Privacy Policy
Last updated: July 30, 2026
Rogue Return ("the App") is a Shopify application operated by Juiced Systems ("we", "us"). The App lets merchants create customer returns with prepaid shipping labels directly from the customer page in the Shopify admin. This policy explains what data the App processes, why, and what happens to it.
Data we store
We keep our stored footprint deliberately small:
- Merchant authentication sessions. When a store installs the App, Shopify issues OAuth access tokens that we store in our database so the App can call the Shopify Admin API on the merchant's behalf. For staff members who open the App, the session record may include the staff member's name, email address, and locale as provided by Shopify. This is data about the merchant's staff, not about the merchant's customers.
- App settings. Saved return-destination addresses and package-size presets are stored as metafields inside the merchant's own Shopify store, not on our servers.
Customer data we process (but do not store)
When a merchant creates a return, the App reads the following from the Shopify Admin API, uses it to complete that single operation, and does not persist it in our systems:
- Customer name, email address, phone number, and shipping address
- Order and line-item details for the items being returned
This data is used solely to create the return order, purchase the return shipping label through Shopify Shipping, and let Shopify send its native return-instructions notification to the customer. The resulting orders, returns, and labels live in the merchant's Shopify store — Shopify's own privacy policy governs that data. The merchant remains the controller of their customers' personal data; we act only as a processor/service provider on the merchant's instructions.
What we don't do
- We do not sell or rent personal data to anyone.
- We do not use personal data for advertising or profiling.
- We do not share personal data with third parties except the infrastructure providers below, and only as needed to run the App.
Service providers
The App is hosted on Vercel, and merchant session records are stored in a managed PostgreSQL database. Both providers process data on our behalf under their own security and privacy commitments. All traffic between your browser, Shopify, and the App is encrypted in transit (TLS/HTTPS).
Retention and deletion
- When a store uninstalls the App, its stored sessions are deleted.
- We honor Shopify's mandatory privacy webhooks:
customers/data_request,customers/redact, andshop/redact. Because we do not store customer personal data, customer data requests and redactions have nothing to return or erase; shop redaction removes any remaining merchant-session records for that store.
Your rights
Depending on where you live (for example under GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or restrict processing of your personal data. Merchants can exercise these rights — for themselves or on behalf of their customers — by contacting us at dylan@juicedsystems.com. Customers of a store using the App should contact that store directly, since the store controls their data.
Changes to this policy
If we make material changes to this policy, we will update this page and revise the "Last updated" date above.
Contact
Juiced Systems — dylan@juicedsystems.com