Trust

Privacy

Mano helps Shopify merchants triage returns. We collect the minimum personal data needed to do that and we keep it only as long as needed. This page describes exactly what, why, and for how long — in the same level of detail we'd want from a tool we were buying.

Last reviewed: 2026-06-25.

1. Who we are

Mano is operated by Mano Technologies Limited (UK company registration in progress). We're a software-as-a-service product that connects to a merchant's Shopify store and helps the merchant decide which returns to approve, deny, or investigate. We're currently a small team operating from the United Kingdom with infrastructure in the United States; see section 9 for the residency detail.

Contact for privacy questions: security@mano.help. We answer within 24 business hours.

2. Our role: processor on the merchant's behalf

For data about a merchant's end-customers (the people who bought from the merchant's Shopify store), the merchant is the data controller and Mano is the data processor. The merchant decides what data to share with Mano (by connecting their Shopify store) and the purpose of the processing (returns triage). Mano processes that data only as instructed by the merchant and only for that purpose.

For data about the merchant themselves (the merchant's account email, their Shopify store domain, their subscription metadata), Mano acts as the data controller.

A working-draft Data Processing Agreement (DPA) is available on request — email security@ and we'll send it back the same business day. The standard published DPA is on the Stage 2 roadmap; the working draft is load-bearing today.

3. What personal data we collect, why, and our legal basis

We collect the minimum needed to provide the service. The table below names every category, the source, the purpose, and the legal basis under UK GDPR / EU GDPR.

  • Merchant account data— email (from Clerk auth), Shopify store domain, encrypted Shopify OAuth access token. Source: the merchant themselves at sign-up + OAuth install. Purpose: authenticate the merchant, connect to their Shopify store. Legal basis: performance of contract (the Mano-merchant terms).
  • End-customer profile data— name, email, phone, default shipping address (hashed for duplicate-detection), Shopify customer ID, count of orders, total amount spent. Source: the merchant's connected Shopify store via the Admin GraphQL API, OR a CSV the merchant uploads. Purpose: identify the end-customer and compute risk signals across that customer's return history with the merchant. Legal basis (Mano-as-processor): the merchant's legitimate interest in fraud prevention + their contractual relationship with the end-customer.
  • Order + return + refund data— order numbers, line items, dates, financial / fulfilment status, refund records. Source: Shopify Admin GraphQL or CSV upload. Purpose: feed the rules engine that scores returns. Legal basis: same as above.
  • Decision audit data— every action a merchant takes from the Inbox (approve, deny, block, refund, etc.) is recorded with the actor, the decision, the timestamp, and the recommendation Mano had made. Source: the merchant's own actions in the Mano dashboard. Purpose: provide a tamper-evident audit trail; support undo + reversal flows. Legal basis: merchant's legitimate interest in operational accountability.
  • Billing data— Stripe customer ID and subscription metadata only. Mano never sees or stores payment card details. Source: Stripe Checkout + webhooks. Purpose: provision and bill the subscription. Legal basis: performance of contract.
  • Operational logs— webhook payloads, sync run statuses, error traces. Source: the running application. Purpose: troubleshoot failures + detect anomalies. Legal basis: legitimate interest in service reliability. May contain end-customer personal data; see section 5 for the retention treatment.

Things we explicitly do notcollect: payment card numbers, social-security-equivalents, health data, biometric data, government IDs, location data outside the order's shipping address, or any data not sourced from the merchant's connected Shopify store or their CSV uploads.

4. Purpose limitation

We use personal data only for the purposes named in section 3. We do not:

  • Sell personal data to anyone, ever.
  • Share personal data with third parties for marketing, advertising, or analytics outside the subprocessors named in section 7.
  • Use end-customer personal data to train machine learning models for unrelated purposes (we have no ML training pipeline today).
  • Send marketing emails to end-customers. The only emails Mano can send to end-customers are returns-related transactional messages, gated on the merchant explicitly triggering them — and that feature is dormant today (no live trigger fires).

