Pricing & Margins

Part of Dropshipping software

Reviewing app permissions to customer data

Check what a dropshipping app can access, which customer details reach suppliers and how to review access, retention and removal.

Before you connect a dropshipping app, check which customer details it can access and why the intended order workflow needs them. Review access again when permissions or your use of the app changes. Order fulfilment does not justify an unrelated use of customer information.

Reviewing app permissions to customer data: Key steps

  • Check what customer details the app can accessBefore connecting a dropshipping app, verify which personal information it can access and ensure it aligns with your order workflow.
  • Map the data flow from store to supplierTrace each handoff in the order process and record which fields (name, address, email, etc.) are shared and why they are needed.
  • Review Shopify’s permission screen for scopesCheck the app’s access scopes in Settings > Apps; only approve what is necessary for functionality.
  • Maintain an access and exit recordDocument each app’s purpose, review date, owner, and confirm data deletion when uninstalling the app.

Map the data flow

Trace an order from the store to the connector, supplier and any other recipient. For each handoff, record whether it includes a name, delivery address, email, phone number, order contents or another identifier, and why that field is needed.

Separate access to a store record from information passed onward. A connector may read an order while the supplier receives only the fields required to dispatch it. Ask the developer what it stores, where recipients operate, who else receives the data and what happens to retained copies after an order is complete. A privacy policy helps answer these questions but does not prove how your configured workflow behaves.

Read the platform permission screen

For a Shopify store, open Settings > Apps and select the app to view its about page. Shopify states this page includes privacy details and permission details.

Shopify’s developer documentation says access scopes control which store data an app can read and write. It advises requesting only the data an app needs to function, and notes that merchants approve an app’s requested scopes when they install it. Shopify approval is required for some scopes.

Record the permission list, review date and reason each category is needed. If access appears unrelated to the intended workflow, ask the developer for a specific explanation before using the connection. The platform screen shows access categories; it does not settle the developer’s storage, subcontractor or onward-disclosure practices.

App permission types on Shopify vs. privacy obligations under APPs

  • Shopify Access ScopesDefine what data an app can read/write (e.g., orders, customer details). Merchants approve these at install.
  • Australian Privacy Principle 6 (APP 6)Limits use or disclosure of personal information to the purpose for which it was collected unless an exception applies.
  • Australian Privacy Principle 8 (APP 8)Requires reasonable steps before disclosing personal information overseas, including assessing risks and ensuring safeguards.
  • Australian Privacy Principle 11 (APP 11)Mandates reasonable security measures and timely de-identification or destruction of data no longer needed.

Apply the Australian privacy question

If the Privacy Act and Australian Privacy Principles (APPs) apply to your business, APP 6 generally limits use or disclosure for a purpose beyond the one for which information was collected unless an exception applies.

APP 8 sets a framework for disclosure of personal information to an overseas recipient, including reasonable steps and exceptions. APP 11 requires reasonable security steps and, subject to its exceptions, reasonable steps to destroy or de-identify information no longer needed for a permitted purpose.

Compare the proposed flow with what customers were told when their details were collected. Check the provider’s terms for overseas recipients, security, retention and deletion. Where an obligation or a material data use remains unclear for the actual arrangement, obtain an answer before connecting the app.

Key privacy compliance considerations for dropshipping apps in Australia

  • APP 6 - Use/Disclosure LimitationOnly use customer data for the intended purpose unless an exception applies.
  • APP 8 - Cross-Border DisclosureIf data goes overseas, take reasonable steps to protect it; assess recipient country’s privacy laws.
  • APP 11 - Data Security & DeletionImplement reasonable security; destroy or de-identify data when no longer needed.

Keep an access and exit record

Name the person allowed to approve apps. Record each connected app’s purpose, permission review date and owner. Revisit the record after a change to the app, supplier route or provider.

Before retiring an app, preserve order information needed for open cases. Then uninstall it through the platform and ask the developer how retained data will be handled. Request confirmation of deletion where appropriate.

More from Pricing & Margins