Privacy Policy
Draft. 19 details in [brackets] still need to be filled in before this document takes effect.
Effective date: [DATE]
Last updated: [DATE]
This Privacy Policy explains how REASONBACK ("REASONBACK", "we", "us") collects, uses, shares and protects personal data. REASONBACK is operated by [LEGAL ENTITY NAME], with its address at 1st District, Obour City, Cairo.
REASONBACK is a returns and exchange portal for online stores ("Brands"), most of which sell through Shopify. This policy covers three groups of people:
1. Brand users: the owners and team members of Brands who use the REASONBACK dashboard.
2. Shoppers: customers of a Brand who use that Brand's return portal, or whose orders are synced into REASONBACK.
3. Visitors: people who visit our website and documentation.
1. Our role
For Brand users and Visitors, we decide how and why their data is used. We are the controller of that data.
For Shoppers, the Brand decides why their data is used, and we process it only on the Brand's behalf and on its instructions. The Brand is the controller and we are its processor. Our processing for Brands is governed by our Data Processing Agreement. If you are a Shopper, the Brand's own privacy policy also applies to you, and you should normally contact the Brand first with any request about your data. We will help the Brand answer you.
2. Data we collect
2.1 Brand users
- Account details: name, email address, role, the Brand you belong to, and your sign-in method.
- Sign-in data: your password is stored only in a one-way hashed form by our authentication provider. We never see it in readable form. We also record your last sign-in time and the country of sign-in.
- Activity records: actions you take on return requests (who, what and when), so your Brand has a reliable history.
- Integration keys: the access keys that connect your store to Shopify and Bosta. They are encrypted before storage and never shown back to anyone.
- Billing details: [plan, invoices, and payment status. Card details are handled by [PAYMENT PROVIDER / Shopify Billing] and never reach us].
- Support messages: anything you send us when you contact support.
2.2 Shoppers (processed on behalf of the Brand)
- Contact details: name, phone number, email address and delivery or pickup address, copied from the Brand's Shopify orders or entered by the Shopper.
- Order details: items bought, prices, dates, discount codes and product tags.
- Return requests: items, reasons, notes, the chosen refund method, and a timeline of each step.
- Photos: images the Shopper uploads to show a problem. They are resized on upload, and location and camera metadata are removed.
- Refund details: the InstaPay address or mobile wallet number the Shopper gives, the transfer reference, and the proof of transfer uploaded by the Brand.
- Messages: a record of emails or messages sent to the Shopper about their return.
- Security data: to stop order-number guessing, we keep a one-way scrambled code derived from the visitor's connection, not their IP address.
We do not collect card numbers or bank account numbers through the portal.
2.3 Visitors
- Anonymous visit counts that contain no names, phone numbers or order numbers.
- Essential cookies needed to keep you signed in. We do not use advertising or third-party tracking cookies.
3. Why we use data, and our legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service to Brands | Brand user and Shopper data | Our contract with the Brand. For Shopper data, the Brand's instructions |
| Keeping accounts and portals secure (sign-in, preventing abuse, rate limiting) | Sign-in data, security data | Our legitimate interest in security |
| Customer support | Support messages, account data | Contract / legitimate interest |
| Billing | Billing details | Contract, legal obligations (tax, accounting) |
| Improving the service | Anonymous and aggregated usage data only | Legitimate interest |
| Legal compliance and disputes | Relevant records | Legal obligation / legitimate interest |
We do not sell personal data, and we do not use Shopper data for advertising, profiling, or training AI models, or for any purpose of our own.
4. Who we share data with
We share personal data only with service providers who help us run REASONBACK ("sub-processors"), and only to the extent they need it:
| Provider | What they do | Location of data |
|---|---|---|
| Supabase | Database, sign-in, file storage | European Union (Frankfurt, Germany) |
| Vercel | Application hosting | [Region: e.g. Frankfurt (fra1)]; global network for delivery |
| [EMAIL PROVIDER] | Sending emails to Brand users and Shoppers | [LOCATION] |
| [ERROR MONITORING PROVIDER, if any] | Error reports (without message contents) | [LOCATION] |
The current list is kept at [URL /legal/subprocessors].
Integrations the Brand chooses. When a Brand connects Shopify or Bosta, we exchange data with those services on the Brand's instruction. For example, we send the Shopper's name, phone number and address to Bosta so a courier can collect the return. Shopify and Bosta handle that data under their own terms with the Brand.
Other cases. We may disclose data if required by law or a valid order from a competent authority, to protect the safety or rights of people or of REASONBACK, or as part of a merger or sale of the business, in which case this policy will continue to protect the data.
5. International transfers
Our main data storage is in the European Union. Some providers may process limited data outside the country where you are located. Where the law requires it, we rely on appropriate safeguards (such as standard contractual clauses) and any approvals required by applicable law, including Egypt's Personal Data Protection Law No. 151 of 2020.
6. How long we keep data
| Data | Retention |
|---|---|
| Shopper details, orders and return requests | While the Brand uses REASONBACK. Erased when the Shopper's erasure request is received, or about 48 hours after the Brand uninstalls the app |
| Shopper photos and refund proofs | [Until erasure as above / X months after the return is closed] |
| Records of notifications from Shopify and Bosta (without contents) | 30 days |
| Error records | 60 days |
| Order sync history | 90 days |
| Anonymous portal visit counts | About 13 months |
| REASONBACK staff access audit log (no Shopper personal data) | [X months] |
| Brand user accounts | Until the account is deleted, plus [30] days |
| Billing records | As required by tax and accounting law |
| Backups | Overwritten within [X] days. Erased data disappears from backups within this time |
After a Shopper's data is erased, a record of the return remains (items, dates, amounts and governorate) without their name, contact details or address, because the Brand needs it for stock and financial records.
7. How we protect data
Security measures include: encryption in transit (HTTPS) and at rest; server-side checks of identity, Brand and role on every request; a database closed to direct browser access; encryption (AES-256) of integration keys; private files served only through links that expire after one hour; role-based permissions; mandatory two-step sign-in for REASONBACK staff; and audit logs of every access by REASONBACK staff. More detail is on our security page.
Staff access. Authorised REASONBACK staff may open a Brand's account only to provide support, in a read-only view that closes after one hour. Every access is logged.
No system is perfectly secure. If a personal data breach affects your data, we will notify the affected Brand without undue delay, and in any case within 72 hours of becoming aware of it, and notify authorities where the law requires.
8. Your rights
Depending on the law that applies to you, you may have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent.
- Brand users: contact us at [privacy@DOMAIN].
- Shoppers: contact the Brand you bought from. If you contact us directly, we will forward your request to the Brand and help it respond.
We respond within 30 days. You may also complain to your data protection authority, including Egypt's Personal Data Protection Center.
9. Children
REASONBACK is a business tool and is not directed at children. Brands must not use it to collect data from children in a way that breaks the law.
10. Changes to this policy
We will post changes on this page and update the date above. For significant changes, we will notify Brand owners by email or in the dashboard at least [14] days before they take effect.
11. Contact
[LEGAL ENTITY NAME]
1st District, Obour City, Cairo
Privacy: [privacy@DOMAIN]
Security issues: [security@DOMAIN]