Shopify app permissions are access scopes — declarations that tell your store exactly which data an app can read or modify when it is installed. When you click "Install" in the Shopify App Store, you are presented with a data access consent screen listing the scopes the app has requested — clicking through grants them.
If you are running a Shopify store in South Africa, understanding those scopes is not optional. POPIA makes you the responsible party for your customers' personal data, including any data you share with third-party apps.
Most merchants click through the install screen without reading it. That works for a well-scoped app with a narrow feature set. It becomes a problem when an image-optimisation tool asks for full customer data export, or when an abandoned app keeps active read access to your order history long after you stopped using it.
This guide explains what each permission category actually exposes, which scopes require Shopify's explicit approval, and how to audit your existing app stack from Settings > Apps — the monitoring dashboard Shopify released in March 2026.
Quick Answer
Shopify app permissions (also called access scopes) define which parts of your store — products, orders, customer records, themes, or payment data — a third-party app is allowed to read or edit. You review and grant them at install time via a consent screen; each scope stays active until you uninstall the app. Since March 2026, Shopify's Settings > Apps dashboard lets you check every app's active scopes, recent API activity, and any permissions that have gone unused for 30 days. For South African merchants, granting customer-data scopes also triggers POPIA obligations — the app developer becomes an "operator" processing personal information on your behalf, and a written data processing agreement should be in place.
Jump to
How the Permission System Works
What Each Permission Grants Access To
Permissions That Require Shopify Approval
Not sure which apps in your stack have over-broad access?
Send us your store URL and we will walk through your installed apps and flag any permission combinations worth reviewing before they become a compliance or security issue.
Get a free app-stack reviewHow the Shopify Permission System Works
Shopify app permissions operate through a structured OAuth system where an app declares the scopes it needs, you approve them on install, and Shopify enforces the boundaries at the API level. An app that was granted read_products can fetch your product catalogue; it cannot modify orders because it was never granted write_orders. The enforcement is platform-side — the app cannot simply request access it was not granted.
Shopify App Store permissions follow a consistent format: an action (read or write) plus a resource type. Shopify organises them into three categories based on which API surface they control — see the full scope reference on Shopify's developer documentation:
| Category | API Surface | What It Covers |
|---|---|---|
| Authenticated Scopes | GraphQL Admin API, Web Pixel API, Payments Apps API | Store operations: products, orders, customers, themes, discounts, inventory — plus web pixel and payments app integrations |
| Unauthenticated Scopes | Storefront API | Customer-facing actions: browsing products, initiating checkout, reading collections |
| Customer Scopes | Customer Account API | Customer-owned data: their orders, profile, addresses |
One important mechanic: write permissions implicitly include read access. If an app requests write_customers, it can also read every customer record — you do not get a separate read-only grant. Shopify's own guidance to developers is to request write access only when the app genuinely needs to create or modify records, not just retrieve them. When an app's install screen shows a write scope for a feature that only displays data, that is a calibration problem worth questioning.
Optional vs. required scopes
Some apps declare optional scopes — permissions they will request only if you enable a specific feature. At install time, the consent screen should distinguish between mandatory and optional scopes. You can sometimes decline optional scopes and still use the app's core functionality. Check the App Store listing's Data Access section before installing to see whether a scope is required or optional.
What Shopify App Permissions Actually Grant Access To
Each Shopify access scope maps to a specific data set inside your store — understanding the mapping is how you evaluate whether a scope is proportionate to the feature an app provides.
| Scope | Data Accessed | Risk Level | Justified When |
|---|---|---|---|
read_customers | Names, emails, phone numbers, addresses, order history | High | CRM, email marketing, loyalty apps |
write_customers | Everything above + can create or modify customer records | Very High | Subscription management, loyalty with tier changes |
read_orders | All orders including attached customer details | High | Order management, analytics, fulfilment apps |
write_orders | Can create, edit, or fulfil orders | Very High | Fulfilment integrations, POS, ERP connections only |
read_products | Catalogue, pricing, inventory levels | Medium | Analytics, SEO tools, product-feed managers |
write_products | Can create or edit products, prices, variants | Medium–High | Bulk editors, PIM tools, feed sync apps |
write_themes | Can modify store theme code directly | Very High | Theme customisation apps only — no other justification |
read_all_orders | Orders beyond the default 60-day window | High — Restricted | Accounting software, long-range analytics |
The critical rule: once an app transfers data to its own servers, the security of that data depends entirely on the app developer's infrastructure — not Shopify's. read_customers granted to a marketing app means your customer list exists on that developer's servers. If their infrastructure is compromised, your customers' data is exposed even though your Shopify store itself is secure.
