Privacy Policy
Last updated 7 August 2026
Who we are
Swapify+ is a returns and exchanges application for Shopify stores, operated by MO TECH Solutions. Merchants install it on their store; their customers use it to request a return or an exchange.
For data about a merchant's customers, the merchant is the data controller and MO TECH Solutions is the processor. We handle that data to provide the service to the merchant, and for nothing else.
What we collect, and why
When a customer files a return request, we store:
- their email address and phone number, so the merchant can reply
- the order number, and the items selected from that order
- the reason given, and any note written
- photographs uploaded as evidence of the item's condition
- a salted, truncated hash of the submitting IP address — used to rate limit and to trace abuse. The address itself is not stored.
From the merchant's Shopify store we read the order being returned and the products on it, using the read_orders and read_products permissions. We request no others. We do not read the merchant's customer list, and we do not write anything back to their store.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not use it to train machine learning models.
- We do not combine data across merchants. Each merchant's data is isolated, and no merchant can see another's.
Where it is held
Request data is stored in a PostgreSQL database hosted by Supabase. Photographs are stored in a private object storage bucket — they are never publicly readable, and the merchant's staff view them through short-lived signed links that expire after five minutes.
Access tokens for a merchant's Shopify store are encrypted at rest with AES-256-GCM. The encryption key is held outside the database.
How long we keep it
- Return requests and their photographs are kept while the merchant keeps the app installed, so the merchant retains a record of decisions they made.
- When a merchant uninstalls, Shopify notifies us and we stop processing immediately. Shopify then sends an erasure instruction 48 hours later, on receipt of which all of that merchant's data — requests, photographs, staff accounts, and audit history — is deleted.
- Webhook delivery records are kept for 30 days, which is what stops the same event being processed twice.
Your rights
If you are a customer of a store using Swapify+, your relationship is with that store. Ask them to access, correct, or delete your data and they can instruct us through Shopify; we action those instructions automatically.
Requests for erasure delete the return requests filed under your email address for that store, together with every photograph attached to them. Deletion is permanent and is not recoverable from backup after the backup rotates.
Sub-processors
- Supabase — database and file storage
- Vercel — application hosting
- Shopify — the source of order data, and the merchant's own platform
Changes
Material changes will be notified to merchants by email before they take effect. The date at the top of this page is the last revision.