Webhooks and data privacy
The app subscribes to four webhook topics. One does the work, one cleans up after an uninstall, and three are the privacy topics Shopify requires of every public app. All of them arrive at a single endpoint and are verified before anything is read.
Verification
Every request is checked against the X-Shopify-Hmac-Sha256 header, computed over the exact bytes Shopify sent. A payload that fails the check is rejected with a 401 before it is parsed. A payload that passes but is malformed is acknowledged with a 200, so Shopify does not retry it forever.
orders/create
Fires when a new order is created. When Verify orders automatically is on for that store, the app:
- Looks up the connection for the shop domain
- Extracts the order ID from the payload
- Fetches the full order from the Admin API
- Runs the verification, spending credits from the organization's balance
- Stores the result and, when tagging is on, writes the tag and metafields
Verification happens after the order exists, so nothing sits in front of the buyer at checkout. A verification takes 15 to 30 seconds.
If automatic verification is off for the store, the webhook is acknowledged and nothing else happens.
app/uninstalled
Fires when a merchant removes the app. The access token is already dead by then, so the app deletes the store connection outright rather than marking it revoked. Cached verifications for that store are removed with it.
Your organization's verification log is not touched. That log records decisions your team made and is independent of whether the store is still connected.
Privacy topics
Shopify requires three compliance webhooks on every public app. They cannot be registered through the Admin API, so they are declared in the app configuration and registered at deploy time.
| Topic | What Verify AI does |
|---|---|
customers/data_request |
Logs the request with its payload for the 30-day response window |
customers/redact |
Logs the request. There is no customer personal data on a verification record to erase |
shop/redact |
Logs the request and removes every connection for the shop |
The reason customers/redact is short is worth stating plainly: a Verify AI verification record holds the order ID, order name, amount, currency, and the AI assessment. Customer names, emails, phone numbers, addresses, payment details, and IP addresses are read from Shopify at verification time and are not persisted.
Retention
| Data | Where it lives | Removed when |
|---|---|---|
| Store connection and encrypted tokens | Verify AI | The app is uninstalled, or shop/redact arrives |
| Cached verification per order | Verify AI | The store connection is removed |
| Organization verification log | Verify AI | The organization is deleted |
| Compliance request records | Verify AI | Retained for the response window and audit |
Answering a data request
When a merchant forwards a customers/data_request, the answer is usually short: Verify AI holds no personal data about that customer. What it holds is the assessment of orders, keyed by Shopify order ID. If a customer's order IDs are known, those records can be identified and removed on request.