Trust

How we look after your data.

How Returns and AMED handle your data. Questions go to [email protected].

Each company’s data is kept apart

Returns

Every return, claim and setting belongs to one store. The data layer refuses any query that doesn’t name the store, so a mistake fails instead of showing another store’s data.

AMED

Each workspace is kept apart by row-level security in the database, and AMED refuses to start with a database role that could bypass it.

Credentials are encrypted

Returns

Shopify and carrier API credentials are encrypted with AES-256-GCM before they’re stored.

AMED

Connection tokens are kept in an encrypted vault (AES-256-GCM) and are never passed to the AI model.

AMED only reads

AMED

  • AMED only reads your ad, sales and stock systems. It can’t change campaigns, orders, stock or bookings.
  • The one place outside AMED it writes is Google Sheets it created, in your connected Google account. Google itself limits it to those sheets, and it can overwrite data in them, for example on each refresh.
  • Meta: AMED asks for read access only, and Meta enforces it.
  • Shopify: AMED asks for read access and refuses any change request before it’s sent.
  • Google Ads: Google’s permission covers reading and writing, so AMED enforces read-only in its own code. For a second lock, connect with a Google Ads user that has the Read-only role.
  • A broken connection gives an error, never made-up numbers.

You choose what AMED sees

AMED

  • An owner or admin connects each source and ticks the Google Ads and Meta ad accounts AMED may read. The AI model never sees the others. Ad data read through Triple Whale follows your Triple Whale shop.
  • Roles: owners, admins and members.

Safe payouts in Returns

Returns

  • Before every automatic refund, gift card or exchange, the portal reads the live Shopify order. It stops and flags the return if the order was cancelled, has an open chargeback, or the item was already refunded.
  • An item can’t be returned or claimed more times than it was bought.
  • With auto-approve off, nothing pays out until your team approves.

Data processing agreement

Our data processing agreement (GDPR Article 28) is available on request: [email protected].

Sub-processors

The full list of providers that process personal data for us, with what they do and where, is available on request: [email protected].