G9 Returns · Legal · Privacy Policy← All documents

Privacy Policy — G9 Returns

Version: 1.0 · Effective on publication.

⚠️ Template, not legal advice. This is a starting template grounded in how G9 Returns actually processes data. Have it reviewed by qualified legal counsel before relying on it, and align it with your master Terms of Service, your Data Processing Agreement, and each merchant's own customer-facing privacy notice.

This Privacy Policy explains how G9 AS ("G9", "we", "us") handles personal data in the G9 Returns service ("Service") — a self-service returns and exchange portal that merchants embed in, or link from, their Shopify storefronts. It reflects Regulation (EU) 2016/679 ("GDPR") and the Norwegian Personal Data Act (personopplysningsloven).


1. Who we are and our role

G9 AS provides the G9 Returns Service to retail merchants. When a shopper uses the Service to return or exchange an order, G9 acts as a data processor on behalf of the merchant, who is the data controller of their customers' personal data. The merchant decides why and how their customer data is processed; G9 processes it only to provide the Service, on the merchant's documented instructions, under the Data Processing Agreement (Article 28 GDPR).

This means:

  • If you are a shopper, your primary privacy relationship is with the merchant whose store you bought from. Their own privacy notice governs the overall handling of your data; this policy describes what G9 does on their behalf.
  • If you are a merchant, this policy describes the processing G9 performs for you. (Where G9 processes your staff's account data — e.g. sign-in identity — for our own operational purposes, G9 acts as controller for that limited data.)

Contact: see Section 11.


2. Personal data we process

G9 deliberately minimises the personal data it touches. To provide a return or exchange, we process:

DataWhy it is needed
Order identifiers (order number / order GID)Look up the order the shopper wants to return.
Shopper email addressVerify that the person requesting the return owns the order.
Shipping postcode / addressVerify order ownership and generate the Posten/Bring return label.
Item and return details (products, quantities, reason, condition notes, any photo evidence the policy requires)Apply the merchant's return policy and process the refund/exchange.
Pseudonymised customer reference (Shopify customer GID or a salted hash)Persist a return without storing raw customer identifiers.

We do not intentionally process special categories of personal data (e.g. health, biometrics). Please do not include such data in free-text fields or photos.

Pseudonymisation and PII minimisation. Personal data used to identify a shopper is pseudonymised: we store a Shopify customer GID or a salted hash rather than raw customer identifiers. Before any data is sent to our AI assessment step, personally identifying fields are masked or pseudonymised — the AI receives the minimum needed to assess the return. Our append-only audit/event log stores no raw PII.


3. Why we process it, and our legal basis

G9 processes the data above to carry out the return or exchange that the shopper has requested. The legal basis depends on the relationship:

  • Performance of a contract / a service the shopper requested (Art. 6(1)(b)) — looking up the order, verifying ownership, generating the return label, and processing the refund/exchange are necessary to deliver the return the shopper initiated.
  • Legitimate interests (Art. 6(1)(f)) — of the merchant and G9 in operating a secure, fraud-resistant returns process (e.g. verifying order ownership, preventing abuse, maintaining an audit trail). Where required, the merchant is responsible for the underlying lawful basis as controller.
  • Legal obligation (Art. 6(1)(c)) — where retention or processing is required by law (e.g. accounting/consumer-protection rules).

The merchant, as controller, determines and is responsible for the lawful basis applicable to its customers; G9 supports the merchant in meeting that responsibility.


4. Automated AI assessment — drafts only, human-approved

G9 Returns uses a chain of AI agents to read the order, apply the merchant's policy, and assess any required photo evidence, in order to draft a recommendation for each return.

No solely-automated decision with legal or similarly significant effect is made about a shopper. Specifically:

  • Deterministic eligibility (return window, valid reason, category exclusions) is decided by plain code, not by an AI model.
  • AI agent outputs are drafts that require human approval. The AI never auto-rejects a return — it can only flag a case for a human reviewer.
  • A shopper's statutory rights — including the Norwegian right of withdrawal (angrerett) — cannot be overridden by an AI assessment or by store policy.
  • Inputs to the AI are PII-minimised (see Section 2).

Because a human is always in the loop before any meaningful outcome, this processing does not constitute a solely-automated decision under Article 22 GDPR. Where a merchant configures the Service differently, the merchant remains responsible as controller.

