【Delete Me】Which Customer Data Can Your App Access? How to Check in the Shopify Admin — and How to Minimize What You Hold
What you'll learn in this article
- How to check which customer data each of your Shopify apps can access — right from the admin panel
- Why it's worth reviewing your installed apps' data access on a regular basis
- How to minimize the customer data you hold in the first place (with Delete Me's dormant member auto-deletion)
Do you know what customer data your apps are looking at?
Shopify stores can install a wide variety of apps — for reviews, email marketing, inventory management, customer management, and more. As convenient as they are, these apps have access to critical store data: products, orders, and customer information.
Customer information and order history are personal data in the most direct sense — names, email addresses, purchase histories. Understanding "which app can access which data, and to what extent" is essential for both store credibility and personal data protection.
You can check app data access right in the Shopify admin
It's actually possible to see exactly "what data each app can access" and "when it last accessed it" — directly from the Shopify admin panel.
How to check: Shopify Admin → Settings → Apps → select the app → Activity and permissions
This screen gives you a breakdown by access area, showing read and write permissions alongside the timestamp of the most recent access.
In the example below, Customer management and Order management both show "View and Edit" permissions, with recent activity shown as "31 minutes ago." In other words, you can see at a glance that the app was actively accessing customer and order data just moments ago.

Key takeaway
- Permissions tell you what an app can access — but the recent activity log tells you what it's actually been doing. Check for any access that seems unexpected.
Why regular reviews matter
Apps left installed and forgotten, or apps with broader permissions than they actually need, increase the surface area where personal data is exposed to third parties. We recommend building habits like these:
- Review permissions before uninstalling any app you're no longer using
- For apps that access customer or order data, know who provides them and what they're used for
- Check the recent activity log periodically for any access you didn't expect
Delete Me itself is designed not to store personal data
We've been talking about checking app access — so what about Delete Me itself? A fair question.
Delete Me is an app built to delete and clean up customer personal data. By its very nature, it touches customer data when carrying out deletions and masking. However, it does not store that data on its own servers after the fact.
Personal data is never stored on our servers. Information such as names, email addresses, postal addresses, and order history is only