App reviews, troubleshooting, and recommendations
Hello,
We are developing a public app solution for Shopify marketplace. We have been checking mandatory GDPR webhooks and have a question:
As I understood from GDPR webhooks technical requirements, it seems we are only supposed to gather these requests and return 200 to show we successfully received the request in scope of subscribing into GDPR webhooks. Could someone confirm that there is no technical requirements on returning a response once related data removed from our platform? Are we also required to return a response when we successfully deleted data? or that process only between us and the merchant after that time?
I am trying to understand technical requirements for public app solutions and respond webhook part sounded little bit vague.
Thanks for help.
Solved! Go to the solution
This is an accepted solution.
Your understanding is correct, that is how we understood it too.
In summary:
- Validate the request
- Return. 200 OK
- Remove the data within 30 days unless required by law to keep it
There is no other end points to call later for confirming deleting the data
This is an accepted solution.
Your understanding is correct, that is how we understood it too.
In summary:
- Validate the request
- Return. 200 OK
- Remove the data within 30 days unless required by law to keep it
There is no other end points to call later for confirming deleting the data
Thank you, I really appreciate your answer
In Canada, payment processors, like those that provide payment processing services t...
By Jacqui Mar 14, 2025Unlock the potential of marketing on your business growth with Shopify Academy's late...
By Shopify Mar 12, 2025Learn how to increase conversion rates in every stage of the customer journey by enroll...
By Shopify Mar 5, 2025