Privacy Policy

Draft. 19 details in [brackets] still need to be filled in before this document takes effect.

Effective date: [DATE]
Last updated: [DATE]

This Privacy Policy explains how REASONBACK ("REASONBACK", "we", "us") collects, uses, shares and protects personal data. REASONBACK is operated by [LEGAL ENTITY NAME], with its address at 1st District, Obour City, Cairo.

REASONBACK is a returns and exchange portal for online stores ("Brands"), most of which sell through Shopify. This policy covers three groups of people:

1. Brand users: the owners and team members of Brands who use the REASONBACK dashboard.
2. Shoppers: customers of a Brand who use that Brand's return portal, or whose orders are synced into REASONBACK.
3. Visitors: people who visit our website and documentation.

1. Our role

For Brand users and Visitors, we decide how and why their data is used. We are the controller of that data.

For Shoppers, the Brand decides why their data is used, and we process it only on the Brand's behalf and on its instructions. The Brand is the controller and we are its processor. Our processing for Brands is governed by our Data Processing Agreement. If you are a Shopper, the Brand's own privacy policy also applies to you, and you should normally contact the Brand first with any request about your data. We will help the Brand answer you.

2. Data we collect

2.1 Brand users

  • Account details: name, email address, role, the Brand you belong to, and your sign-in method.
  • Sign-in data: your password is stored only in a one-way hashed form by our authentication provider. We never see it in readable form. We also record your last sign-in time and the country of sign-in.
  • Activity records: actions you take on return requests (who, what and when), so your Brand has a reliable history.
  • Integration keys: the access keys that connect your store to Shopify and Bosta. They are encrypted before storage and never shown back to anyone.
  • Billing details: [plan, invoices, and payment status. Card details are handled by [PAYMENT PROVIDER / Shopify Billing] and never reach us].
  • Support messages: anything you send us when you contact support.

2.2 Shoppers (processed on behalf of the Brand)

  • Contact details: name, phone number, email address and delivery or pickup address, copied from the Brand's Shopify orders or entered by the Shopper.
  • Order details: items bought, prices, dates, discount codes and product tags.
  • Return requests: items, reasons, notes, the chosen refund method, and a timeline of each step.
  • Photos: images the Shopper uploads to show a problem. They are resized on upload, and location and camera metadata are removed.
  • Refund details: the InstaPay address or mobile wallet number the Shopper gives, the transfer reference, and the proof of transfer uploaded by the Brand.
  • Messages: a record of emails or messages sent to the Shopper about their return.
  • Security data: to stop order-number guessing, we keep a one-way scrambled code derived from the visitor's connection, not their IP address.

We do not collect card numbers or bank account numbers through the portal.

2.3 Visitors

  • Anonymous visit counts that contain no names, phone numbers or order numbers.
  • Essential cookies needed to keep you signed in. We do not use advertising or third-party tracking cookies.

We do not sell personal data, and we do not use Shopper data for advertising, profiling, or training AI models, or for any purpose of our own.

4. Who we share data with

We share personal data only with service providers who help us run REASONBACK ("sub-processors"), and only to the extent they need it:

The current list is kept at [URL /legal/subprocessors].

Integrations the Brand chooses. When a Brand connects Shopify or Bosta, we exchange data with those services on the Brand's instruction. For example, we send the Shopper's name, phone number and address to Bosta so a courier can collect the return. Shopify and Bosta handle that data under their own terms with the Brand.

Other cases. We may disclose data if required by law or a valid order from a competent authority, to protect the safety or rights of people or of REASONBACK, or as part of a merger or sale of the business, in which case this policy will continue to protect the data.

5. International transfers

Our main data storage is in the European Union. Some providers may process limited data outside the country where you are located. Where the law requires it, we rely on appropriate safeguards (such as standard contractual clauses) and any approvals required by applicable law, including Egypt's Personal Data Protection Law No. 151 of 2020.

6. How long we keep data

After a Shopper's data is erased, a record of the return remains (items, dates, amounts and governorate) without their name, contact details or address, because the Brand needs it for stock and financial records.

7. How we protect data

Security measures include: encryption in transit (HTTPS) and at rest; server-side checks of identity, Brand and role on every request; a database closed to direct browser access; encryption (AES-256) of integration keys; private files served only through links that expire after one hour; role-based permissions; mandatory two-step sign-in for REASONBACK staff; and audit logs of every access by REASONBACK staff. More detail is on our security page.

Staff access. Authorised REASONBACK staff may open a Brand's account only to provide support, in a read-only view that closes after one hour. Every access is logged.

No system is perfectly secure. If a personal data breach affects your data, we will notify the affected Brand without undue delay, and in any case within 72 hours of becoming aware of it, and notify authorities where the law requires.

8. Your rights

Depending on the law that applies to you, you may have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent.

  • Brand users: contact us at [privacy@DOMAIN].
  • Shoppers: contact the Brand you bought from. If you contact us directly, we will forward your request to the Brand and help it respond.

We respond within 30 days. You may also complain to your data protection authority, including Egypt's Personal Data Protection Center.

9. Children

REASONBACK is a business tool and is not directed at children. Brands must not use it to collect data from children in a way that breaks the law.

10. Changes to this policy

We will post changes on this page and update the date above. For significant changes, we will notify Brand owners by email or in the dashboard at least [14] days before they take effect.

11. Contact

[LEGAL ENTITY NAME]
1st District, Obour City, Cairo
Privacy: [privacy@DOMAIN]
Security issues: [security@DOMAIN]