OAuth, not passwords
You connect Shopify through OAuth. We never ask for your Shopify password.
Security
Dropshipped connects to Shopify so it can create branded listings and keep inventory, prices, and tracking accurate. Here is what we access and why.
You connect Shopify through OAuth. We never ask for your Shopify password.
Shopify offline tokens are encrypted at rest and never printed in logs.
We are building toward SOC 2 controls as part of the production security roadmap.
Shopify access
read_productsImport product and variant details from Shopify when we need to match or update a listing.
write_productsCreate or update products only when you take that action in Dropshipped.
read_inventoryCheck current inventory item IDs and stock state for variant mapping.
write_inventoryUpdate stock counts when sync is enabled for a connected store.
read_ordersRead order data needed for tracking sync and reconciliation.
Data we access
We keep data while your account is active so imports, mappings, billing, and sync can work. You can disconnect Shopify anytime. You can also request deletion, and we will delete data unless we must keep limited records for legal or billing reasons.
We will list hosting, database, email, billing, and AI providers on the sub-processors page before launch.
We never sell your data.
We never train AI on your store data.
We never create or rewrite products without your action.
We delete your data on request.
We never log Shopify access tokens.