Data Access and Deletion
Shopify privacy requests are received automatically through the mandatory customers/data_request, customers/redact and shop/redact webhooks. Receipt records the request for verified operational handling; it does not by itself mean that export or deletion is complete.
Approved request and deletion process: Verified Shopify privacy requests are recorded, tenant-scoped, exported or redacted by an authorized administrator, checked for ERP and customer-service records and attachments, and completed within 30 days with retry and escalation for failures.
Merchants can also request export or deletion by emailing privacy@xzkj.ai from an authorized business address. Include the store domain and request type; do not send customer data in the email. We verify authority before acting and retain only records required by law or security obligations.