2. Permissions Postflows Requires and Why
When you connect your Shopify store, Postflows requests a set of permissions to access your store data. This article explains what each permission is for.
Why Postflows needs permissions
Postflows monitors your orders and shipments in real time to trigger automated notifications. To do that, it needs read access to order, fulfillment, and customer data - and write access to a limited set of order fields.
You'll see these permissions listed on the Shopify authorization screen before you approve the connection.
Permissions requested
GDPR compliance
Postflows also registers the following Shopify compliance webhooks automatically. These are not permissions you approve - Shopify requires all apps to handle them:
Customer data request - If a customer requests their data, Postflows receives the notification
Customer data deletion - If a customer's data is deleted from Shopify, Postflows removes it
Shop data deletion - If your store is deleted, Postflows removes all associated data
Postflows processes these requests in compliance with Shopify's data protection requirements.
Data security
Postflows stores only the data required to operate the service
Access tokens are encrypted at rest
Postflows does not share your store or customer data with third parties