Data & privacy

What RevLogic can access

A plain-language explanation of RevLogic's Shopify permissions — read orders, customers, and products, create draft orders, add its own analytics fields to customers and orders, and optionally tag winback customers. It never edits or deletes your store data.

When you install RevLogic, Shopify asks you to approve a set of permissions. This article explains, in plain language, exactly what those permissions let RevLogic do — and, just as importantly, what they don’t.

What RevLogic reads

  • Your orders. RevLogic reads your order history — line items, quantities, prices, and dates — because orders are the raw material for every customer profile, reorder cycle, and recommendation.
  • Your customers. It reads customer records — names, companies, email, phone, and location — to match orders to accounts and to power search and the call list.
  • Your products. It reads your catalog, including product types and vendors, so cross-sell recommendations and the categories/brands-to-pitch suggestions know what you sell.

What RevLogic writes

RevLogic writes in exactly four places, and nowhere else:

  • Draft orders. The New quote button lets your sales team build a quote for a customer; when they send it, RevLogic creates a standard Shopify draft order from it, which then opens in your Shopify admin for you to finish.
  • Its own analytics fields on customers. Churn risk, health, reorder cycle status, value tier, and top category, added as custom fields in RevLogic’s own revlogic namespace so you can group your Shopify reports by them. See RevLogic in Shopify Analytics.
  • Its own analytics fields on orders. Whether an order started as a RevLogic quote, and who on your team keyed it — again as custom fields in the revlogic namespace.
  • Its own status tags on customers, if you switch them on. RevLogic can keep a tag on a customer record for each of its statuses, adding and removing it as they take the status on and lose it. Each tag has its own switch and each is off unless you turn it on. They are spelled exactly RevLogic Key Account, RevLogic Growing, RevLogic Shrinking, and RevLogic Winback — those four are the only tags RevLogic ever touches, and it only ever removes a tag it added, so your own tags are never changed. See Customer statuses and key accounts and Churn risk and winback.

That’s the complete list. If RevLogic ever needed additional permissions, Shopify would prompt you to review and approve them before they took effect — which is exactly what happened when the analytics fields were added.

What RevLogic never does

Even with permission to write to customers and orders, RevLogic only ever adds its own fields and its own tags. It cannot and does not:

  • Edit or delete your orders, or change what’s on them.
  • Edit or delete your customers, or change their names, contact details, or addresses.
  • Edit or delete your products, prices, or inventory.
  • Change any of your store’s settings.
  • Add, change, or remove any customer tag other than its own four: RevLogic Key Account, RevLogic Growing, RevLogic Shrinking, and RevLogic Winback.

The only things it creates anywhere in Shopify are a draft order from a quote your team builds — a proposed order sitting in your admin that you review, adjust, and decide whether to collect payment on — the RevLogic analytics fields described above, and the status tags you’ve switched on. RevLogic never places a finished order or charges a customer on its own.

Every write onto customer records is yours to switch off: the analytics fields in Settings → Shopify Analytics, the winback tag in Settings → Winback tag in Shopify, and the other three in Settings → Status tags in Shopify. Quoting and everything else carries on unchanged either way.

Where your data goes

The orders, customers, and products RevLogic reads are stored in RevLogic’s own encrypted database, scoped to your store, so the app can compute intelligence quickly without querying Shopify on every click. This data:

  • Is used only to provide the RevLogic features you see in the app.
  • Is never sold or shared with third parties.
  • Stays tied to your store and is deleted when you uninstall.

Customer contact details in particular stay within your store and RevLogic’s secure database — they’re never handed off to anyone else.

Why these permissions are the right ones

RevLogic asks for the minimum it needs to do its job: read the data that describes your customers and their buying, turn the quotes your sales team builds during calls into draft orders, and hand its findings back to your store as report dimensions you own. Nothing in that set lets the app alter your storefront, your catalog, or the contents of your customers’ and orders’ records — which is exactly how a sales-intelligence tool should behave.

Next steps