This article helps you understand what to review before approving app
permissions, enabling integrations, and sharing store or order data.
What this helps you do
Understand the categories of Shopify access the app requests, why the app uses
store and order information, which optional features share data, and how to ask
privacy or security questions.
Prerequisites
Access to the app install screen or app in Shopify admin
Instructions
Before installing or reconnecting the app, review Shopify's permission
screen. It is the authoritative list of access requested from your store.Approve the app only if the requested access is acceptable for your store.
Depending on the released app version and enabled features, access can cover:orders and customer-account order experiences
products, inventory, and locations
theme and storefront integration
cart transforms and cart or checkout validation
The app uses this access to configure and enforce delivery or pickup rules,
show the picker, associate selections with Shopify orders, and support the
features you enable. It is not a payment processor and you should not enter
payment-card data in app fields.In the app, review which settings affect:
locations
schedules
delivery and pickup availability
product restrictions
If your team edits themes, limit theme changes to approved staff.
Delivery and pickup choices are written to Shopify cart or order attributes.
The app also stores scheduling metadata associated with the Shopify order,
such as the delivery method, date, time, location or profile, postal/country
information, comments, order totals, tags, and rescheduling history when the
applicable feature uses them.Review optional integrations separately. Calendar feeds, direct Google
Calendar sync, EasyRoutes, CSV export, Shopify Flow, merchant webhooks, and
API features can process or transmit order information according to the
options you enable. Contact sharing is optional where that integration
provides a contact-sharing control.Treat private calendar-feed URLs, API credentials, webhook signing secrets,
and integration credentials like passwords. Revoke or rotate them if they
are exposed.Save a record of who changes delivery settings or enables integrations in
your team process.Avoid sharing full admin access when a staff role with limited permissions
would be enough.
Optional destinations and merchant responsibilities
When you enable an export or integration, the destination can receive copies of
order or schedule information. Access and retention at that destination are
controlled by the merchant and the destination provider after delivery.
CSV files are downloaded to the device or system you choose.
Calendar providers can retain synchronized events or subscribed feed data.
EasyRoutes can receive delivery-stop and order information required for route
operations.Shopify Flow stores workflow activity within Shopify.
Merchant webhook receivers and API clients are systems you authorize and
operate.
Disable an integration when it is no longer needed, remove downloaded exports
according to your own retention policy, and review each provider's privacy and
security terms.
Privacy and data requests
For a customer-data access, deletion, or shop-deletion request, use Shopify's
established privacy-request process and contact RP support with the store domain,
request type, Shopify request/reference ID, and request date. Do not email the
customer's complete order record, address, credentials, or other unnecessary
personal data. Support will verify the store and coordinate the request response.
Expected result
You understand the basic permission and data-handling points relevant to daily use of the app.
Troubleshooting notes
If you are not sure why a permission is needed, ask support before approving it.
If you use a third-party developer, confirm they will not make untracked theme changes on the live theme.
Important warnings or limitations
Warning: Theme changes and delivery-rule changes can affect customer orders immediately on a live store.
Do not place passwords, payment-card information, secrets, or unnecessary
sensitive personal data in delivery comments or integration settings.Uninstalling the app, disconnecting an integration, or receiving a Shopify
privacy-request acknowledgement must not be treated as proof that every live,
downstream, log, or backup copy has been erased. Contact support for the
confirmed outcome of a specific request.This help article is operational guidance, not a privacy policy, data
processing agreement, retention schedule, security certification, or legal
advice.Review the standard RosePerl Privacy
Policy. Obtain any current retention,
subprocessor, data-location, data-processing, or security details not stated
there from support before completing a legal or compliance review.
Suggested Articles
When and how to contact support
Contact support if you need clarification on permissions, stored delivery data, or safe theme changes.
Send only:
your store URL
the permission, privacy-request type, or data question
the Shopify request/reference ID and request date, when applicable
sanitized screenshots only when they are needed
the legal, security, or compliance requirement you need clarified
Never send passwords, access tokens, private feed URLs, webhook secrets, API
credentials, payment-card data, or an unredacted customer export to support.
Use:
https://roseperl.com/privacy-policy/
