Read-only. Not as a setting — as a design.
Pippen requests read scopes and only read scopes. It can see everything about how your store runs, and it cannot change a single row of it. Every recommendation it makes ends with a person deciding.
Five read scopes, and what each one is for.
If a scope is not on this list, Pippen did not ask for it — and it asks for nothing it does not read. The scopes are the contract: they are what the access token can do, and there is nothing in them that writes.
| No. | Scope | What it reads | Why it needs it |
|---|---|---|---|
| 01 | read_orders | Orders, line items, and where they shipped | Velocity, lost sales, channel mix, and every answer that starts with “how many”. |
| 02 | read_products | Products, variants, prices, status | The catalogue the whole census hangs off — plus stale listings and bundle candidates. |
| 03 | read_inventory | Stock levels per variant per location | Cover, stockout-before-restock, reorder points, slow movers. |
| 04 | read_locations | Your locations and their roles | So “out of stock” means out of stock where the demand actually is. |
| 05 | read_customers | Customer records attached to orders | Repeat rate and cohorts. Pippen joins orders to customers; it does not market to them. |
Nothing is written. Ever.
Pippen holds no write scopes, so this is not a promise about behaviour — it is a limit on what the access token can do at all. Even if you asked it to, it could not.
- 01Change a price, a product, or a listing
- 02Edit, cancel, refund, or fulfill an order
- 03Adjust inventory or move stock between locations
- 04Message your customers, or add them to anything
- 05Install other apps or change your store settings
How you connect
Install Pippen from the Shopify App Store and your workspace is set up inside your Shopify admin — nothing to sign up for separately. Or sign up here and connect the store: you approve the same five read scopes on Shopify's own screen. Either way there are no keys to paste.
When you uninstall
Access stops the moment Shopify tells us you uninstalled — the token goes with the install. The store connection is disabled and syncing halts. Nothing is deleted yet: the history already synced stays in the workspace, so a reinstall picks up where it left off. Deletion is the next step.
When data must be deleted
Shopify sends mandatory redaction requests after an uninstall, and for individual customers on request. We act on each one when it arrives. On shop/redact the store's workspace is deleted — its commerce data, credentials and everything stored for it; only a billing record an invoice depends on is kept, with the store's name removed. On customers/redact that customer's record and addresses are deleted, and their name, email, phone and address are removed from the orders they placed — the orders stay, because your sales history is yours.
How billing works
Installed from the App Store, Pippen bills through Shopify: you approve the charge on Shopify's own confirmation screen, it lands on your Shopify invoice, and you cancel it from Shopify. The 14-day trial runs first. Signed up directly instead, it is a card on file and the same plans apply.
Install it from the Shopify App Store, or sign up and connect your store, and watch the census run. About fifteen minutes later you get the first thing Pippen has to say about your operation. Questions before you install? Write to support@pippen.com.