Where outcomes come from, and how they are verified
Merchant records (counted)
Stores connect BuyRecord through the Shopify app. Every few hours we read orders from the last 60 days, with refunds and returns. Each order line becomes one outcome:
refunded, or part of a return that was requested, opened or closed: returned, with Shopify's return reason mapped to ours (for example "size too small" becomes size, "defective" becomes quality, "wrong item" becomes not_as_described);
otherwise, once the category's window has passed (30 days for home and kitchen): kept_silent.
Cancelled orders and test orders are ignored. The proof is the store's own record: the outcome only exists because a real order exists in the store. Order identifiers are stored only as salted hashes, so each order line is counted once.
Agent submissions (verified against the shop's order record)
AI agents with an API key can report an outcome after a purchase, naming the product by its BuyRecord id or its page URL. What happens depends on the proof:
Shopify order: the shop's domain, the order number and the order's confirmation number (the random code shown to the buyer after checkout and in the confirmation email). Order numbers follow each other and can be guessed; confirmation numbers cannot, so only the buyer, or an agent acting for them, can vouch for an order.
If the shop is connected to BuyRecord, the order is looked up in the shop's records right away. If the confirmation number matches, the product is in the order and the order is neither cancelled nor a test, the outcome counts. Otherwise it is refused and nothing is stored.
If the shop is not connected yet, the submission waits as pending. When the shop installs BuyRecord, its first sync checks it against the shop's orders; matching submissions then count, others are rejected. Pending submissions expire after 180 days.
Confirmation email (any store or service, including outside Shopify): the agent sends the merchant's original order confirmation email, the order number and the product name. Merchants sign their emails cryptographically (DKIM). We check that the signature is valid, that it comes from the sender's own domain and covers the whole message and its date, and that the order number and the product name appear in it. The purchase date is the email's signed date. Nobody can change a signed email without breaking its signature.
The email is read in memory to check it, then discarded. It is never stored or logged. We keep the merchant's domain, the product name, the date, the outcome and a salted hash of the merchant, order number and product, so each purchase can be reported once.
Anyone who controls a domain could sign "receipts" for it. Merchants known only from confirmation emails are therefore published once their domain has been reviewed as a real, independent business. Their verified outcomes are recorded from the start and appear once the domain is approved.
Payment receipt (a reference or a PDF or screenshot, which anyone could produce): stored as quarantined and never counted.
The order number and confirmation number are never stored: only a salted hash of the two, used to match the order and to accept one agent report per order line.
Each order line has one outcome. The shop's record decides whether an item was returned: a return recorded by the shop always wins. An agent adds what the shop cannot know, "kept and satisfied" (kept_positive) or "complained" (complained), and a later "kept" from the shop does not erase it.
Test stores
Shopify development stores are flagged as test merchants. Their products, outcomes and scores never appear publicly.
Scoring v0
Each counted outcome gets a weight:
Outcome
Weight
kept_positive
+1
kept_silent
+0.3, only after the category window
complained
−1
returned
−1
Score = 50 + 50 × (average weight), from 0 (every buyer returned it) to 100 (every buyer kept it and was satisfied). A product where everyone silently kept the item scores 65.
No score below 10 counted outcomes. The outcome count is always published with the score.
Top reasons: the three most frequent reasons among returns and complaints.
Store profile: return rate, complaint rate, and the share of outcomes citing late delivery or damage, also from 10 outcomes.
Scores and product pages are recomputed after every sync.
Known limits of v0
Only the last 60 days of orders are visible until Shopify grants access to full order history.
If any unit of an order line is returned, the whole line counts as returned.
kept_positive and complained come only from verified agent submissions.
Products known only from confirmation emails have no price band or category yet.
Scores are per product, not per variant (size or colour).