Shopify Permissions Explained

Glimmio requests the minimum Shopify API access scopes needed to power its features. Here is what each scope does.

Access scopes requested

read_products, write_products

Read product titles, descriptions, prices, images, and variants. Write is required to apply approved product content updates (AI-optimized titles, descriptions, SEO meta).

read_orders

Read order revenue, line items, customer acquisition source, and UTM attribution. Used to calculate True ROAS and connect ad spend to actual sales.

read_inventory

Read inventory levels per product and location. Used to prevent ads and lifecycle promotions from sending shoppers to unavailable products.

read_customers

Read aggregate customer acquisition data — how customers were acquired and their purchase history. We do NOT read personal customer profiles for advertising targeting.

read_checkouts

Read abandoned checkout data (cart contents, checkout URL). Used for WhatsApp and email abandoned checkout recovery flows.

write_price_rules, write_discounts

Create discount codes when a discount action is approved. Discounts are never created automatically without your explicit approval.

What we do NOT request

  • Staff account management (we cannot add or remove staff)
  • Billing information or payout data
  • Payment gateway configuration
  • Fulfillment service creation
  • Metafield write access on most resource types

Customer data

Customer emails, phone numbers, purchase history, and current marketing-consent state are stored only when needed for connected lifecycle messaging, audience membership, suppression, attribution, and verified-purchase reviews. Records are isolated by workspace and Business Account and are removed through the documented disconnect and data-deletion workflows.

Revoking access

Uninstall the Glimmio app from your Shopify Admin → Apps → Glimmio → Delete. Access can also be removed from Settings → Integrations → Shopify → Disconnect in Glimmio.

← Connect Shopify guide