Version 2026-10-08 · Zentara LLC, trading as Merchavelo.
Scope and availability
This notice describes how PackReturn handles store data. PackReturn is preparing for App Store release and is not yet available for public installation. The store owner accepts the PackReturn merchant terms inside the app before sale setup.
The merchant determines why its sale records are processed. Zentara LLC processes those records to provide PackReturn on the merchant's instructions and is responsible for its own service-administration and support correspondence. Privacy contact: privacy@merchavelo.com. General support: PackReturn support.
Information PackReturn processes
- Shop identity, domain and installation state.
- Shopify staff authorization, permissions, session identifiers and encrypted access tokens. Shopify authentication can supply staff account information.
- Order and line identifiers, item titles, quantities, amounts, currency, payment status, completed refund facts and return facts.
- Versioned return policies, pre-sale receipts, matched original sale evidence and saved, unexecuted refund advice.
- The accepted merchant terms version, accepting staff account and time.
- Lifecycle events, privacy-request references, recovery state and early-shop free-access eligibility.
- Support correspondence and technical information needed to investigate a reported problem.
The order query does not request customer names, email addresses, phone numbers or postal addresses. Do not enter customer contact details in receipt titles, policy evidence or support messages. Identifiers and item records can still relate to an identifiable customer in the merchant's systems.
Purpose and access
PackReturn uses these records to authorize shop staff, match original sale evidence, calculate partial-return advice, show advice history, handle installation and privacy events, and prevent erased records from being restored into use. It reads Shopify orders and returns. It does not execute refunds, take payment, change orders or reserve stock. Staff review the result and perform any native action in Shopify.
Shopify supplies authentication and order APIs. Cloudflare supplies application hosting and storage. Support email is forwarded through Cloudflare Email Routing to the existing support mailbox. Cloudflare storage is not limited to the European Union, so data can be processed outside the merchant's country. The store owner agrees to these subprocessors and locations when accepting the merchant terms.
Retention
- Bound sale evidence and associated advice expire 365 days from the immutable pre-sale receipt timestamp. Later reads or advice saves do not restart that period.
- Policy versions expire 365 days after creation. Unbound receipts expire after 24 hours. Online sessions expire with their Shopify authorization.
- Valid privacy erasure can remove current business records earlier. Uninstall and shop-redaction events revoke app access and clear business state.
- Early-shop free-access eligibility survives ordinary uninstall; full shop erasure removes that grant.
- Minimal lifecycle, erasure and privacy-request markers are kept for as long as the store's app records can exist, so that erased records cannot return from a later import or restore. They contain hashed shop or order identifiers and no order details, and are not used for any other purpose.
- Our copy of a privacy export is deleted within 30 days after delivery.
Deleting current application state does not certify immediate removal from recoverable provider history. Cloudflare storage recovery can include the preceding 30 days. Recovery must respect the separate erasure records before data is made available again.
Privacy requests
Email privacy@merchavelo.com with the app name, shop domain and the nature of your request. Customers should contact their merchant first so the merchant can identify the relevant order and authorize the request. Do not attach full customer exports or credentials. We may need proportionate verification before disclosing or deleting information.
PackReturn verifies Shopify's signed customer data and redaction requests. We respond within 30 days. A customer data export is delivered to the verified store owner through a protected channel, never as an ordinary email attachment. Receiving a webhook acknowledgement does not by itself mean an export has been delivered.
Where applicable, privacy law provides rights to access, correction, erasure, restriction, objection and portability, and to complain to a supervisory authority. Contact us to raise a concern.
Marketing
PackReturn does not collect Shopify customer contact details for Merchavelo marketing, sell app records or send them to advertising services. App installation and support enquiries do not enroll anyone in a marketing list. Any future Merchavelo newsletter will require a separate voluntary choice and an unsubscribe option.
Changes
The version above identifies this notice. Material changes are published here. The website privacy notice covers visits to merchavelo.com and website enquiries; other apps have their own notices in the app directory.