The proportionality test
Ask one question about every scope on an install screen: which specific feature in this app requires this level of access? If you can name the feature, the scope is probably proportionate. If you cannot — a countdown timer app requesting read_customers, for example — the app is requesting more access than its function justifies. That is the moment to contact the developer or choose an alternative.
Which Scopes Require Prior Shopify Approval
According to Shopify's developer documentation, certain access scopes are restricted — apps must have Shopify's explicit approval before they can declare or use them. The approval process runs through the Partner Dashboard, and the merchant cannot grant these scopes to an app that has not been cleared for them.
Restricted scopes as of 2026 include:
read_all_orders— extends order access beyond the default 60-day window. Required by accounting and analytics tools that need historical data. Apps must apply through the Partner Dashboard and justify the use case.- Subscription API scopes (
read_customer_payment_methods,read_own_subscription_contracts,write_own_subscription_contracts) — required for subscription products. Shopify approval is mandatory before these can be used in production. - Shopify Payments dispute scopes — limited to dispute-management apps using public distribution. Note: Shopify Payments was not available in South Africa as of mid-2026 — verify current availability on Shopify's supported-countries page before relying on this exclusion.
read_users— restricted to finance embedded apps and to stores on the Shopify Plus or Advanced plan.read_shopify_payments— requires Shopify approval but carries no plan-level restriction; available to eligible finance applications regardless of plan.
From the merchant side, the practical implication is: if an app is requesting a restricted scope, Shopify has already reviewed and approved that app for it. That does not mean you should grant it uncritically — it means the app had a legitimate use case. The question for you is whether your store has that use case. Shopify API permissions in the restricted category are a signal that the data being accessed is sensitive enough that Shopify required a formal vetting process before any app could request it.
Protected customer data (enforced December 2025)
Since December 10, 2025, apps accessing customer PII — name, email, phone number, physical address — via web pixels require Shopify's explicit "protected customer data" approval. Apps without this approval receive null values in those fields at runtime. For merchants, this means any app claiming to personalise customer-facing experiences with personal data should be able to show their protected customer data approval status on their App Store listing.
How to Review App Permissions in Your Shopify Admin
Shopify introduced a dedicated app activity and permissions dashboard on March 11, 2026. You access it at Settings → Apps, then click any installed app's name to open its about page. The about page shows four sections relevant to permissions:
- Activity and permissions — lists each store area the app has view or edit access to, with the date of its most recent activity in each area. If an area shows no activity, you can identify it under the "Unused access" subsection — Shopify flags permissions inactive for more than 30 days.
- Admin API activity — shows the number of API requests the app made across different store areas in the last 30 days. A bulk-import tool that has not been used in three months will show near-zero activity; if it also holds
write_products, that is an idle permission worth reviewing. - Privacy — lists the personal data categories the app can access, including sensitive customer and staff information. You can click through to the developer's privacy policy directly from this section.
- App History — shows when staff members granted updated app permissions, giving you an audit trail of who approved what and when.
One important limitation: this tracking applies to third-party apps only. Shopify's own native apps do not appear in the activity dashboard. If your store uses Shopify Email, Shopify Shipping, or other first-party tools, their data access is governed by Shopify's own privacy policy rather than the per-app dashboard.
Quarterly permission audit — three things to check
Once every three months, open Settings → Apps and run through three checks: (1) any app with "Unused access" flags — permissions it was granted but has not exercised in 30+ days; (2) any app you no longer actively use but have not uninstalled; (3) any app holding write_customers, write_orders, or write_themes — confirm the specific feature that justifies those scopes is still in use.
Want a structured review of your current Shopify app stack?
