DATA / PRIVACY REQUEST

Use the request path that matches your relationship to the store.

Privacy requests are easier to handle when they are routed through the Shopify merchant or authenticated shop that controls the underlying store relationship. This page explains the supported paths without asking you to send account secrets.

Operator AI Ecommerce SolutionsLast updated August 29, 2026
Protect your credentials

Do not send Shopify passwords, access or refresh tokens, API secrets, payment-card numbers, or unrelated identity documents through a support or privacy request.

REQUEST PATHS

Who are you making the request about?

The correct route depends on who controls the Shopify store relationship and what information the request concerns.

01

Shopper or store customer

If your request concerns an order, purchase, customer account, review, or information associated with a particular Shopify store, begin with that merchant. The merchant controls the store relationship and can identify the relevant order/customer context and initiate an applicable Shopify privacy request.

Useful starting pointProvide only the store and order/review context reasonably needed to identify the request.
02

Installed Shopify merchant

For app-held data associated with your shop, use the authenticated Privacy Requests area in Sold Countly & Reviews when a Shopify customer-data request is delivered to your store. For related questions or assistance, use the authenticated Help & Support conversation.

See Help & Support →
03

General privacy enquiry

For a general question about Sold Countly & Reviews that is not tied to an installed shop, use the support channel displayed on the app's Shopify App Store listing. Do not send another merchant's private store data or credentials.

OperatorAI Ecommerce Solutions

REQUEST TYPES

A privacy request can involve different actions.

Availability of a particular action depends on the information involved, the requester, applicable law, Shopify requirements, and any lawful retention obligation.

Access

Request information about personal data relating to you where an applicable request path exists.

Correction

Ask about correcting information that is inaccurate where correction is appropriate and supported.

Deletion / redaction

Ask whether matching personal information can be deleted or redacted, subject to Shopify timing and lawful retention requirements.

Restriction or other handling

Depending on applicable law and context, a request can involve restricting or otherwise changing how certain information is handled.

PREPARE THE REQUEST

Provide enough context to locate the issue without oversharing.

Identity or authority checks can be needed before information is disclosed, changed, or deleted.

01
Your relationship

State whether you are the store merchant, a customer/shopper, or an authorized representative.

02
Relevant store context

Include the Shopify store/domain or merchant name when known so the request can be scoped correctly.

03
Relevant transaction or review context

If applicable, provide the order/review context needed to locate the record. Avoid unrelated personal information.

04
What you are asking for

Describe the data or privacy action you want considered, such as access, correction, deletion/redaction, or another applicable request.

IDENTITY & AUTHORITY

Some requests need verification before action can be taken.

To reduce the risk of disclosing or changing data for the wrong person or store, AI Ecommerce Solutions or the relevant Shopify merchant can need reasonable information to verify identity, store authority, or representative authority.

Do not send account secrets.
  • No Shopify password.
  • No access or refresh token.
  • No API secret.
  • No payment-card number.
  • No unrelated identity document.

SHOPIFY PRIVACY EVENTS

Sold Countly & Reviews includes Shopify privacy-request handling.

The app's privacy workflow is scoped to the authenticated Shopify shop and the identifiers supplied through Shopify's privacy-event process.

SHOPIFY PRIVACY TOPICS Supported topic types: customers/data_request, customers/redact, and shop/redact.

For a customer data request, the app records minimized request metadata and provides an authenticated merchant workflow for a shop-scoped export. Customer and shop redaction requests are designed to remove or redact matching app-held customer-linked or shop-scoped data, subject to lawful retention requirements.

Read the Privacy Policy →

WHAT HAPPENS NEXT

The response depends on the request and records involved.

Applicable response timing can vary based on the request route, Shopify requirements, identity/authority verification, and applicable law.

Scope

Identify the relevant shop, person, feature, and records covered by the request.

Verify

Confirm identity or authority where reasonably needed before disclosing or changing information.

Review

Determine the supported action based on the request, Shopify workflow, current app records, and lawful retention needs.

Respond

Provide or complete the applicable action through the verified merchant or Shopify request channel.

DELETION IS CONTEXT-SPECIFIC

A deletion request does not mean every record can be removed in the same way or at the same time.

Some information can be eligible for deletion or redaction, while other records can require retention for legal, billing, fraud-prevention, dispute, audit, or service-integrity reasons. Where retention is required, minimization, restriction, or redaction can be used where appropriate.

Review Privacy Policy

PRIVACY REQUEST GUIDANCE

Start with the merchant or authenticated Shopify shop whenever the request is store-specific.

This keeps customer and merchant information scoped to the correct Shopify relationship and reduces unnecessary disclosure.