Emplario · Refund Integrity Guard
Privacy policy
Effective 7 October 2026. This policy covers Refund Integrity Guard, provided by EMPLARIO LTD, trading as Emplario, registration HE 486307, Eleftheriou Venizelou 48, 8021 Paphos, Cyprus. Director: Sven Dorin Lapadus. Contact: emplario.support@proton.me.
Our role and purpose
We process Shopify store evidence on the merchant's instructions to identify refund and return issues, explain findings and maintain an audit history. The merchant controls its store data. We act as controller for our own support communications and service-security records, using them to provide the service, respond to requests and protect it from abuse. The relevant bases are performance of our service agreement, legitimate interests in support and security, and applicable legal obligations.
Data the app uses
We read Shopify order, refund, transaction, return, inventory and location evidence within the granted read-only permissions. Stored information includes shop domains, Shopify object identifiers, exact monetary amounts and currencies, quantities, timestamps, case classifications, evidence snapshots, audit events and processing status. We do not request customer names, customer email addresses, phone numbers, addresses, card details or bank credentials through our Shopify queries. Order identifiers and transaction evidence may nevertheless relate to individuals.
Shopify authentication sessions can contain merchant or staff user identifiers, first and last names, email, locale, account-owner and collaborator flags, token expiry and verification status. Access and refresh tokens are encrypted by the application; the other session fields are not separately application-encrypted. Support emails contain the information you choose to send.
How data is used and protected
We use this data for authenticated app access, deterministic findings, canonical rereads, exports, tenant isolation and operational security. The app does not sell personal data, serve behavioral advertisements or use findings to make legal or similarly significant automated decisions about people. Findings are evidence for merchant review; unavailable information is not treated as a confirmed financial outcome.
Access is limited to the relevant shop and authorized operators. Webhooks are authenticated, tokens are encrypted at rest and operational logs avoid raw webhook bodies and tokens. We do not store webhook bodies. Essential authentication/session mechanisms are used; the app does not add advertising trackers.
Providers and locations
The service integrates with Shopify and uses Railway for app hosting and database storage. Its configured hosting region is EU West. The designated Backblaze B2 backup bucket is in US East; when backup processing is enabled, encrypted database copies are transferred there. A private Google Drive folder controlled by Emplario stores a password-encrypted recovery package containing versioned recovery keys and an already encrypted database snapshot. Providers and their infrastructure may process data outside your country. Contact us for information about applicable data-processing terms and international-transfer safeguards. We do not represent that encryption alone replaces any legally required transfer mechanism.
Retention and deletion
While installed, open cases remain available. Verified-resolved evidence is retained according to the merchant's configured policy, from 30 to 730 days. Completed operational records are removed by the app's retention process. Shopify uninstall and shop-redaction notifications trigger deletion of active tenant records and sessions. Support correspondence is retained only as needed to resolve the request and meet applicable legal obligations.
Encrypted backup copies, when enabled, are eligible for removal after seven days and are removed on the next successful six-hour backup run. Retention can be longer during an operational failure. Deletion from the active database does not edit an older backup. A restoration must reapply subsequent deletion requests before normal service resumes. Until that expiry, backup copies are restricted to recovery use.
Your requests and rights
Contact emplario.support@proton.me to request information, access, correction, deletion, restriction, portability or to object to processing where applicable. We may need to verify your identity and authority over the shop. If the merchant is the controller of the requested store data, we will assist it with the request. You may complain to your competent supervisory authority, including the Office of the Commissioner for Personal Data Protection in Cyprus.
The separate Drive recovery package is manually versioned and is not subject to B2's automatic seven-day expiry. Its database snapshot must be reviewed and replaced or removed through the protected recovery procedure when deletion is required; keys needed for retained backups are preserved. It is never used to bypass later deletion requests when restoring service.
Shopify customer privacy requests
Shopify privacy webhooks can include customer identity fields. We authenticate and process those messages transiently without storing their bodies or customer identity fields. For data requests, we retain the request reference and requested order identifiers until fulfillment or tenant deletion, and provide matching app records to the authenticated merchant in Help & support. The merchant must respond securely to the customer within 30 days and then confirm fulfillment. Confirmation clears the requested order list. Acknowledging Shopify's webhook or downloading a file does not itself mean the customer has been answered.
Order deletion requests remove matching active cases, evidence, history and processing records. We retain the shop domain, a pseudonymous hash of the shop and order reference, and the deletion time to prevent old reads or reinstallation from recreating the erased records. This suppression reference is not anonymous data and is used only for deletion enforcement and recovery. Previously delivered merchant-configured Flow workflow data remains under the merchant's control.
Changes
We update this page when our processing changes and revise its effective date. Material changes affecting installed merchants will be communicated through an appropriate service channel.