Tell us how many apps your store is running and we will assess the permission combinations against your actual use cases — and flag anything that looks over-scoped for what you are getting.
Book a Shopify permissions reviewHow to Audit Any App Before You Install It
A structured pre-install review of shopify app permissions takes under five minutes and catches the most common problems before they become live data access grants. Run through all four steps before adding any new app to your store.
Step 1: Read the Data Access section on the App Store listing before you click Install
Every App Store listing should have a Data Access section where developers explain each scope they request and the single feature it powers. A well-scoped app reads clearly: each scope listed has a plain-language reason tied to one named feature. If the explanation is missing or vague, contact the developer before installing.
Step 2: Map every permission to a specific visible feature
For each scope on the install consent screen, name the feature in the app that requires it. write_products for a bulk price editor — clear mapping. read_customers for a countdown timer widget — no mapping. If you cannot justify a scope to a specific feature, the app is requesting access beyond what it needs. That is a scope to question, not automatically approve.
Step 3: Note what the app explicitly does not access
Reputable developers will state in their listing or documentation which store resources they deliberately avoid. An analytics app that explicitly notes it does not access customer personal data — only aggregate event data — is signalling that its scoping was intentional. That transparency is a trust indicator worth weighing alongside star ratings.
Step 4: Compare the App Store listing against the install consent screen
Before confirming installation, compare the scopes listed on the App Store page with the scopes shown on the actual install consent screen. They should match. If the consent screen requests scopes not mentioned in the listing, the developer updated their scope requirements without updating their listing — or the listing was deliberately understated. Either way, pause before proceeding.
Three permission red flags that warrant declining an install
- Customer data export access for an app with no customer-facing features. A product review widget or a page-speed optimiser has no legitimate need for your customer list. If it is requesting
read_customersorwrite_customers, ask why. - Privacy policy hosted on a free Google Doc or generic URL. Apps handling customer personal data are legally required to maintain a proper privacy policy on their own domain. A Google Doc privacy policy signals the developer has not invested in POPIA or GDPR compliance infrastructure.
- Vague subprocessor lists. An app that processes customer data should be able to name the third-party services it sends data to (email providers, analytics platforms, cloud hosts). "We may share data with trusted partners" is not a subprocessor disclosure — it is a liability gap.
POPIA and Third-Party App Data Access — What SA Merchants Need to Know
South Africa's Protection of Personal Information Act positions your store as the "responsible party" for every piece of customer personal information you collect. When you grant a third-party app access to that data, the app developer becomes an "operator" — a processor acting on your behalf. POPIA requires that the relationship between a responsible party and an operator be governed by a written agreement specifying the conditions under which personal information can be processed.
In practice, Shopify app data access to customer records is not just a technical setting — it is a legal relationship. The privacy policy and data processing terms of every app holding customer-data scopes (read_customers, write_customers, read_orders) are not just the developer's problem — they are your compliance exposure too. If an app developer suffers a data breach and customer email addresses are exposed, POPIA's accountability principle places responsibility on your store as the entity that chose to grant access to that data.
Three POPIA-driven steps for SA merchants:
- Review each app's Shopify app privacy policy for a data processing clause. The policy should specify what data is collected via the Shopify integration, where it is stored (country of processing matters under POPIA's transborder flow provisions), how long it is retained, and the conditions for deletion.
- Apply the purpose limitation principle. POPIA requires that data be processed only for the specific purpose it was collected. Granting an app
read_customersso it can send abandoned cart emails is a defined purpose. That same app using your customer list to build lookalike audiences for their own advertising would be a purpose violation — check the app's terms for secondary data use. - Uninstall apps you are not using. An uninstalled app cannot continue processing data. Shopify revokes the app's API credentials on uninstall. Leaving an unused app installed with active customer-data scopes is an unnecessary processing activity that has no purpose basis under POPIA.
POPIA and app permissions — the short version
You are responsible for your customers' data even after it leaves your Shopify store and reaches an app developer's servers. Every app holding customer personal data should have a written privacy policy and data processing terms you have reviewed. Granting permission is not the end of the compliance obligation — it is the beginning of one.
