B2B Marshal Policy

GDPR and CCPA Request Handling

Privacy-rights and Shopify mandatory privacy webhook handling for B2B Marshal.

As of August 19, 2026. Depending on location and role, applicable privacy laws can provide rights to access, correct, delete, restrict, object to, or receive a copy of personal data and to opt out of certain sale, sharing, or targeted-advertising uses.

B2B Marshal does not sell personal information, use merchant customer data for targeted advertising, or build cross-store marketing profiles.

Shopify privacy webhooks

B2B Marshal implements Shopify's mandatory handlers for:

  • customers/data_request
  • customers/redact
  • shop/redact

Requests are authenticated without depending on an active merchant session. The app can retain limited compliance metadata such as topic, delivery/request ID, Shopify customer ID supplied with the request, requested-order count, processing status, and timestamps. Raw signed request bodies are not stored as application records.

Valid requests are acknowledged and the required action is completed within Shopify's required response window unless applicable law requires particular information to be retained.

Customer data requests and redaction

B2B Marshal does not store customer contact profiles, customer email/phone/address fields, or a customer-ID-to-order index. Its stored order/account state is associated with Shopify B2B company and location identifiers rather than a copied customer profile. Customer-level Shopify requests therefore normally have no stored customer record to return or delete.

The merchant remains the appropriate first contact for a customer request about the merchant's Shopify store, orders, account, or business records. Five Acre Code will coordinate with the verified merchant when needed and will not disclose merchant data to an unverified requester.

Shop deletion

On uninstall, B2B Marshal deletes sessions, stops authenticated access, marks the shop uninstalled, and cancels pending reconciliation/projection work. When Shopify sends shop/redact, B2B Marshal deletes remaining per-shop application records, including company/location, order/draft, exposure, policy, settings, audit, queue, cache, and webhook/privacy records.

Provider backups, support emails, security records, billing references, legal records, and abuse-prevention records can persist for a reasonable period when lawfully required or needed for security, provider recovery, audit, or disputes. Access is limited and backups age out under provider retention processes.

Direct merchant and admin-user requests

Merchants or authorized Shopify admin users can email support@fiveacrecode.com. Include:

  • Shopify shop domain.
  • Request type.
  • Your relationship to the merchant or data subject.
  • Enough detail to identify the relevant app account or support interaction.

Do not include credentials, payment card data, or unnecessary customer personal data in the initial message. We may require verification through the Shopify merchant or another reasonable method before fulfilling a request.

Appeals and complaints

If you disagree with a response, reply to the request thread and explain the issue. Depending on applicable law, you may also have the right to contact a privacy or data-protection regulator.

This page describes the app process and is not legal advice. Merchants are responsible for their own privacy compliance, notices, request handling, and instructions to service providers.