Home Help centre Account and security

Security, data and the permissions Everstock asks for

Account and securityUpdated 3 September 2026

Everstock asks Shopify for five permissions, and none of them touch orders, fulfillments or customer records. This page lists exactly what the app can see, how your supplier credentials are stored, and what deleting a connection removes.

The five permissions Everstock asks for

At install, Shopify shows you the access the app requests. Everstock requests exactly five scopes and nothing else:

  • read_products: to match supplier SKUs and barcodes against the products and variants you already have, and to read the current title, description, vendor, product type, tags and price on a matched variant so the app can work out what actually changed.
  • write_products: to write the supplier price onto a matched variant (only if you tick "Sync price", which is off by default), to write supplier title, description, vendor, product type or tags (only for the fields you tick under "Product fields (advanced)", all of which are off by default), and to create missing products (only if you turn that on, always as drafts, carrying any supplier metafields you mapped).
  • read_inventory: to read your current stock so the app can work out what actually changed, and to read your quantities before a supplier write-back push if you enable one.
  • write_inventory: to set the new quantity on a matched variant. This is the core job of the app.
  • read_locations: to list your store's locations, so you can choose which one a connection syncs to, and to check that a connection's chosen location is still active before a run.

What the app never sees

Everstock requests no order, fulfillment or customer scopes, so it cannot read your orders, your fulfillments or anything about your shoppers. It stores no shopper personal data at all. Shopify's mandatory customer data-request and customer-redaction webhooks are answered with nothing to hand over, because there is nothing held.

What the app does store is store-level operational data: your supplier connections and their settings, your sync run history and its per-record audit, your plan status, the Shopify session for your store, an install record for your shop domain, the payload of any sync job that ran out of retry attempts, and, if you answer the in-app rating prompt, the rating you gave, the reason you picked and any message you typed.

How credentials are protected

Supplier credentials and Shopify access tokens are encrypted at rest with AES-256-GCM before they reach the database. Nothing is kept as plain text.

Secret values are also never sent back to your browser. On a connection's Credentials section you see the auth type, the base URL and a "Secret status:" badge saying whether a secret is set, but never the secret itself. The section reads: "Rotate this supplier's auth secrets or base URL without recreating the connection. Leave a secret field blank to keep its current value." Use Test connection to check a rotated secret works, then Save credentials.

Never email us a key or token

Please do not send us your supplier API keys, bearer tokens, or your Shopify access token, in email or in any support message. We never need a live credential to help you, and the app is built so that credentials never have to travel to us in plain text.

If you think a credential may have been exposed, rotate it with the supplier first, then update it in the Credentials section of that connection.

What deleting a connection removes

Deleting a connection removes the connection, its stored credentials and its schedule, and it takes that supplier's sync run history and per-record audit with it. The confirmation modal is headed Delete connection? and carries the warning "Scheduled syncs for this supplier stop immediately". The action cannot be undone, so if you only want the syncing to stop, changing Sync frequency to Manual is the reversible option.

Uninstalling the app deletes the Shopify session for your store and marks your store inactive. On its own it does not remove your connections or your run history. When Shopify tells the app to erase its shop-scoped data for a closed store, the app deletes the connections, the run history and its per-record audit, the plan record, the session, any failed-job payloads and anything you sent through the rating prompt. The install record for your shop domain is erased 30 days later, and reinstalling inside that window cancels the deletion.

Need help? Visit the support page or email hello@usenormalize.com.