Use the request path that matches your relationship to the store.
Privacy requests are easier to handle when they are routed through the Shopify merchant or authenticated shop that controls the underlying store relationship. This page explains the supported paths without asking you to send account secrets.
Operator AI Ecommerce SolutionsLast updated August 29, 2026
Protect your credentials
Do not send Shopify passwords, access or refresh tokens, API secrets, payment-card numbers, or unrelated identity documents through a support or privacy request.
REQUEST PATHS
Who are you making the request about?
The correct route depends on who controls the Shopify store relationship and what information the request concerns.
01
Shopper or store customer
If your request concerns an order, purchase, customer account, review, or information associated with a particular Shopify store, begin with that merchant. The merchant controls the store relationship and can identify the relevant order/customer context and initiate an applicable Shopify privacy request.
Useful starting pointProvide only the store and order/review context reasonably needed to identify the request.
02
Installed Shopify merchant
For app-held data associated with your shop, use the authenticated Privacy Requests area in Sold Countly & Reviews when a Shopify customer-data request is delivered to your store. For related questions or assistance, use the authenticated Help & Support conversation.
For a general question about Sold Countly & Reviews that is not tied to an installed shop, use the support channel displayed on the app's Shopify App Store listing. Do not send another merchant's private store data or credentials.
OperatorAI Ecommerce Solutions
REQUEST TYPES
A privacy request can involve different actions.
Availability of a particular action depends on the information involved, the requester, applicable law, Shopify requirements, and any lawful retention obligation.
↗
Access
Request information about personal data relating to you where an applicable request path exists.
✎
Correction
Ask about correcting information that is inaccurate where correction is appropriate and supported.
×
Deletion / redaction
Ask whether matching personal information can be deleted or redacted, subject to Shopify timing and lawful retention requirements.
◌
Restriction or other handling
Depending on applicable law and context, a request can involve restricting or otherwise changing how certain information is handled.
PREPARE THE REQUEST
Provide enough context to locate the issue without oversharing.
Identity or authority checks can be needed before information is disclosed, changed, or deleted.
01
Your relationship
State whether you are the store merchant, a customer/shopper, or an authorized representative.
02
Relevant store context
Include the Shopify store/domain or merchant name when known so the request can be scoped correctly.
03
Relevant transaction or review context
If applicable, provide the order/review context needed to locate the record. Avoid unrelated personal information.
04
What you are asking for
Describe the data or privacy action you want considered, such as access, correction, deletion/redaction, or another applicable request.
IDENTITY & AUTHORITY
Some requests need verification before action can be taken.
To reduce the risk of disclosing or changing data for the wrong person or store, AI Ecommerce Solutions or the relevant Shopify merchant can need reasonable information to verify identity, store authority, or representative authority.
Do not send account secrets.
No Shopify password.
No access or refresh token.
No API secret.
No payment-card number.
No unrelated identity document.
SHOPIFY PRIVACY EVENTS
Sold Countly & Reviews includes Shopify privacy-request handling.
The app's privacy workflow is scoped to the authenticated Shopify shop and the identifiers supplied through Shopify's privacy-event process.
SHOPIFY PRIVACY TOPICSSupported topic types: customers/data_request, customers/redact, and shop/redact.
For a customer data request, the app records minimized request metadata and provides an authenticated merchant workflow for a shop-scoped export. Customer and shop redaction requests are designed to remove or redact matching app-held customer-linked or shop-scoped data, subject to lawful retention requirements.
The response depends on the request and records involved.
Applicable response timing can vary based on the request route, Shopify requirements, identity/authority verification, and applicable law.
Scope
Identify the relevant shop, person, feature, and records covered by the request.
Verify
Confirm identity or authority where reasonably needed before disclosing or changing information.
Review
Determine the supported action based on the request, Shopify workflow, current app records, and lawful retention needs.
Respond
Provide or complete the applicable action through the verified merchant or Shopify request channel.
DELETION IS CONTEXT-SPECIFIC
A deletion request does not mean every record can be removed in the same way or at the same time.
Some information can be eligible for deletion or redaction, while other records can require retention for legal, billing, fraud-prevention, dispute, audit, or service-integrity reasons. Where retention is required, minimization, restriction, or redaction can be used where appropriate.