What we can (and can’t) see in your Shopify
Short version: your products, your stock, and the orders we send you. Never your customer list, your other orders or your money.
We set up a private app made only for your store (Shopify’s rule for marketplaces that keep their own checkout). You click Connect on IonxSupply, Shopify shows you its own approval screen listing every permission, and you click Install. Shopify’s servers enforce that list: the app can’t reach data outside it. Shopify’s access-scope documentation
Your access key is stored encrypted (AES-256-GCM) and never shown to anyone, us included.
Each permission, in plain English
read_productsTitles, prices, photos and variants, so your catalogue comes across without retyping it.
read_inventoryHow many of each item you have, so we never list something you've already sold.
write_inventoryA sale on IonxSupply drops that item's Shopify count by exactly the quantity sold. This is what stops the same part selling twice.
read_locationsShopify requires this to change a stock count at all. Location names only.
write_ordersWhen someone buys your part here, the order appears in your Shopify admin like any other, with the buyer's shipping address, so you fulfil it the way you already do.
read_ordersShopify's permission is broader than how we use it, and because orders carry the buyer's name and address, Shopify's approval screen calls it "View customer data". Our system only ever asks for an order by the ID it created. It never lists or reads your other orders.
read_fulfillmentsWhen you add tracking in Shopify, we pick up the number, email it to the buyer, and mark the order shipped, which gets you paid.
What we never touch
- Your customer list: names, emails, phone numbers. We never request Shopify's customers permission (the "View customer data" line on Shopify's screen is the order permission above).
- Your other orders: anything not placed through IonxSupply.
- Your payouts, bank details, revenue or Shopify billing.
- Editing, renaming, repricing or deleting your products.
- Your theme, apps, staff accounts or store settings.
- Your discount codes, marketing, or anything on your storefront.
The last arrow is the stock write. Without it your Shopify keeps selling a part that's gone.
Straight talk about the two that write
Check it yourself, and switch it off whenever
In your Shopify admin: Settings, then Apps and sales channels, then the IonxSupply app. It lists the exact permissions. Click Uninstall and our access ends that second; your listings here stay put and stop syncing. You can also disconnect from your IonxSupply dashboard.
Is this normal?
Yes. Inventory-sync apps like Syncio and Stock Sync use the same product and inventory permissions, and marketplace connectors add order access for the same reason we do: so orders land where you already ship from. A private app for one store is Shopify’s documented custom distribution method.