Billing handles sales tax for US merchants and VAT for EU merchants. For Indian merchants we register for GST and issue compliant invoices in INR with the CGST/SGST or IGST breakdown, unless the merchant opts for the reverse-charge mechanism. See /pricing for tier details.
Questions about this policy? Email support@eturns.app.