Last updated: July 5, 2026
This page lists the third-party Sub-Processors that Friros AB (org. nr 559100-9047), operator of Returner, engages to process personal data on behalf of merchants. It is maintained in sync with our Privacy Policy and our internal Record of Processing Activities (GDPR Art. 30). Merchants who require advance notice of changes to this list may subscribe by contacting [email protected].
Some Sub-Processors are engaged only when a related feature is enabled (for example, customer payment processing, AI-assisted features, or analytics) or when selected by the merchant (for example, a shipping carrier). Primary application data (database and object storage) is hosted in the EU. US-based Sub-Processors are engaged under Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
| Sub-Processor | Purpose | Data categories | Location |
|---|---|---|---|
| Shopify Inc. | E-commerce platform; order and return data source | Order and customer data | Canada / USA |
| DigitalOcean LLC | Cloud infrastructure, database, and object storage (labels/photos) | All application data | EU (Amsterdam, Netherlands) |
| Resend, Inc. | Transactional email (return notifications, verification codes) | Email, name, return status | USA |
| Sub-Processor | Purpose | Data categories | Location |
|---|---|---|---|
| Revolut Ltd | Merchant subscription billing (off-platform tenants) | Merchant billing identifiers | United Kingdom |
| Stripe, Inc. | Customer top-up payments on uneven exchanges (opt-in, merchant's own account) | Payment data, email | USA / EU |
| Sub-Processor | Purpose | Data categories | Location |
|---|---|---|---|
| Anthropic, PBC | AI-assisted merchant support and analytics. Off by default; only the data needed to fulfil a given request is sent, under Anthropic's commercial (no-training) terms. See our AI Policy. | Customer name/email (support queries only); aggregate metrics otherwise | USA |
| Sub-Processor | Purpose | Data categories | Location |
|---|---|---|---|
| PostHog, Inc. | Cookieless product-usage analytics (where enabled) | Pseudonymous id, event metadata | USA / EU |
| Plausible Analytics OÜ | Cookieless web analytics (aggregate, no PII) | Aggregate traffic data | EU (Estonia) |
| Google Ireland Ltd | Google Analytics 4 / Ads; loads only after Analytics/Marketing consent | Pseudonymous usage/event data, approximate location | EU / USA (consent-gated) |
| LinkedIn Ireland UC | LinkedIn Insight tag; loads only after Marketing consent (marketing site only) | Pseudonymous conversion data | EU / USA (consent-gated) |
| Functional Software, Inc. (Sentry) | Error monitoring | PII-scrubbed stack traces | USA |
When a merchant configures a carrier, return shipment name and address are shared with that carrier to generate labels and tracking. Carriers include PostNord, UPS, FedEx, DHL, Bring, Sendcloud, Shippo, and Cirro, depending on the merchant's configuration.