Sheet 01 · Shopify app

Read-only. Not as a setting — as a design.

Pippen requests read scopes and only read scopes. It can see everything about how your store runs, and it cannot change a single row of it. Every recommendation it makes ends with a person deciding.

Sheet 02 · What Pippen reads

Five read scopes, and what each one is for.

If a scope is not on this list, Pippen did not ask for it — and it asks for nothing it does not read. The scopes are the contract: they are what the access token can do, and there is nothing in them that writes.

Shopify — scopes requested at install
5 scopes
read-only
No.ScopeWhat it readsWhy it needs it
01read_ordersOrders, line items, and where they shippedVelocity, lost sales, channel mix, and every answer that starts with “how many”.
02read_productsProducts, variants, prices, statusThe catalogue the whole census hangs off — plus stale listings and bundle candidates.
03read_inventoryStock levels per variant per locationCover, stockout-before-restock, reorder points, slow movers.
04read_locationsYour locations and their rolesSo “out of stock” means out of stock where the demand actually is.
05read_customersCustomer records attached to ordersRepeat rate and cohorts. Pippen joins orders to customers; it does not market to them.
Five scopes, all of them reads. Pippen holds no write scope, so there is no setting to get wrong.
Sheet 03 · What it can never do

Nothing is written. Ever.

Pippen holds no write scopes, so this is not a promise about behaviour — it is a limit on what the access token can do at all. Even if you asked it to, it could not.

  • 01Change a price, a product, or a listing
  • 02Edit, cancel, refund, or fulfill an order
  • 03Adjust inventory or move stock between locations
  • 04Message your customers, or add them to anything
  • 05Install other apps or change your store settings

How you connect

Install Pippen from the Shopify App Store and your workspace is set up inside your Shopify admin — nothing to sign up for separately. Or sign up here and connect the store: you approve the same five read scopes on Shopify's own screen. Either way there are no keys to paste.

When you uninstall

Access stops the moment Shopify tells us you uninstalled — the token goes with the install. The store connection is disabled and syncing halts. Nothing is deleted yet: the history already synced stays in the workspace, so a reinstall picks up where it left off. Deletion is the next step.

When data must be deleted

Shopify sends mandatory redaction requests after an uninstall, and for individual customers on request. We act on each one when it arrives. On shop/redact the store's workspace is deleted — its commerce data, credentials and everything stored for it; only a billing record an invoice depends on is kept, with the store's name removed. On customers/redact that customer's record and addresses are deleted, and their name, email, phone and address are removed from the orders they placed — the orders stay, because your sales history is yours.

How billing works

Installed from the App Store, Pippen bills through Shopify: you approve the charge on Shopify's own confirmation screen, it lands on your Shopify invoice, and you cancel it from Shopify. The 14-day trial runs first. Signed up directly instead, it is a card on file and the same plans apply.

Sheet 04 · Close

Install it from the Shopify App Store, or sign up and connect your store, and watch the census run. About fifteen minutes later you get the first thing Pippen has to say about your operation. Questions before you install? Write to support@pippen.com.