Skip to main content
Refund orchestration

Resolve refunds with policy, not guesswork.

Lumtry automates refund decisions with deterministic policy and AI reasoning, routing the edge cases to your team for approval.

The Lumtry overview dashboard: today's KPI row, cases over time, and the action center with pending refund approvals.

Connects to the tools you already run

How a refund gets decided

Every case moves through the same five stages in order, with a compensation path back out if execution fails partway through.

Most cases: cleared by policy, no waitingGray areas: AI weighs the case; clear ones proceed, close calls go to a personIf execution fails: compensation walks it back

Intake

A Shopify order or refund-request signal arrives as a verified webhook.

Policy engine

Deterministic rules evaluate the case against the org's policy version, pinned for the life of the run.

deterministic

AI reasoning

Model-assisted reasoning weighs ambiguous cases and writes a rationale. Cases it can clear within policy proceed; close calls route to a person.

always behind policy

Human approval

The close calls AI cannot clear, and every case when AI is unavailable, wait here for an operator to approve or deny from the dashboard or Slack.

Execution

The approved refund executes through Stripe or PayPal and writes an audit row.

Every case flows from intake through the policy engine. Most cases are cleared by policy and execute immediately. Gray areas route to AI reasoning: cases the AI can clear within the policy proceed straight to execution, while close calls, and every case when AI is unavailable, go to a human approver first. If execution fails, a compensation step walks the refund back; nothing is left half-applied.

Automation you can defend to an auditor

Lumtry pairs rules that never drift with reasoning you can inspect, so every refund has a grounded, reviewable decision behind it.

From signal to settled

A durable workflow drives each refund from intake through validation, policy evaluation, approval, and execution, with explicit compensation if a step fails.

Deterministic policy engine

Versioned, immutable rules decide the predictable cases. In-flight refunds pin the policy version they started on.

AI reasoning, scoped

Model-assisted judgment for the gray areas, always behind your policy and surfaced with its rationale.

The Lumtry approvals queue, showing pending refund cases with masked customer names, amounts, and risk flags.

Dashboard and Slack approvals

Every case that needs a human shows its amount, masked customer, and risk flag, cleared from the dashboard or from Slack.

The Lumtry trace timeline for a refund case, moving from validating to policy evaluated to a pending approval request.

Full audit trail

Every decision, signal, and override lands as a timestamped, traceable step from policy evaluation onward.

Return-receipt gating

A refund tied to a return holds until the item is scanned back in, so payouts never race the package.

Usage-metered billing

Plan usage is metered against your entitlements. Work at the limit is held for review, never silently dropped.

See it before you connect anything

1

Create a workspace with sample data

Nothing real moves. Cases, policies, and approvals all run against sample data until you connect a store.

2

Walk the guided tour

Approve a simulated refund end to end: policy evaluation, AI rationale, and the approval decision, in order.

3

Connect Shopify and go live in shadow mode first

New workspaces default to shadow mode. Real orders flow in and get decided end to end, but nothing executes until you switch to live.

The Lumtry overview dashboard with the guided tour's first step callout, walking a new workspace through its first sample refund case.

Built for teams that move money

Security and auditability are the product, not an afterthought. Every decision is grounded, every action is logged, and access is scoped to the tenant.

Tenant isolation, row-level security Append-only audit trail No raw card data, processor tokens only TLS and strict security headers
Tenant data isolated with row-level security and backend re-checks
Processor tokens only. Raw card data is never stored
Webhook signatures verified before any write
Append-only audit and webhook logs
Secrets from a vault, never logged or echoed
TLS at the edge, strict CSP and CORS allowlist

Coming next

These are planned, not yet shipped. Nothing below is live in the product today.

Guided first-run wizard

Will walk a new workspace from demo data through connecting a store, writing a first policy, and going live in shadow mode.

Coming soon

Self-serve purchase

Will add published prices, in-app checkout, and a trial, so a workspace can start without a sales call.

Coming soon

Voice approvals

Will let an approver clear or decline a case by voice when they're away from a screen.

Coming soon

Fraud network signals

Will feed cross-tenant fraud signals into policy and AI reasoning as another input.

Coming soon

ERP integrations

Will connect refund orchestration to the ERP systems finance teams already reconcile against.

Coming soon

Visual policy flow builder

Will let policy authors branch rules visually instead of editing structured rule text.

Coming soon

Frequently asked questions

What happens when I hit my plan limit?

Work at the limit is held for review, not dropped. Usage is metered against your plan's entitlements, and anything over the limit waits for your team instead of failing silently.

Does the AI decide refunds on its own?

No. Policy runs first and resolves the predictable cases deterministically. AI reasoning weighs the gray areas within what policy already allows and writes a visible rationale: cases it can clear proceed, and close calls go to human approval on the dashboard or in Slack. If AI is unavailable, those cases go to a person instead.

What happens if a refund fails partway through?

The workflow that drives a refund from intake to execution has explicit compensation for every step that can fail, so a partial failure doesn't leave a refund half-applied.

Can I try Lumtry without connecting my store?

Yes. A new workspace starts with sample data, so you can walk the guided tour and approve a simulated refund before connecting anything real.

Which payment processors does Lumtry work with?

Stripe and PayPal for refund execution, with orders and refund requests intaken from Shopify.

Put your refund policy on autopilot

Start free, connect your store, and let policy and AI handle the volume while your team handles the exceptions.