Opus Returns & Exchanges
Privacy Policy
This policy explains how Opus handles merchant and buyer information when providing returns and exchange workflows.
Effective date: 2026-08-05
Who operates Opus
Opus Returns & Exchanges operates the Opus Returns & Exchanges Shopify application. Shopify merchants choose whether to install and configure Opus for their stores.
Information we process
Opus processes the minimum information needed to evaluate and manage return, exchange, refund, store-credit, replacement, and resend requests. Depending on the workflow, this can include:
- Shop identity, configuration, locations, locale, products, variants, inventory, and return rules.
- Shopify order, fulfillment, return, refund, transaction, draft-order, and fulfillment-order identifiers and status.
- Customer and order identifiers, checkout email used to verify guest access, and shipping country used for eligibility and routing.
- Request reasons, customer and merchant messages, selected resolutions, tracking details, inspection results, and uploaded evidence.
- Technical and security records such as timestamps, rate-limit fingerprints, error categories, and audit events.
Opus does not store raw checkout email on a return request. It stores a secret-keyed digest where correlation is required. Opus does not collect card numbers or process payments outside Shopify.
How information is used
- Provide and secure the requested return or order-help workflow.
- Show merchants and authorized customers the status of a request.
- Create Shopify-native returns, refunds, store credit, exchanges, replacement orders, and related fulfillment work after confirmation.
- Deliver operational messages, investigate errors, prevent duplicate actions, and meet legal privacy obligations.
Opus does not sell personal information and does not use merchant or buyer data for advertising or unrelated personalization.
Storage, retention, and deletion
Evidence and generated exports are kept in private, access-controlled object storage and delivered through short-lived links. General exports expire after seven days. Customer privacy exports expire after 30 days. Completed or declined request data is minimized after the merchant-configured retention period, which defaults to 365 days. Short-lived portal sessions and operational records are removed on shorter schedules.
Shopify’s mandatory customer-data and shop-redaction requests are authenticated, durably queued, and processed by Opus. A shop-redaction request removes the shop’s Opus records and private stored objects.
Service providers and processing locations
Opus uses Shopify and the service providers required to host, store, monitor, and deliver the application. The configured providers are:
- Shopify
- Railway
Processing locations: United States
Security and cookies
Opus uses Shopify-authenticated requests, HTTPS in production, tenant-scoped database access, private evidence storage, short-lived signed links, restricted operational logging, and confirmation and idempotency controls for consequential actions. Uploaded images are decoded, metadata-stripped, normalized, and re-encoded before storage.
Opus does not use advertising cookies. Shopify manages embedded-app authentication. The storefront portal may remember a storefront font preference in the browser; customer access is otherwise verified with short-lived, server-backed sessions.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, or restriction of personal information. Buyers should normally contact the Shopify merchant they purchased from. Merchants and buyers can also contact Opus using the privacy contact below.
Contact
Opus Returns & Exchangesopusreturns@gmail.com