I run an app on the Shopify App Store and I’m looking for guidance on escalating a review-violation report.
One of our recent reviews makes a specific and demonstrably false security claim about the app, alleging it installs malicious code and collects private data covertly. None of that is accurate as we are not request such access as a part of app installation. The app is listed and passed Shopify’s app review, and our data handling is limited to getting the store URL and contact information what’s disclosed in our privacy policy. We can back all of this up with our codebase, app-review status, and documentation.
Steps we’ve already taken, in line with the process:
Submitted a report through the partner violation form multiple times and recent one today 16th June 2026.
Opened multiple tickets via Partner support case from part few months under #63862310, #64002300, and #64068856. The recent one is #68119999.
Tried reaching to merchant mutiple times but there has been no response.
I’ve also read the existing threads on policy-violating reviews (the “are reports being monitored” and “tackling fake app reviews” discussions), so I understand the governance queue is busy and outcomes aren’t shared publicly.
My questions:
Is there anything further we can provide up front to help the investigation, given this is a false factual claim rather than a subjective complaint?
Is there a way to have a review containing a false security or malware allegation prioritized, since the reputational harm is ongoing while it stays live?
Roughly what timeline should we expect for a manual review right now?
Happy to share the listing URL and additional details to staff members or anyone who can help us point to the right direction. Thanks for any pointers.
Thanks for laying this out. For this kind of review concern, the best path is still the existing Partner Support / Partner Governance case rather than opening new duplicate reports.
I can’t confirm the outcome or provide a timeline publicly, and we’re not able to adjudicate the substance of an individual review here in the forum. That said, making the security/malware allegation clear in the ticket context is helpful so the right team has the full picture.
I definitely realize it’s not an ideal situation, so I’ll also pass along your feedback here that public security allegations on app listings feel especially time-sensitive from a Partner reputation standpoint. Let me know if I can clarify anything on our end here.
Thank you for the reply. I completely understand that you cannot adjudicate or share outcomes publicly here in the forum.
The core issue driving me to the community team is that we are not getting updates or transparency privately either. In our live support chats, the agents explicitly agreed that this specific review qualifies for removal due to the false security allegations, yet the ticket remains stagnant.
While the queue processes background requests, this live review is actively deterring merchants from installing a verified, secure app by falsely claiming it contains malware. The reputation and commercial damage is compounding daily.
Since the ticket context already clearly outlines the security falsehoods, could you please use your internal channels to escalate our latest ticket (#68119999) directly to the Partner Governance team for a priority human review? Any movement or private update on that specific case would be incredibly appreciated.
Hey @Ishan_Makkar, I really understand where you’re coming from. It’s not ideal that it takes a while to have these sorts of issues investigated, especially when it’s having an effect on how potential users perceive your app/services.
The best spot to reach out to about your particular case is still the ticket you have open with our Partner Governance team.
That said, we are making improvements into how we handle these types of reviews:
I still can’t guarantee what these improvements will look like or when they’ll be implemented, but I did want to mention this since it’s something on our radar. I know that doesn’t make the process feel any better, but I just wanted to be as open as possible about what I can confirm.
I hope this gives a bit more context at least. I understand this isn’t the best situation, and we are aware of the issue on our side.
For a review that makes a demonstrably false security or data-handling claim, the path that has worked for other app builders is to go through Partner Support with documentation, not through the in-listing “report review” flow. The in-listing flow goes to a content-moderation queue that mostly looks for banned words; security claims need the App Trust / Privacy team to validate.
Specifically what to attach:
Your app’s data-access scopes as a screenshot from the OAuth install screen. This is the canonical record of what your app actually requests at install time and it is impossible to argue with.
Your privacy policy URL and the relevant section (data collection / data handling).
The result from your most recent BFS / app review pass if you have it - that’s a Shopify-internal validation that your app handles data within policy.
The specific text of the review and the specific claim that is factually wrong.
If you have analytics / logs that prove the app doesn’t make the network calls the reviewer alleges, attach a small redacted snippet.
Frame it as a Trust & Safety violation by the reviewer, not as a content dispute. Shopify’s App Store policy explicitly prohibits reviews that contain false statements of fact about the app, and a fabricated security claim is the textbook case.
One thing worth noting: even when these get removed, the review timeline shows “this review has been deleted” rather than the review disappearing, and the response thread (if you replied to it) is what most subsequent merchants will see. If you haven’t replied to the review yet, a measured, factual reply citing your scopes and policy URL is the cheapest defense for everyone reading it in the meantime. Don’t argue tone, just state what your app does and doesn’t do, then link the privacy policy.
The escalation form (not the community “report review” flow) lives under Partner Support → “Report a Listing or Review” → “Inaccurate or misleading review”. That gets it to the right team rather than the general queue.
I wanted to follow up as it has been two weeks since our last update. Based on advice from the developer community regarding false security/data-handling claims, I have updated our active ticket #68119999 with concrete, technical proof.
I have attached our exact OAuth data-access scopes, our strict privacy policy parameters, and a factual breakdown proving the reviewer’s security claims are technically impossible based on how app operates.
Could you please ensure this is specifically routed to the App Trust / Privacy / Governance Team rather than the general content moderation queue?
They are the only team equipped to validate that this is a textbook Trust & Safety policy violation.
We can’t comment on governance cases on the public developer forum - this channel is strictly for technical troubleshooting. The only way to connect with the governance team is via direct support, which it sounds like you’ve done.
Whenever you reach out to direct support, you get an update that investigation in going on and ticket is closed. Like it happened yesterday when I reached out to them.
Is there any other door I can knock on? Or is it the case where we just keep waiting and forget it.
I hope you understand how frustrating and time consuming all this is.
Hi @Ishan_Makkar I experienced this in the past, a very frustrated merchant, not just with our app but with the whole shopify thing and they were leaving bad reviews to many app, and I found they were also sending a lot of bad message on the Shopify forum to tell how terrible are apps on Shopify.
I reported it to the shopify support with proof they’re overall very frustrated, and the review got removed even before it was published, but I think it’s mostly because they left many frustrated reviews on many apps, and publicly on the forum. I think it might have been different if they only left a review on the app.
That being said, you can visit the thread where we complain about Shopify not handling fake review, which is something slightly different but essentially is the same core issue that Shopify is not doing a great job at ensuring quality of reviews. It’s right here: Is Shopify actually addressing the fake review problem?
Any voice that adds up there will increase the chances that Shopify actually does something!
I do not see anything new unless there is any action being taken in the coming weeks as the suggested in the response by @Luke and Shopify’s own post on Strengthening trust in App Store reviews by @jzaz .