5. Retention periods

We keep personal data only as long as needed for the purpose, and we delete it on a defined schedule once that purpose ends.

  • While the Shopify integration is active: end-customer profile data, order data, return data, and decision audit data are retained for as long as the merchant has Mano installed. The merchant can request deletion of a specific end-customer's data at any time via Shopify's customers/data_request / customers/redact flow, which Mano honours end-to-end (see section 6).
  • On merchant uninstall: 48 hours after the merchant uninstalls Mano from their Shopify store, Shopify fires shop/redact. Within 30 days of that webhook (typically minutes) Mano cascade-deletes all of that merchant's personal data — end-customer rows, orders, returns, decisions, and the merchant record itself. The merchant's account email (held by Clerk) is severed from any merchant reference and retired according to Clerk's account lifecycle.
  • End-customer redaction request: on receipt of customers/redactfrom Shopify (which fires when an end-customer exercises GDPR erasure), Mano deletes that customer's row plus every cascading record (fraud flags, returns, return items, merchant actions, decision audit rows, inbox dismissals, approval requests, Shopify tag operations) in a single database transaction. The deletion is recorded in a separate DeletionAuditLog table that has no foreign key to Merchant, so the audit record outlives a shop redact.
  • Operational logs: webhook event payloads + sync run records are retained for up to 90 days and then pruned. (Self-imposed limit; the implementation of the prune job is on the Stage 2 roadmap. Until it ships, payloads that hold personal data are subject to the same redact-on-request flow as end-customer rows. Honest disclosure: extending the redact path to the webhook-event store is an active workstream and is tracked publicly in our backlog.)
  • Billing data: kept for as long as the financial relationship requires (typically 6 years after the last subscription event, in line with UK HMRC and EU statutory record-keeping obligations). This data does not include end-customer information.
  • Decision audit data after shop redact: the DeletionAuditLogrow that records that we deleted a merchant's data is kept indefinitely so we can prove the deletion was performed. It contains no personal data — only timestamps, the deletion reason, and the deleted merchant's identifier (no contact data).

6. Your rights

Under UK GDPR + EU GDPR + similar privacy laws, end- customers + merchants have the following rights over personal data Mano processes about them:

  • Access— you can request a copy of the personal data we hold about you.
  • Rectification— you can request that we correct inaccurate or incomplete data.
  • Erasure— you can request that we delete your data. For end-customers, exercise this through the Shopify merchant whose store you ordered from; Shopify will fire customers/redact and Mano will honour it automatically. For direct contact, see below.
  • Restriction of processing— you can ask us to limit how we use your data.
  • Objection— you can object to processing carried out under our legitimate-interest basis.
  • Data portability— you can request a machine-readable export of data you provided to us.
  • Lodge a complaint— with the UK Information Commissioner's Office (ICO) or the supervisory authority in your EU member state.

How to exercise: for end-customers, contact the merchant you ordered from + ask them to initiate the request through Shopify. The webhook handoff is automatic. For merchants or anyone wanting to contact Mano directly, email security@mano.help with the subject “Data subject request”. We'll acknowledge within 24 business hours and fulfil within 30 days, in line with GDPR Article 12. No fee for the first request in a 12-month window.

Mano surfaces risk signals + recommendations to merchants; the merchant makes every decision themselves via the Inbox interface, and by default no action executes without a human pressing it. A merchant may additionally switch on a narrow automation: refunds at or under a value ceiling the merchant sets and consents to explicitly, and only where the return passes the merchant's policy and the customer carries no open risk signal. Every such execution is recorded with the conditions it passed, the merchant can switch it off at any time, and anything outside those bounds always falls back to human review. Automated processing never produces a decision ADVERSE to an end-customer without a human: automation can only carry out a refund the merchant's own settings already sanctioned.

7. Subprocessors

Mano relies on the following third parties to provide the service. Each is bound by a Data Processing Agreement with us + processes personal data only on our documented instructions.

