Data & privacy

What RevLogic can access

A plain-language explanation of RevLogic's Shopify permissions: read orders, customers, and products, create draft orders, add its own analytics fields to customers and orders, and optionally tag winback customers. It never edits or deletes your store data.

When you install RevLogic, Shopify asks you to approve a set of permissions. This article explains in plain language what those permissions let RevLogic do, and what they don’t.

What RevLogic reads

  • Your orders. RevLogic reads your order history (line items, quantities, prices, and dates) because orders are the raw material for every customer profile, reorder cycle, and recommendation.
  • Your customers. It reads customer records (names, companies, email, phone, and location) to match orders to accounts and to power search and the call list.
  • Your products. It reads your catalog, including product types and vendors, so cross-sell recommendations and the categories/brands-to-pitch suggestions know what you sell.

What RevLogic writes

RevLogic writes in exactly four places:

  • Draft orders. The New quote button lets your sales team build a quote for a customer; when they send it, RevLogic creates a standard Shopify draft order from it, which then opens in your Shopify admin for you to finish.
  • Its own analytics fields on customers. Churn risk, health, reorder cycle status, value tier, and top category, added as custom fields in RevLogic’s own revlogic namespace so you can group your Shopify reports by them. See RevLogic in Shopify Analytics.
  • Its own analytics fields on orders. Whether an order started as a RevLogic quote, and who on your team keyed it. These are also custom fields in the revlogic namespace.
  • Its own status tags on customers, if you switch them on. RevLogic can keep a tag on a customer record for each of its statuses, adding and removing it as they take the status on and lose it. Each tag has its own switch and each is off unless you turn it on. They’re spelled exactly RevLogic Key Account, RevLogic Growing, RevLogic Shrinking, and RevLogic Winback. Those four are the only tags RevLogic ever touches, and it only ever removes a tag it added, so your own tags are never changed. See Customer statuses and key accounts and Churn risk and winback.

That’s the complete list. If RevLogic ever needed additional permissions, Shopify would prompt you to review and approve them before they took effect. That’s what happened when the analytics fields were added.

What RevLogic never does

Even with permission to write to customers and orders, RevLogic only ever adds its own fields and its own tags. It can’t and doesn’t:

  • Edit or delete your orders, or change what’s on them.
  • Edit or delete your customers, or change their names, contact details, or addresses.
  • Edit or delete your products, prices, or inventory.
  • Change any of your store’s settings.
  • Add, change, or remove any customer tag other than its own four: RevLogic Key Account, RevLogic Growing, RevLogic Shrinking, and RevLogic Winback.

The only things it creates anywhere in Shopify are a draft order from a quote your team builds (a proposed order sitting in your admin that you review, adjust, and decide whether to collect payment on), the RevLogic analytics fields described above, and the status tags you’ve switched on. RevLogic never places a finished order or charges a customer on its own.

Every write onto customer records is yours to switch off: the analytics fields in Settings → Shopify Analytics, the winback tag in Settings → Winback tag in Shopify, and the other three in Settings → Status tags in Shopify. Quoting and everything else carries on unchanged either way.

If you connect Klaviyo

Connecting Klaviyo is separate from your Shopify permissions and entirely optional. Nothing here happens unless you connect it yourself in Settings → Klaviyo and then switch the property push on.

When you do, RevLogic sends each customer’s email address, plus seven values it derived about them (reorder status, health score, revenue tier, spend trend, key-account status, expected reorder date, and last order date) to your Klaviyo account, at your direction. That’s the whole payload. RevLogic never sends order contents, product data, phone numbers, addresses, or your notes.

On reading: Klaviyo’s approval screen lists read access to profiles alongside the write access, and RevLogic uses it for one thing: asking Klaviyo whether the batch of property updates it just sent finished. It never reads, stores, or displays your profiles, lists, segments, flows, or campaign data. The only other thing it reads is your account’s name, once, so the Settings card can show you which account you connected.

  • It may create profiles. A customer Klaviyo doesn’t already know about gets a profile when RevLogic writes to them. RevLogic tells you how many customers it will reach before you turn the push on.
  • Customers with no email never leave. A name-only customer can’t be matched to a Klaviyo profile, so nothing about them is sent.
  • Your Klaviyo credentials are stored encrypted and are deleted when you disconnect and when you uninstall RevLogic.
  • Disconnecting clears the expected reorder date on every profile RevLogic wrote to, so date-triggered flows stop firing. The other six properties keep their last values, under Klaviyo’s own retention.

Full detail is in RevLogic properties in Klaviyo.

Where your data goes

The orders, customers, and products RevLogic reads are stored in RevLogic’s own encrypted database, scoped to your store, so the app can compute intelligence quickly without querying Shopify on every click. This data:

  • Is used only to provide the RevLogic features you see in the app.
  • Is never sold, and never shared with a third party except one you connect yourself. Today that means Klaviyo, and only the email address plus the seven derived values described above.
  • Stays tied to your store and is deleted when you uninstall.

Customer contact details in particular stay within your store and RevLogic’s secure database. The one exception is an integration you connect and switch on yourself, like Klaviyo. There, the only contact detail that travels is the email address, so RevLogic can match the customer to their profile.

Why these permissions are the right ones

RevLogic asks for the minimum it needs to do its job: read the data that describes your customers and their buying, turn the quotes your sales team builds during calls into draft orders, and hand its findings back to your store as report dimensions you own. Nothing in that set lets the app alter your storefront, your catalog, or the contents of your customers’ and orders’ records.

Next steps