Version 2026-10-07 · Zentara LLC, trading as Merchavelo.
Scope and availability
This notice describes PackReturn's current private testing build. PackReturn is preparing for release and is not available for public installation. Testing uses a designated development store and synthetic sale records. Before public installation, this notice will be reviewed against the released service and its request-handling procedures.
The merchant determines why its sale records are processed. Zentara LLC processes those records to provide PackReturn on the merchant's instructions and is responsible for its own service-administration and support correspondence. Privacy contact: privacy@merchavelo.com. General support: PackReturn support.
Information PackReturn processes
- Shop identity, domain and installation state.
- Shopify staff authorization, permissions, session identifiers and encrypted access tokens. Shopify authentication can supply staff account information.
- Order and line identifiers, item titles, quantities, amounts, currency, payment status, completed refund facts and return facts.
- Versioned return policies, pre-sale receipts, matched original sale evidence and saved, unexecuted refund advice.
- Lifecycle events, privacy-request references, recovery state and early-shop free-access eligibility.
- Support correspondence and technical information needed to investigate a reported problem.
The order query does not request customer names, email addresses, phone numbers or postal addresses. Do not enter customer contact details in receipt titles, policy evidence or support messages. Identifiers and item records can still relate to an identifiable customer in the merchant's systems.
Purpose and access
PackReturn uses these records to authorize shop staff, match original sale evidence, calculate partial-return advice, show advice history, handle installation and privacy events, and prevent erased records from being restored into use. It reads Shopify orders and returns. It does not execute refunds, take payment, change orders or reserve stock. Staff review the result and perform any native action in Shopify.
Shopify supplies authentication and order APIs. Cloudflare supplies application hosting and storage. Support email is forwarded through Cloudflare Email Routing to the existing support mailbox. This configuration does not establish processing only within the EU. Applicable data-processing agreements and transfer safeguards must be in place before a public service processes personal data.
Retention in the current build
- Bound sale evidence and associated advice expire 365 days from the immutable pre-sale receipt timestamp. Later reads or advice saves do not restart that period.
- Policy versions expire 365 days after creation. Unbound receipts expire after 24 hours. Online sessions expire with their Shopify authorization.
- Valid privacy erasure can remove current business records earlier. Uninstall and shop-redaction events revoke app access and clear business state.
- Early-shop free-access eligibility survives ordinary uninstall; full shop erasure removes that grant.
- Separate lifecycle, request and recovery records include linkable hashes of shop or order identifiers. The current build does not automatically age out all of that metadata. A defined retention schedule for those records is a release requirement.
Deleting current application state does not certify immediate removal from recoverable provider history. Cloudflare storage recovery can include the preceding 30 days. Recovery must respect the separate erasure records before data is made available again.
Privacy requests
Email privacy@merchavelo.com with the app name, shop domain and the nature of your request. Customers should contact their merchant first so the merchant can identify the relevant order and authorize the request. Do not attach full customer exports or credentials. We may need proportionate verification before disclosing or deleting information.
PackReturn's private build includes signed Shopify privacy-event handling. End-to-end request fulfilment, secure export delivery, export expiry and a verified recovery rehearsal remain prerequisites for public release. Receiving a webhook acknowledgement does not mean an export has been delivered.
Where applicable, privacy law provides rights to access, correction, erasure, restriction, objection and portability, and to complain to a supervisory authority. Contact us to raise a concern about testing or correspondence.
Marketing
PackReturn does not collect Shopify customer contact details for Merchavelo marketing, sell app records or send them to advertising services. App installation and support enquiries do not enroll anyone in a marketing list. Any future Merchavelo newsletter will require a separate voluntary choice and an unsubscribe option.
Changes
The version above identifies this prelaunch notice. A released service will publish its current notice here. The website privacy notice covers visits to merchavelo.com and website enquiries; other apps have their own notices in the app directory.