Skip to content

Data Processing Agreement

Last updated: September 18, 2026

This Data Processing Agreement ("DPA") is part of the Eturns Terms of Service at /policy/terms. It applies when a Shopify merchant directs Eturns to process personal data of that merchant's customers.

It is written for operators. The roles are below. The operational facts match the Privacy Policy at /policy/privacy.

1. Roles

  • Merchant = controller of their store's customer data (or, if the merchant is itself a processor, a processor of their end-controllers).
  • Eturns = processor acting on the merchant's documented instructions — the in-app constitution plus this DPA.

2. What we process, for how long

Eturns processes personal data to run the after-sales operator: returns, exchanges, refunds, warranty, tracking, tickets, reviews, fraud signals, and recovery offers. Processing lasts for the subscription term plus the 48-hour purge window after uninstall or a shop/redact webhook.

3. People and data

  • People: the merchant's customers, and anyone named in a ticket or claim.
  • Data: identity (name, email, address, phone), commercial (orders, returns, refunds), behavioural (return cadence, fraud signals), content (submissions, messages, photos), and communications we send.

4. What Eturns does

  • Process personal data only on the merchant's documented instructions.
  • Keep people who handle the data under confidentiality.
  • Use the technical and organizational measures in the Security section of the Privacy Policy at /policy/privacy.
  • Engage subprocessors only with prior general authorization — the list at /policy/subprocessors — and bind them to equivalent terms.
  • Help the merchant with data-subject requests, breach notice, and assessments where required.
  • Delete or return personal data within 30 days of termination, and immediately on shop/redact.

5. Subprocessors

The authorized list is /policy/subprocessors. We tell merchants about additions or material changes 30 days in advance, as that page describes.

6. International transfers

Personal data we persist rests in India. Compute runs in Singapore. Some subprocessors process telemetry or send email outside those regions. India is not currently the subject of a European Commission adequacy decision. The terms that govern these transfers are this DPA and each subprocessor's own data processing agreement, listed at /policy/subprocessors. We do not claim that any particular model clause is in force or sufficient on its own.

7. Audits

Once per 12 months, on request, we provide a written summary of how we comply with this DPA and access to relevant security certifications our subprocessors publish (Shopify SOC 2, Supabase SOC 2, and the like). On-site audits need 30 days' notice and run at the merchant's expense.

8. Breach notification

We notify the merchant of a confirmed personal-data breach without undue delay and in any event within 72 hours, with the facts the merchant needs for its own notice duties.

9. Liability and governing law

Liability under this DPA follows the limits in the Terms of Service. This DPA is governed by the laws of Singapore, the same venue as the Terms, except where mandatory data-protection law of another place also applies.

10. Contact

Eturns Inc. — contact@eturns.app

Questions about this policy? Email contact@eturns.app.