Shopify permissions explained
Every Shopify access scope the Hushdesk app asks for, in plain words, why it is needed, and what Hushdesk never does with your store.
Last updated 2 min read
Before you install the Hushdesk app, Shopify shows the access it asks for. This page explains each permission in plain words and what Hushdesk uses it for.
Before you start
- Who this is for: store owners and admins reviewing the install screen.
- Plan: all plans.
Step by step
- Open Settings > Apps > Shopify.
- Read What Hushdesk can access:
- Read customers, orders, products and fulfilments.
- Write orders (refunds, cancellations, edits, draft orders).
- Adds a chat app embed to your theme (you switch it on).
- Press Install on Shopify and compare with Shopify's own install screen.
What happens next
The scopes, one by one
| Shopify scope | Used for |
|---|---|
read_customers, write_customers |
Match tickets to Shopify customers; keep their details in step |
read_orders, read_all_orders |
Show orders beside tickets, including orders older than 60 days |
write_orders |
Refunds, cancellations and order tags from the inbox |
write_order_edits |
Change the shipping address before an order ships |
read_draft_orders, write_draft_orders |
Create a replacement order ("Duplicate") |
read_discounts, write_discounts |
Make a replacement free for the customer |
read_products |
Product titles and images on the order card |
read_fulfillments, read_merchant_managed_fulfillment_orders |
Fulfilment status and tracking numbers |
read_returns |
Return status on orders |
read_themes |
Open the theme editor with the chat embed ready |
Webhooks Shopify sends to Hushdesk
Uninstall, order created, updated and cancelled, fulfilment created and updated, refund created, customer created and updated, plus Shopify's three privacy topics. Every webhook is checked with the app's secret before it is accepted.
The app proxy
Hushdesk registers a storefront address, /apps/helpdesk, which lets the chat recognise logged-in shoppers without any code from you. Shopify signs every request to it.
Order and customer webhooks update Hushdesk straight away: orders, refunds and fulfilments refresh on the order card, and new or changed customers are matched to existing profiles by their Shopify id, then by email. Nothing your team typed on a profile is overwritten. If one delivery fails, Shopify sends it again and Hushdesk handles it once.
Shopify's privacy requests
Hushdesk acts on Shopify's three privacy webhooks automatically, and records each step in Settings > Audit logs:
| Request | What Hushdesk does |
|---|---|
| A customer asks for their data | The customer's details, conversations, messages and cached orders are collected as a file and emailed to the workspace owners ("A customer asked for their data"), who answer the shopper. |
| A customer asks to be erased | 10 days after the request, the customer is anonymised, their messages and conversation subjects are blanked, their files deleted and their cached orders removed. |
| The store is removed (48 h after uninstall) | The store's cached orders are deleted. If no other store is connected and the workspace has no paid plan, the whole workspace is deleted. A reinstall before then cancels it. |
Tips
- Install with the staff account that should appear as the installer in Shopify.
- Review the scopes again whenever Shopify asks you to approve updated access after an app update.
- If you only want chat for now, the snippet method needs no app at all. See Install live chat on your Shopify store.
Troubleshooting
Shopify says you do not have permission to install apps
Your Shopify staff account needs the permission to manage apps. Ask the store owner.
Frequently asked questions
Why does Hushdesk need write access to my Shopify orders?
So your team can act on orders from the inbox. Refunds, cancellations, address changes, order tags and free replacement orders all change the order in Shopify. Hushdesk only makes these changes when someone on your team presses the button, and each change is recorded in the ticket's activity log.
Can Hushdesk see my Shopify payments or payouts?
No. The app asks for customers, orders, products, fulfilments, order edits, draft orders, returns, discounts and themes. It does not ask for access to Shopify Payments, payouts, balances or your store's financial reports, so it cannot read them.
Why does Hushdesk ask to read all orders?
Shopify normally only shares the last 60 days of orders with apps. Customers often write about older orders, for example warranty questions, so Hushdesk asks for all orders so agents can find the one the customer means, even if it was placed months ago.
Does Hushdesk change my Shopify theme?
Not by itself. It asks to read themes so the Turn on chat in your theme button can open the right theme editor. The chat embed is added only when you switch it on in the theme editor, and today chat is added with a snippet you paste yourself.
What happens to customer data when I uninstall the Hushdesk app?
The connection is marked as uninstalled and nothing more syncs. 48 hours later Shopify asks Hushdesk to delete the store's data, and its cached orders are removed. If no other store is connected and you have no paid plan, the whole workspace is deleted. Reinstalling within those 48 hours cancels the deletion.
Was this helpful?
Related articles
- Connect your Shopify storeInstall the Hushdesk app on your Shopify store from Settings, Apps. Orders, customers and fulfilments sync into tickets; Growth and Scale add more stores.
- Refund, cancel or edit a Shopify orderRefund all or part of an order, cancel it before it ships, change the address or create a free replacement from the ticket, sent straight to your Shopify store.
- Troubleshoot the Shopify connectionFix Shopify install errors, a store linked to another workspace, missing orders and app page messages, and disconnect or uninstall the Hushdesk app.
- Identify logged-in shoppers in chatTell the chat widget who a logged-in shopper is with Helpdesk.identify, so chats land on the right customer. Learn what verified identity adds.
Still stuck?
Chat with the Hushdesk team. A person answers on every plan.