This processing is documented in more detail in our Data Protection Impact Assessment for the agent chain (see DPIA.md), which covers the risk assessment, the design mitigations described above, and the residual risk that remains.


5. Sub-processors

G9 engages the sub-processors listed in Annex III of the DPA to deliver the Service. At the date of this version they are:

Sub-processorPurposeRegion
VercelApplication hostingEU/US
NeonPostgres databaseEU (eu-central)
ClerkStaff authenticationUS
InngestBackground jobs / webhooksUS
AnthropicAI return assessment (PII-minimised input)US
ShopifyCommerce platform (order / refund / returns APIs)Global
Posten/BringCarrier (return label / QR)EU/Norway

The application database (Neon Postgres) is hosted in the EU (eu-central). We will inform merchants of intended additions or replacements to this list and give a reasonable period to object, as set out in the DPA. Each sub-processor is bound by equivalent data-protection obligations.


6. International transfers

Where personal data is transferred outside the EEA (for example to a US-based sub-processor listed above), G9 relies on an appropriate transfer mechanism for each sub-processor, such as the EU Standard Contractual Clauses or self-certification to the EU-U.S. Data Privacy Framework, together with supplementary measures where needed. We prioritise EEA/Norway data residency where available; the primary application database is hosted in the EU. The confirmed mechanism for each sub-processor (and any still being verified) is tracked in Annex III of the DPA, which is the authoritative record.


7. Retention

We keep personal data only as long as needed to provide the Service, then delete it — unless retention is required by law (e.g. accounting/consumer-protection rules). Personal data is deleted:

  • on a valid erasure request routed via Shopify's customers/redact flow, or
  • at the end of the Service for a merchant,

with a target of deletion within 30 days. Full detail is in Annex II — Retention of the Data Processing Agreement, which is the authoritative retention statement for the Service. (A standalone retention schedule may be published at ./RETENTION-POLICY.md; until then, Annex II of the DPA governs.)


8. Data-subject rights

Shoppers have the rights granted by the GDPR, including access, rectification, erasure, restriction, objection, and data portability. Because G9 is a processor, these rights are exercised through the merchant (the controller):

  • Shoppers: contact the merchant whose store you shopped at to exercise your rights. The merchant will instruct G9 where G9 holds relevant data.
  • Merchants: G9 assists you in responding to data-subject requests. The Service implements Shopify's mandatory privacy flows:
  • customers/data_request — surfaces the personal data G9 holds for a given shopper so you can respond to an access request.
  • customers/redact — deletes/erases the shopper's personal data G9 holds.

You may also lodge a complaint with a supervisory authority — in Norway, the Datatilsynet (Norwegian Data Protection Authority).


9. Security

G9 applies the technical and organisational measures in Annex II of the DPA. In summary:

  • Encryption in transit: TLS/HTTPS everywhere; HMAC-verified webhooks and signed app-proxy sessions.
  • Encryption at rest: per-tenant credentials encrypted with AES-256-GCM, with the additional authenticated data (AAD) bound to the tenant; the Neon Postgres database is encrypted at rest, including managed backups.
  • Tenant isolation: three enforcement layers — Postgres Row-Level Security (non-owner role, FORCE RLS), repository-level scoping, and per-agent scope — verified against live Postgres.
  • Data minimisation: only the fields in Section 2 are processed; PII is pseudonymised/masked before AI processing; the append-only audit log stores no raw PII.
  • Access control: staff authenticate via Clerk; admin/provisioning is restricted to a super-admin allowlist; the database uses a least-privilege role.
  • Resilience: managed backups and point-in-time recovery; RLS prevents cross-tenant leakage.

We make no claims of formal certification. Security is maintained through the measures described above and reviewed on an ongoing basis.


10. Changes to this policy

We may update this policy as the Service evolves. Material changes will be communicated to merchants, and the version number above will be incremented. Continued use of the Service after an update constitutes acknowledgement of the revised policy.


11. Contact

For privacy questions about the G9 Returns Service:

  • G9 AS — privacy contact: privacy@g9.no (confirm the monitored address before publishing)
  • Shoppers: please contact the merchant whose store you shopped at first; they are the controller of your data.
Reminder: this is a template. Confirm the contact address, the sub-processor list and their current regions/transfer mechanisms, and align this policy with counsel before publishing.

G9 AS · Norway · Governed by Norwegian law.