  • Neon(Postgres database hosting, AWS us-east-1). Stores merchant + end-customer data at rest. Encryption at rest enabled by platform default; encrypted backups via Neon's continuous backup + point-in-time recovery.
  • Vercel (application hosting). Runs the Mano application; receives and processes HTTPS traffic. No long-term storage of personal data on Vercel itself.
  • Clerk(authentication). Handles merchant account sign-in, MFA, session management. Stores the merchant's email + any auth identifiers they choose to enrol.
  • Stripe(billing). Stores the merchant's payment instrument + handles all subscription payments. Mano never sees or stores card numbers.
  • Resend (transactional email). Used to send merchant digest emails + operational notifications. The end-customer email path is not live today; if and when it activates, end-customer email addresses will be shared with Resend solely for the transactional message the merchant explicitly triggers.
  • Shopify (data source). Mano receives merchant + end-customer data from Shopify via OAuth and webhooks. Shopify is the upstream source of the end-customer data Mano processes.

We'll update this list when we change subprocessors and email merchants 30 days in advance of any material change (e.g., adding a new subprocessor with access to end-customer personal data).

8. Security

The technical and organisational measures Mano uses to protect personal data are described in detail on our Security page. Highlights:

  • Shopify OAuth tokens are encrypted at rest with AES-256-GCM.
  • HTTPS-only transport everywhere.
  • Multi-tenant scope: every database query is scoped by merchantId as a precondition; cross-tenant reads are not possible through the application layer.
  • Incoming Shopify webhooks (including GDPR compliance topics) are HMAC-verified with timing-safe comparison.
  • Stripe webhook signatures verified via stripe.webhooks.constructEvent.
  • Strong-password + MFA available for merchant accounts via Clerk.
  • Incident response: see /security §8 for the disclosure policy + commitments.

What we don't have yet is also on the Security page (section 7). We'd rather you know where the edges are.

9. International transfers

Mano is operated from the United Kingdom; primary infrastructure is in the United States (AWS us-east-1, via Neon + Vercel). Transfers from the UK + EU to the US are covered by the EU-US Data Privacy Framework + the UK Extension where applicable, or by Standard Contractual Clauses (SCCs) where not. UK/EU-resident infrastructure is on the Stage 2 roadmap and is not available today; if EU/UK residency is a procurement-blocking requirement, please raise it before connecting your store.

10. Children

Mano is a B2B service used by Shopify merchants. It is not directed at children and we do not knowingly collect data from anyone under 16. End-customer data Mano processes is whatever the merchant's Shopify store has on file; if a merchant's store collects data from children, that's the merchant's collection + the merchant's legal responsibility, not Mano's.

11. What's still in progress

The honest section. These are the things we know we need and are working on:

  • Standard published DPA— today the DPA is a working draft available on request. We expect to publish the standard form in Stage 2.
  • Webhook-payload redact-coverage— the GDPR redact handlers cascade-delete Customer+ every dependent row, but a small number of operational records hold incoming Shopify webhook payloads that may contain end-customer data. Extending the redact path to clear those records is an active workstream + is tracked publicly in our backlog (search for “WebhookEvent redact”). For redact requests in the interim, we fulfil the deletion against those records manually within the 30-day window.
  • Self-serve data export— end-customer access requests are fulfilled manually today; a self-serve export endpoint is queued.
  • EU/UK data residency— on the Stage 2 roadmap.
  • SOC 2 / ISO 27001 / third-party pen test— scheduled to begin at 5+ paying merchants. See /security §7.

12. Changes to this policy

Material changes are emailed to merchants at least 30 days before they take effect. The “Last reviewed” date at the top of this page is updated on every change. For material changes affecting end-customer data processing, we'll update + we expect the merchant to relay relevant detail to their own end-customers in line with their own privacy policy.

13. Contact

Privacy questions, DPA requests, data-subject requests, complaints: security@mano.help.

For supervisory authority complaints in the UK, see the Information Commissioner's Office at ico.org.uk. For EU member states, contact your national data protection authority.