Privacy Policy
Last updated September 3, 2026
Returnio is a Shopify app built and operated by Talivio Technology OÜ ("Talivio", "we", "us"). Returnio helps merchants run self-serve returns and exchanges for their customers. This policy explains what data passes through Returnio, why, and what happens to it.
When a merchant installs Returnio, the merchant is the data controller for their shoppers' information -- Returnio processes it on the merchant's behalf, under Shopify's own merchant-facing terms and this policy.
What we collect, and why
| Data | Source | Purpose |
|---|---|---|
| Order number, shipping postal code | Typed by the shopper in the return portal | To look up the order and confirm the shopper is entitled to see it -- no password or account is ever created |
| Order, line items, shipping address, customer name and email | Read from the merchant's Shopify store via the Shopify Admin API | To show the shopper what they can return and process the outcome they choose |
| Return reason, an optional note, chosen outcome (refund / exchange / store credit) | Typed by the shopper in the return portal | To carry out and record the return |
| Return and refund records | Created by Returnio, written back to Shopify | So the merchant's own Shopify admin reflects the outcome |
Returnio does not run ads, does not sell data, and does not use shopper data for marketing.
How data is stored
A shopper's name, email address, and shipping address are encrypted at rest in Returnio's database. A separate, non-reversible value derived from the email address is used only to look up a shopper's own past returns (for example, to flag a repeat return) -- it cannot be turned back into the original email address.
Who else sees it
- Shopify -- Returnio reads and writes order and return data through Shopify's Admin API, under Shopify's own Privacy Policy.
- The merchant -- return records, including the shopper's contact details, are visible to the merchant in Returnio's admin screen inside their Shopify admin, the same way an order is.
- Email delivery -- return confirmation emails are sent through Talivio's own transactional email infrastructure, solely to deliver that email.
Returnio does not share shopper data with any other third party.
Your rights (GDPR and equivalent laws)
A shopper can ask the merchant they bought from to access or delete the personal data Returnio holds about them. Shopify requires every app to support this, and Returnio does: a merchant's request is relayed to us automatically by Shopify and fulfilled without manual handling. You can also contact us directly at [email protected] and we will forward your request to the relevant merchant.
When a merchant uninstalls Returnio, Shopify notifies us and we permanently delete that store's data, including every shopper record tied to it, typically within 48 hours.
Data retention
While a return is being handled, we keep everything needed to process it. Once a return is finished (completed, cancelled, rejected, or expired), the information that identifies you as the shopper -- your name, email, and shipping address -- is automatically removed after 2 years; the merchant's underlying record of the return itself (what was returned, its outcome) is kept so their own refund and accounting history stays accurate. If the merchant uninstalls Returnio, everything tied to their store, including this, is deleted immediately (see above).
Changes to this policy
If this policy changes materially, the date at the top of this page will change. Continued use of Returnio after a change means you accept the update.
Contact
Talivio Technology OÜ
[email protected]