Why South African Businesses Choose Growth Pulse Media
Growth Pulse Media is a Shopify marketing agency in South Africa founded by Dirk van Greuning, who built and scaled a large South African ecommerce business before moving into agency work. That background means our Shopify work starts from the operational reality of running a store — including the unglamorous work of auditing app stacks, reviewing data access agreements, and making sure the tools driving growth are not creating compliance exposure in the process.
We hold Registered Shopify Partner status, work with a limited number of clients at any time, and keep all work in-house. If you are a South African operator managing a Shopify store and want a clear picture of what your installed apps can actually access — and whether that access is proportionate — that is the kind of review we do as part of our onboarding process.
Who This Is NOT For
Stores running only Shopify's own built-in tools
If your store uses only native Shopify features — Shopify Email, Shopify Shipping, Shopify Payments (where available) — and no third-party apps, this guide does not apply to your current setup. Shopify's own apps are governed by Shopify's platform privacy policy rather than the per-app permission model described here.
Merchants with a dedicated technical agency already managing their stack
If you have a development agency or in-house developer who manages all app installations and reviews permissions as part of their retainer, this operational layer is already covered. The decision-making framework here is most useful when the store owner is the one reviewing the install consent screen.
Businesses building custom private apps for their own store
Custom private apps you build yourself operate under scopes you define — you are both the developer and the merchant. The audit framework above is designed for evaluating third-party apps where you did not write the scope declarations and cannot see the underlying code.
Merchants who have not yet launched on Shopify
This guide covers operational permission management for live stores. If you are still deciding whether to build on Shopify or researching what the platform can do, a better starting point is the Shopify South Africa overview before getting into the permissions layer.
Ready to audit what your Shopify apps can actually access?
Send us a note through our contact page and we will assess your installed app permissions against your store's actual use cases — no obligation, response within 24 hours.
Start the conversationFrequently Asked Questions
What are Shopify app permissions?
Shopify app permissions are access scopes that define which parts of your store data an app is allowed to read or modify. Each scope corresponds to a specific resource — products, orders, customers, themes — and each action (read or write) determines whether the app can only retrieve data or can also create and modify records. You review and grant these scopes when you install an app via the consent screen.
Can I revoke Shopify app permissions without uninstalling the app?
In most cases, no — Shopify's permission model works at the app level rather than the individual scope level. If you install an app and grant its requested scopes, those scopes remain active for the life of the installation. To remove access entirely, you uninstall the app, which causes Shopify to revoke the app's API credentials. Some apps with optional scopes may let you disable specific features that use those scopes, but this depends on how the app was built.
How do I check what permissions my installed Shopify apps currently have?
Go to Settings → Apps in your Shopify admin, then click any app name to open its about page. The Activity and Permissions section lists every store area the app can access, whether the access is view-only or edit, and the date of its most recent activity in each area. Permissions unused for more than 30 days appear under the Unused Access subsection. This dashboard was released by Shopify on March 11, 2026.
Which Shopify app permissions are highest risk for South African merchants?
The highest-risk scopes are those granting access to customer personal data: read_customers and write_customers expose names, email addresses, phone numbers, physical addresses, and order history. Under POPIA, this is personal information your store is responsible for protecting. write_themes is also very high risk because it allows an app to modify your store's code directly, which creates a security exposure beyond data access alone.
Do Shopify app permissions have any relevance to POPIA compliance in South Africa?
Under POPIA, a South African merchant is the "responsible party" for customer personal information — when you grant a third-party app scopes like read_customers or read_orders, the developer becomes an "operator" processing that data on your behalf. POPIA requires responsible parties and operators to have written agreements governing how personal data is processed. Granting broad customer-data access to apps without reviewing their data processing terms creates a POPIA compliance gap.
Get a Shopify App Permissions Review — No Obligation
Growth Pulse Media is a Registered Shopify Partner based in Johannesburg. We work with SA merchants on the operational detail of Shopify — including reviewing app stacks, assessing permission exposure, and building stores that perform without unnecessary compliance risk. All work done in-house. Limited client intake for senior attention. We will get back to you within 24 hours.
Contact Growth Pulse Media

