Privacy policy
Last updated: July 14, 2026
easyReturn (“we”) is the returns assistant at easyreturn.us and its companion browser extension. The short version: we collect the minimum needed to start your returns and cancellations, we never sell your data, and there are no ads or cross-site trackers.
What we collect
- Email address — to sign you in with one-time magic links and keep your returns under your account.
- Return details you enter — store, order number, items, reason, and, when you buy a real shipping label, the name and address the label needs.
- Orders you import — if you paste an order confirmation email or connect Gmail, we extract and store the merchant, order number, items, and dates. We do not keep the email itself.
Card payments for postage and Pro subscriptions are handled by Stripe — we never see or store your full card number. We store payment records tied to your return (amount, status, and Stripe payment id) so we can fulfill the label or refund you if purchase fails, and we store subscription status (plan, period end, Stripe customer/subscription ids) to enforce Pro entitlements. We use no analytics or advertising trackers. The only cookie is the signed session cookie that keeps you signed in.
How we use it
Only to run the service: signing you in, creating and tracking your returns, buying return postage you request, managing Pro subscriptions, and emailing you sign-in links. We never sell or rent personal data, and we do not use it for advertising.
Gmail access (Pro)
Gmail connect is a Pro feature. If you connect Gmail, we request read-only access and scan recent mail for purchase confirmations from supported merchants (up to 180 days on Pro). We extract and store only the order details (merchant, order number, items, dates) — never your messages or contacts. The access token is stored server-side and is deleted the moment you click Disconnect on the Import page; you can also revoke access at myaccount.google.com/permissions.
easyReturn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The browser extension
- It runs only on the store and returns-portal sites you grant — never on every site you visit. Host access is requested per portal origin when you click auto-fill (and for easyreturn.us when you save a captured label).
- The order number and email/ZIP you type into the popup are stored locally in your browser (extension storage) for up to 30 minutes, used to fill that store's returns-portal lookup form and to attach a merchant label if you choose Save, then cleared. The optional app-URL setting is kept in extension sync storage.
- It fills forms only when you ask it to, and it never submits a form for you — you review and submit.
- If a merchant portal shows a return label, QR code, or tracking number, the extension may offer to Save to easyReturn. Only when you click that button do we send the label URL, QR image (if small), tracking number, store, and order number to your signed-in account so they appear under My returns. We collect no browsing history and no analytics.
Service providers
We share data only with the processors that make the service work:
- Resend — delivers sign-in and notification emails (receives your email address).
- Shippo and the carrier (e.g. USPS) — when you buy a return label (receive the names, addresses, and package details on the label).
- Stripe — when you pay for postage or a Pro subscription (receives your payment details; we receive confirmation, amount, and payment/subscription ids, not your full card number).
- Google — only if you connect Gmail (OAuth, read-only scope).
- Railway — hosts the app and its storage in the United States.
Retention and deletion
Returns and imported orders stay under your account until you remove them. To delete your account and everything stored with it, email support@easyReturn.us from the address you signed in with — we delete within 30 days. Disconnecting Gmail deletes the stored token immediately.
Security
Sign-in links are single-use and expire in 15 minutes, sessions use signed (HMAC) cookies, and there are no passwords to breach. All traffic is encrypted in transit (HTTPS).
Children
easyReturn is not directed at children under 13, and we do not knowingly collect their data.
Your rights
Wherever you live, we honor requests to access, correct, export, or delete your data — email us and we will do it.
Changes
If this policy changes materially, we will update this page and its date. Continued use after a change means you accept it.
Contact
Use the support form or email support@easyreturn.us.