What we can (and can’t) see in your Shopify

Short version: your products, your stock, and the orders we send you. Never your customer list, your other orders or your money.

How the connection works

We set up a private app made only for your store (Shopify’s rule for marketplaces that keep their own checkout). You click Connect on IonxSupply, Shopify shows you its own approval screen listing every permission, and you click Install. Shopify’s servers enforce that list: the app can’t reach data outside it. Shopify’s access-scope documentation

Your access key is stored encrypted (AES-256-GCM) and never shown to anyone, us included.

Your ShopifyYou own thisIonxSupplyWe only get the greenYour products + stock countsOne sold here: your stock drops by 1Orders we send youTheir tracking number comes backNever: customer list, other orders, payoutsYour ShopifyYou own thisYour products + stock countsOne sold here: your stock drops by 1Orders we send youTheir tracking number comes backIonxSupplyWe only get the greenNever: customer list, other orders, payouts

Each permission, in plain English

See your product listread_products

Titles, prices, photos and variants, so your catalogue comes across without retyping it.

See your stock countsread_inventory

How many of each item you have, so we never list something you've already sold.

Lower a stock count when we sell onewrite_inventory

A sale on IonxSupply drops that item's Shopify count by exactly the quantity sold. This is what stops the same part selling twice.

See which location holds the stockread_locations

Shopify requires this to change a stock count at all. Location names only.

Put our orders into your Shopifywrite_orders

When someone buys your part here, the order appears in your Shopify admin like any other, with the buyer's shipping address, so you fulfil it the way you already do.

Read back the orders we createdread_orders

Shopify's permission is broader than how we use it, and because orders carry the buyer's name and address, Shopify's approval screen calls it "View customer data". Our system only ever asks for an order by the ID it created. It never lists or reads your other orders.

See when our order shipsread_fulfillments

When you add tracking in Shopify, we pick up the number, email it to the buyer, and mark the order shipped, which gets you paid.

What we never touch

  • Your customer list: names, emails, phone numbers. We never request Shopify's customers permission (the "View customer data" line on Shopify's screen is the order permission above).
  • Your other orders: anything not placed through IonxSupply.
  • Your payouts, bank details, revenue or Shopify billing.
  • Editing, renaming, repricing or deleting your products.
  • Your theme, apps, staff accounts or store settings.
  • Your discount codes, marketing, or anything on your storefront.
BeforeShopify: 5 in stockIonxSupply: 5 in stockSomeone buys 1 hereShopify: 5 in stockIonxSupply: 4 leftSeconds laterShopify: 4 in stockIonxSupply: 4 in stockBeforeShopify: 5 in stockIonxSupply: 5 in stockSomeone buys 1 hereShopify: 5 in stockIonxSupply: 4 leftSeconds laterShopify: 4 in stockIonxSupply: 4 in stock

The last arrow is the stock write. Without it your Shopify keeps selling a part that's gone.

Straight talk about the two that write

Stock: when someone buys your part here, we lower that item’s Shopify count by the amount sold. Nothing else: we can’t edit the product or raise counts.Orders: we add the IonxSupply order to your Shopify so you ship it with your usual tools. The buyer already paid on IonxSupply; adding tracking is what gets you paid.Rather not connect at all? Upload your product export or list by hand, and manage stock yourself.
What Shopify shows you before you approveInstall app⚠ This app hasn’t been reviewedIonxSupply your-shopMade only for your storeThis app needs access to:View customer dataName, email, phone, addressView staff and contributor dataStore ownerView and edit store dataProducts, ordersCustomer data = the buyer details on orders.We use only the orders we send you.CancelInstall
“This app hasn’t been reviewed” is normal here. Shopify reviews apps listed in its App Store; a private app made for one store never goes through that review.“View customer data” is how Shopify labels order access, because every order carries the buyer’s name, email and address. We use it for the orders we send you, so they arrive with a shipping address. We don’t request your customer list and never read your other orders. “Store owner” under staff data is also Shopify’s wording; we don’t use it.

Check it yourself, and switch it off whenever

In your Shopify admin: Settings, then Apps and sales channels, then the IonxSupply app. It lists the exact permissions. Click Uninstall and our access ends that second; your listings here stay put and stop syncing. You can also disconnect from your IonxSupply dashboard.

Is this normal?

Yes. Inventory-sync apps like Syncio and Stock Sync use the same product and inventory permissions, and marketplace connectors add order access for the same reason we do: so orders land where you already ship from. A private app for one store is Shopify’s documented custom distribution method.

Connect my storeQuestions? Talk to us first