Return Goblin — Privacy Policy
Effective date: June 11, 2026 Who we are: Majr Technology Corporation ("Return Goblin", "we", "us", "our") Privacy contact: privacy@majr.app
1. What Return Goblin does
Return Goblin helps you avoid missing Amazon return windows. You send an Amazon
order or shipment email to track@returngoblin.com — by forwarding it yourself,
or with one tap in our Gmail add-on. We read that email, estimate the return
deadline from Amazon's published category return policies, email you a receipt,
and remind you before the window closes. Amazon maintains the official return
date; our estimates are best-effort.
This policy explains what we collect, how we use it, who processes it, and your choices.
2. Information we collect
Information you give us by sending an email to us:
- Your email address — the address you forward from (or that you're signed in to Gmail with when you use the add-on). It's how we send your receipt and reminders.
- The Amazon email you send us, and the order details in it — order ID, product/item title(s), item price(s), ship and delivery dates, product category, and whether the item was sold by Amazon or a third-party seller.
Information the Gmail add-on accesses (only if you install it):
| Permission | What it allows | When |
|---|---|---|
gmail.addons.current.message.readonly |
Read only the message you currently have open (sender, subject, body) | Only while that message is open and the add-on is running |
script.send_mail |
Send email as you | Only when you tap Track this return |
gmail.addons.execute |
Run the add-on's in-Gmail interface | While you use the add-on |
The add-on cannot read, modify, or delete any other message in your mailbox.
It reads a message only when you open it and sends one only when you tap the
button. We do not request broad Gmail access (gmail.readonly, gmail.modify,
or https://mail.google.com/).
Information we generate while operating the service:
- Inbound activity log — the sender address and timestamp of each email sent
to
track@, used to prevent abuse and as an operational audit trail. - Reminder history — which receipts and reminders we sent, when, and the email provider's message ID.
We do not ask for or intentionally collect payment card numbers, government IDs, or special-category data. Please don't send us emails that contain them.
3. What we store, and what we don't
- Our application database (Supabase) stores: your email address; the extracted order details listed above; your reminder history; and single-use action-link tokens, which are stored hashed (SHA-256) so a database read cannot reconstruct a working link.
- We do not store the full raw email body in our application database. The email you send is received and retained by our email provider (Resend) and is processed transiently to extract the order details above. Our database keeps only a reference ID to that message, not its contents.
4. How we use your information
- Parse your email and estimate the return deadline.
- Send you a receipt and reminder emails (including the optional second nudge you can request).
- Operate, secure, debug, and prevent abuse of the service (e.g. rate limiting).
- Comply with law.
We do not sell your information, and we do not use it for advertising or to build advertising profiles.
For users in the EEA/UK, our legal bases are: performance of a service you requested (parsing your email and sending reminders), our legitimate interests (securing the service and preventing abuse), and consent where required.
5. How the email parsing works (AI processing)
To extract the order details, we send the sanitized text of the email you sent to our AI provider, Anthropic (Claude), which returns the structured fields. This content is used solely to provide the reminder feature — to parse the specific email you sent — and is not used to train generalized AI/ML models. Before sending, we strip hidden/invisible control characters and neutralize prompt-injection attempts.
6. Sub-processors
We share data only with service providers that operate Return Goblin on our behalf, under contract:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Anthropic | Parse the email to extract order details | The sanitized email text, transiently |
| Resend | Receive your inbound email; send receipts and reminders | The email you send; your email address; message content |
| Supabase | Application database | Your email address and extracted order details |
| Fly.io | Application hosting | Transient processing of the above |
We may add or change sub-processors as the service evolves; material changes will be reflected here.
7. Google user data and Limited Use
Return Goblin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing return-reminder feature; we do not transfer or sell it; we do not use it for advertising; and we do not use it to train generalized AI/ML models. Humans do not read your Google user data except as needed for security, to comply with law, or with your explicit consent.
8. How we share information
We share information only with the sub-processors in Section 6, and only as needed to run the service. We may also disclose information if required by law or legal process, to protect the rights, safety, or property of Return Goblin or others, or in connection with a merger, acquisition, or asset sale (you'll be notified of any such change that affects this policy). We never sell your data.
9. Data retention and deletion
We keep your information for as long as needed to provide reminders and operate the service, and for a reasonable period afterward for security, audit, and legal purposes. Action-link tokens expire automatically. You can ask us to delete your data at any time by emailing privacy@majr.app; deleting your account removes your shipment records, reminder history, and action tokens. You can also mark items as kept or returned to stop reminders for them.
10. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal information, and to object to certain processing. To exercise any of these, email privacy@majr.app; we will respond as required by applicable law. California residents: we do not sell or "share" (as defined under the CCPA/CPRA) personal information, and you have the right to know, delete, and not be discriminated against for exercising these rights.
You control what we receive: we only process an email when you choose to send it to us, and we only send reminders after you confirm your email address (double opt-in).
11. Security
We take reasonable measures to protect your information, including:
- Encryption in transit (HTTPS/TLS) for our endpoints and provider API calls.
- Database access locked down with row-level security; only our server, using a privileged key, can read these tables (no public/browser access).
- Single-use, expiring action links stored hashed at rest, so a database or backup read cannot replay them.
- Signature verification on inbound email webhooks.
- Double opt-in before any reminders are sent.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. International processing
Your information may be processed in the United States [and other locations where our sub-processors operate]. Where required, we rely on appropriate safeguards for international transfers. [Confirm sub-processor regions and transfer mechanism with counsel.]
13. Children
Return Goblin is not directed to children under [13/16], and we do not knowingly collect their personal information. If you believe a child has used the service, contact us and we will delete the data.
14. Changes to this policy
We may update this policy. Material changes will be reflected by a new effective date at this URL, and where appropriate we'll provide additional notice.
15. Contact
Majr Technology Corporation [MAILING ADDRESS] privacy@majr.app
Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates. Return Goblin is an independent service and is not affiliated with, endorsed by, or sponsored by Amazon.