> For the complete documentation index, see [llms.txt](https://docs.samita.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.samita.io/sami-b2b-onboarding/reference/permissions-and-data.md).

# Permissions and data

See what the app can access in Shopify and why, what data it stores, where buyers' files are kept, and what happens to your data when you uninstall.

Sami B2B Onboarding asks Shopify for access to the parts of your store it works with, and keeps its own records of the applications buyers send you. This page lists both, explains where buyers' files are kept, and what happens to your data on a privacy request or when you uninstall.

## What the app can access in Shopify

Shopify shows these permissions when you install the app.

| What the app can do                                   | Why                                                                                                                                                                                                | Shopify scope                                                                     |
| ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| View and edit customers                               | Find a buyer's existing customer by email, create the customer when you approve, add tags, turn on **B2B approved**, and set a tax exemption when the buyer has no company.                        | `read_customers`, `write_customers`                                               |
| Edit companies                                        | Create the company, its location and its contact when you approve, apply the approval terms, and put a company on hold. Also reads your companies for **Sync from Shopify** and the company pages. | `write_companies`                                                                 |
| Edit products and catalogs                            | List your B2B catalogs in presets, and add an approved company's location to the catalog you chose.                                                                                                | `write_products`                                                                  |
| View orders                                           | Show a company's recent orders, totals and unpaid balance on its page in the app, across all of its orders.                                                                                        | `read_orders`, `read_all_orders`                                                  |
| View and edit online store pages                      | Create a page on your store for each published form, keep its title and visibility in step with the form, and list your pages for **Always allow these pages**.                                    | `read_online_store_pages`, `write_online_store_pages`                             |
| View themes                                           | Find your published theme, to check that the app embed is on and to open the theme editor in the right place.                                                                                      | `read_themes`                                                                     |
| View your store's languages                           | Know your store's default and published languages, for **Settings › Translate**.                                                                                                                   | `read_locales`                                                                    |
| Edit checkout rules                                   | Install the **B2B checkout lock** rule, which blocks checkout for buyers who aren't approved and for companies that are on hold or removed from B2B.                                               | `write_validations`                                                               |
| View and edit metaobjects and their definitions       | Work with your store's custom data entries.                                                                                                                                                        | `write_metaobject_definitions`, `write_metaobjects`                               |
| View products and stock as your storefront shows them | Read-only, and limited to what any visitor to your store can already see.                                                                                                                          | `unauthenticated_read_product_listings`, `unauthenticated_read_product_inventory` |

The app doesn't ask for access to payments.

Shopify also tells the app when you uninstall it, when you publish a different theme, and when a customer or your store asks for data to be shown or erased.

### Your team's own permissions

The app also checks the Shopify permissions of the person using it. Approving an application, or changing an approved company's status, needs the **Companies** and **Customers** permissions on that person's staff account. Changing an approved company's terms or sales rep needs **Companies**. Without them, the app turns the button off and says which permission is missing. The store owner adds them in Shopify admin under **Settings › Users**. See [Team and roles](/sami-b2b-onboarding/settings/team-and-roles.md).

## Customer data

Shopify treats customer names, email addresses, phone numbers and addresses as protected customer data. The app uses them only to run your B2B onboarding: to file applications, to find and create customers and companies in Shopify, and to send the emails you turn on.

## What the app stores

| Data               | What it holds                                                                                                                      | How long it's kept                                                                                             |
| ------------------ | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| Applications       | Every answer, the company and contact name, email, country, the language the buyer used, the status, the decision and the timeline | Rejected and abandoned ones, as set in **Data retention** below. All others, while the app is installed.       |
| Uploaded files     | The documents buyers attach, with their type and any dates                                                                         | As long as their application.                                                                                  |
| Companies          | The companies in the app's list, with their status, sales rep, terms, comments and documents                                       | While the app is installed.                                                                                    |
| Comments           | Your team's comments on applications and companies, with the author's name                                                         | As long as what they're about.                                                                                 |
| Activity log       | What happened in the app: decisions, emails sent and who they went to, imports and settings changes                                | While the app is installed.                                                                                    |
| Your team          | The name, email, role and last visit of each staff member who opened the app                                                       | While the app is installed.                                                                                    |
| Your setup         | Forms, rules, presets, email templates, translations and settings                                                                  | While the app is installed.                                                                                    |
| Keys and passwords | What you enter for your SMTP server and integrations                                                                               | Stored encrypted, while the app is installed. The app shows only that a password is saved, never the password. |

## Where buyers' files are kept

Files buyers upload go to private cloud storage, in a folder of their own for your store. No file has a public link. Your staff download a file through the app, which makes a link that works for five minutes. A buyer's browser never learns where a file is stored.

