Permissions and data
A plain-language summary of what data and permissions Sami B2B Lock, Password Protect needs, and why.
When you install Sami B2B Lock, Password Protect, Shopify asks you to approve a set of permissions for the app. This page explains, in plain language, what each of those permissions is used for. It's a summary for merchants, not a legal document — for the complete legal detail, see the full Privacy Policy linked at the bottom of this page.
Products, collections, pages, blogs, and articles
The app reads these so you can pick what to lock. When you're setting up a lock's content type — Products and variants, Collections, Pages, or Blogs and articles — the app needs to show you a picker of your actual catalog and content so you can choose exactly what to protect.
Customers, their tags, and their companies
The app reads your customers, along with their tags and any B2B company account they belong to, to match customer-based access rules — Logged-in customers, Customer tags, B2B customer, Email contains, and Selected customers all depend on being able to check who the visitor is and what's on their account.
Orders (read and write)
The app reads order data only to support the Purchased items and Order quantity rules — checking what a customer has already bought, or how many orders they've placed, before deciding whether they unlock a piece of content. Write access to orders is used narrowly for the same purpose, and isn't used to modify your orders in any way unrelated to these rules.
Theme content
The app reads and writes a small amount of theme content in order to install and update the app embed that enforces your locks on the storefront. This is the same embed you turn on from the Theme Setup screen — without this permission, the app would have no way to add or update that embed in your theme.
Sending email
The app sends email on your behalf for the Request access feature — the admin notification sent to your store's contact email whenever a shopper submits a request, and the access email sent to the shopper once you grant them a passcode or secret link.
Mailchimp and Klaviyo API keys
If you connect a Mailchimp or Klaviyo account to use with the "Subscribe to unlock" rule, the app stores the API key you provide encrypted, and uses it only to check whether a shopper is already a subscriber, or to add them as one, for that specific rule. The key isn't used for anything else.
The full legal document
This page covers the practical "what and why" of the app's permissions. For the complete terms, see the Privacy Policy.
Related docs
Last updated
Was this helpful?