Shopify Permissions Explained
Glimmio requests the minimum Shopify API access scopes needed to power its features. Here is what each scope does.
Access scopes requested
read_products, write_products
Read product titles, descriptions, prices, images, and variants. Write is required to apply approved product content updates (AI-optimized titles, descriptions, SEO meta).
read_orders
Read order revenue, line items, customer acquisition source, and UTM attribution. Used to calculate True ROAS and connect ad spend to actual sales.
read_inventory
Read inventory levels per product and location. Used to prevent ads and lifecycle promotions from sending shoppers to unavailable products.
read_customers
Read aggregate customer acquisition data — how customers were acquired and their purchase history. We do NOT read personal customer profiles for advertising targeting.
read_checkouts
Read abandoned checkout data (cart contents, checkout URL). Used for WhatsApp and email abandoned checkout recovery flows.
write_price_rules, write_discounts
Create discount codes when a discount action is approved. Discounts are never created automatically without your explicit approval.
What we do NOT request
- Staff account management (we cannot add or remove staff)
- Billing information or payout data
- Payment gateway configuration
- Fulfillment service creation
- Metafield write access on most resource types
Customer data
Customer emails, phone numbers, purchase history, and current marketing-consent state are stored only when needed for connected lifecycle messaging, audience membership, suppression, attribution, and verified-purchase reviews. Records are isolated by workspace and Business Account and are removed through the documented disconnect and data-deletion workflows.
Revoking access
Uninstall the Glimmio app from your Shopify Admin → Apps → Glimmio → Delete. Access can also be removed from Settings → Integrations → Shopify → Disconnect in Glimmio.