1. Authorized access and administration
Review connected stores, users, roles and integrations using Shopify and any administrative controls available in the relevant app. The controls depend on your permissions, feature scope and service agreement; do not assume that a control in one app is available in every other app.
Only authorize people who need the information for their role. An organization is responsible for its own account permissions and for communicating lawful instructions about the information it provides.
2. Review the information a workflow needs
Pricing workflows center on product, variant, offered-price and campaign records. Audit workflows center on authorized storefront observations, screenshots and review evidence. Grievance workflows can involve customer contact information, order context, complaint text, attachments and correspondence.
Limit shared context to the task. Do not include passwords, complete payment-card details or unrelated sensitive information in prompts, screenshots or support enquiries. Review third-party and AI processing requirements before enabling a feature that needs them.
3. Review and approval of outputs
Check pricing calculations and coverage, audit findings and certificate statements, and customer-response drafts before operational use. Maintain the approvals appropriate to your business. Where a workflow records reviewer actions or changes, those records can help explain the decision trail.
Human review is particularly important where a conclusion depends on context that software cannot establish from a page, event or complaint record alone. A request to change information should be made through an authorized account or verified support route.
4. Access and export requests
Contact [email protected] to request available personal information or relevant app records. Identify the app and store or account involved and the scope of your request. Organization-level records may require approval from an authorized merchant or administrator.
We may verify identity and authority and limit disclosure to protect another person’s privacy, confidential information, security or legal obligations. Available export formats and scope depend on the records and the applicable rights or agreement.
5. Correcting information
Use available account controls or contact us to request correction of inaccurate information. If the information comes from Shopify or another connected system, correct it in the source system where appropriate so subsequent synchronization does not reintroduce the same error.
Corrections to historical pricing or audit evidence should preserve a clear record of what changed and why rather than silently rewriting a past decision. This recordkeeping must still respect applicable correction and erasure rights.
6. Disconnecting and deleting
Authorized users can use the applicable Shopify or integration process to disconnect or uninstall an app. Contact us to request deletion of retained account, store, workflow or personal information, identifying the records involved.
Disconnecting access and deleting retained information are distinct operations. Lawful retention may remain necessary for billing, tax, disputes, security or backups, but exceptions do not override mandatory legal or Shopify erasure requirements. We will handle valid shop/customer data requests according to those requirements and the applicable service arrangements.
Deletion can reduce the historical evidence available for later pricing or audit review. Where lawful and appropriate, consider the records your business must retain or export before requesting deletion. This is not a reason to refuse a valid erasure right.
7. Requests from a merchant’s customer
For an order, complaint or customer-data request relating to a merchant, contact that merchant through its published channels. The merchant ordinarily determines the relevant customer relationship and instructions; ComplyCat supports processing requests within its role and lawful access.
If we receive a valid Shopify compliance request or verified merchant instruction concerning information we hold, we will handle it according to applicable platform and legal duties. Government-portal case handling remains subject to the relevant official process.
8. AI context, marketing and storage choices
Choose what context to provide to an AI-enabled workflow, avoid unnecessary personal data, and ask about available feature or agreement-specific processing restrictions. We do not claim that every provider offers identical controls or that every app has a universal retention toggle.
Use available unsubscribe controls or contact us to opt out of marketing. Necessary operational messages may still be sent. Browser settings and service controls can manage some cookies or storage; disabling necessary storage may affect authentication or other core functions. The Privacy Policy describes the website’s current configuration.
9. Verification, timing and available rights
We may confirm your email, account or merchant authority and ask for only the information reasonably needed to evaluate the request. Verification information is used for handling the request, preventing unauthorized access and meeting applicable recordkeeping obligations.
We respond within applicable legal timeframes and explain a lawful refusal or limitation where required. Depending on your jurisdiction and role, additional rights may include restriction, objection, portability, withdrawal of consent or a complaint to a relevant authority. Request handling does not require waiving those rights.
10. Make a request
Email [email protected] with the app name, the account email or store identifier needed to locate the record, the action requested and a brief description. Do not send account passwords or unnecessary customer attachments.
Operator: ComplyCat. This page supplements our Privacy Policy and Terms of Service. Applicable written processing agreements may provide additional procedures.
Questions?
Contact [email protected] for support, billing and privacy enquiries.