## Services that get data

The app sends data to another service only when you use the feature behind it.

| Service                                         | When                                                 | What it gets                                                         |
| ----------------------------------------------- | ---------------------------------------------------- | -------------------------------------------------------------------- |
| The app's mail service, or your own SMTP server | Every email the app sends                            | The recipient's address and the email                                |
| Your captcha provider (reCAPTCHA or hCaptcha)   | A form has a captcha                                 | The buyer's captcha answer and IP address, to check them             |
| Klaviyo                                         | You connect it on a form                             | The answers you map to Klaviyo fields                                |
| Your webhook (for example Zapier, Make or n8n)  | You turn on webhooks for a form                      | The application, for the events you pick                             |
| Google Maps                                     | You turn on address autocomplete                     | What the buyer types in the address box, sent from their own browser |
| The EU's VIES service                           | The tax ID check is on and the number is from the EU | The tax ID and its country                                           |
| An AI translation service                       | You use **Auto-translate**                           | Your form's wording, never buyers' answers                           |

See [Integrations](/sami-b2b-onboarding/integrations/integrations.md) to set these up.

## Data retention

In **Settings › Application rules › Data retention**, you choose how long the app keeps applications that didn't go anywhere. By default, an application waiting on the buyer closes as **Abandoned** after 30 days with no activity, and rejected and abandoned applications are deleted for good after 1 year, with their files, comments and timeline. See [Application rules](/sami-b2b-onboarding/settings/application-rules.md#choose-how-long-applications-are-kept) for the other options.

## Privacy requests

Buyers can ask you, as the store, to see or erase their personal data. You handle these in Shopify admin, from the customer's page: click **More actions**, then **Request customer data** or **Erase personal data**. Shopify passes the request on to the app. See Shopify's guide to [processing customer data requests](https://help.shopify.com/en/manual/privacy-and-security/privacy/processing-customer-data-requests).

* **Erase personal data.** The app finds the applications sent with the customer's email. It clears the contact's name, email and answers, removes the same details from the company in the app's list, deletes their uploaded files, and replaces their name and email on the timeline with "\[redacted]". The application itself and its decision history stay, so your records still show that a decision was made.
* **Request customer data.** The app records the request. To see what the app holds about the buyer, search for their email in **Companies › Applications**. You can export their applications to a CSV file. If you need help, [contact support](/sami-b2b-onboarding/help/contact-support.md).

The app matches requests by email address, so an application sent with a different address isn't included.

## When you uninstall the app

Shortly after you uninstall, the app deletes everything it holds for your store: applications, uploaded files, the companies in its list with their comments, your forms, rules, presets, email templates, translations, settings and the activity log. This can't be undone.

What the app created in Shopify stays in Shopify: customers, companies with their locations and contacts, and tags. The pages it made for your forms stay too; delete them in **Online Store › Pages** if you no longer need them.

Before you uninstall, export what you want to keep. In **Companies**, use **Export** on the **Applications**, **Companies** and **Documents** tabs, and in **Settings › Activity log**. Download any document you need from **Documents**.

If you install the app again, it starts fresh with a new **Wholesale application** form. To bring your Shopify companies back into its list, use [Sync from Shopify](/sami-b2b-onboarding/companies/sync-from-shopify.md).

## Legal

* [Privacy policy](https://samita.io/pages/privacy-policy)
* [Terms and conditions](https://samita.io/pages/terms-and-conditions)
* [GDPR](https://samita.io/pages/gdpr)
* [Data processing agreement (DPA)](https://samita.io/pages/dpa)

## Next steps

* [How it works](/sami-b2b-onboarding/reference/how-it-works.md) — what the app does with an application, step by step.
* [Application rules](/sami-b2b-onboarding/settings/application-rules.md) — set how long rejected and abandoned applications are kept.
* [Contact support](/sami-b2b-onboarding/help/contact-support.md) — ask about a privacy request or your data.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.samita.io/sami-b2b-onboarding/reference/permissions-and-data.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
