App reviews, troubleshooting, and recommendations
Hello,
We are developing a public app solution for Shopify marketplace. We have been checking mandatory GDPR webhooks and have a question:
As I understood from GDPR webhooks technical requirements, it seems we are only supposed to gather these requests and return 200 to show we successfully received the request in scope of subscribing into GDPR webhooks. Could someone confirm that there is no technical requirements on returning a response once related data removed from our platform? Are we also required to return a response when we successfully deleted data? or that process only between us and the merchant after that time?
I am trying to understand technical requirements for public app solutions and respond webhook part sounded little bit vague.
Thanks for help.
Solved! Go to the solution
This is an accepted solution.
Your understanding is correct, that is how we understood it too.
In summary:
- Validate the request
- Return. 200 OK
- Remove the data within 30 days unless required by law to keep it
There is no other end points to call later for confirming deleting the data
This is an accepted solution.
Your understanding is correct, that is how we understood it too.
In summary:
- Validate the request
- Return. 200 OK
- Remove the data within 30 days unless required by law to keep it
There is no other end points to call later for confirming deleting the data
Thank you, I really appreciate your answer
Hey Community 👋 Did you know that March 15th is National Everything You Think Is W...
By JasonH Apr 1, 2025Discover how to increase the efficiency of commerce operations with Shopify Academy's l...
By Jacqui Mar 26, 2025Shopify and our financial partners regularly review and update verification requiremen...
By Jacqui Mar 14, 2025