Legal
Privacy Policy
Last updated 21 September 2026. UK GDPR and the Data Protection Act 2018.
1. Who we are
RE2 Limited, a company registered in England and Wales (“VerifiedReturn”, “we”, “us”), operates verifiedreturn.com and the capture pages served from our capture host. Contact: [email protected], or the contact form.
This policy covers two audiences. Merchants create workspaces and use the dashboard, API, and billing. Consumers open a capture link a merchant sent them and take photos of an item. The two are treated differently below.
2. Roles
For merchant account, billing, and site-analytics data, VerifiedReturn is the controller.
For consumer capture media and the device signals collected on a capture page, the merchant is the controller and VerifiedReturn is the processor. We process that data on the merchant’s instructions to provide the service. If you are a consumer and want to exercise a data-protection right, start with the merchant who sent you the link. We will help them respond.
3. Data we collect from merchants
- Account identity: name, email, workspace name, membership roles.
- Authentication: hashed password, session cookies, password-reset tokens (Devise).
- Billing and plan: selected plan, usage events, invoice metadata.
- Workspace configuration: branding, API keys, webhook endpoints, share-link settings.
- Support: messages you send via the contact form (name, email, company, store URL, topic, message, IP address, user agent).
Legal bases: contract (to run your workspace), legitimate interests (security, abuse prevention, product improvement), and legal obligation (tax and accounting records).
4. Data we collect from consumers on a capture page
When you open a merchant’s capture link we collect only what the session needs. Capture is of the item, not of you. We do not run facial recognition or biometric identification, and merchants must not ask you to photograph a person as the subject.
Typically a session includes:
- still photographs of the item;
- a short video clip recorded while you move around the item;
- an order, RMA, or other reference you type, or that the merchant pre-filled;
- client and server timestamps;
- a SHA-256 hash and a perceptual hash of each still, used to detect reuse and to keep an integrity trail;
- device signals, stored against the session:
- whether the browser looks automated (webdriver, headless);
- whether a virtual camera is in use;
- whether the device reports as mobile and touch-capable;
- a WebGL renderer string;
- motion energy from the device;
- a capabilities snapshot (what the browser said it could do);
- an optional Cloudflare Turnstile result, if the merchant has bot checks on.
The clip is stored with the session so the merchant can review it. It is not sent to any third party for analysis.
Legal bases, acting as processor: the merchant’s instructions, typically their legitimate interest in assessing a return or damage claim, or steps toward a contract with you. We do not use consumer capture media to train generative image models or to advertise to you.
5. How long we keep it
Capture media is purged on a schedule that follows the merchant’s plan, counted from session completion (or from creation if the session never completed):
- Free — 30 days
- Starter — 90 days
- Unlimited — 365 days
Session metadata, scores, and audit events may remain after media is purged so the merchant has a record that a check occurred. Merchant account and billing records are kept for the life of the workspace and for as long as tax or accounting law requires after closure. Contact-form submissions are kept until we have handled them and then archived or deleted.
6. Who we share data with
We do not sell personal data. We use subprocessors to run the product:
- Amazon S3 — object storage for capture media in production.
- Cloudflare Turnstile — optional bot check on the capture page.
- The application host for the Rails app (currently configured per environment; production is a VPS-style host).
- Redis — job queue and cache for Sidekiq.
We may also disclose data if required by law, or to establish or defend a legal claim. Merchant dashboard users see the sessions in their own workspace. A merchant may send session data to their own webhook endpoints; those endpoints are the merchant’s responsibility.
7. International transfers
Some subprocessors store or process data outside the United Kingdom. Where we transfer personal data internationally we use an appropriate safeguard, such as the UK International Data Transfer Addendum to the EU standard contractual clauses, or a processor in a country covered by UK adequacy regulations.
8. Your rights
Under UK GDPR you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability. You may also withdraw consent where we rely on it.
Consumers should contact the merchant who sent the capture link. Merchants should write to [email protected]. We will respond within one month, or explain if we need longer.
You can complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we handle your data.
9. Cookies
The marketing site and dashboard use a session cookie that is necessary to keep you signed in and to protect forms. The capture page uses cookies or similar storage only as needed to run the session (for example a client secret for that capture). We do not run third-party advertising cookies.
10. Children
VerifiedReturn is aimed at merchants and adult customers completing a return or claim. We do not knowingly collect data from children. If you believe a child has used a capture link, contact us and we will delete the session media.
11. Changes
We may update this policy by posting a new version on this page. Material changes will be noted in the dashboard or by email where we have an address.