Clarification on 2.2.1 / 2.2.2 for an embedded app that reads no Shopify data

Building a public embedded marketing app. Confirming the architecture before we build.

Data flow:

The app reads no Shopify customer, order, or product data, and requests no read_customers scope.

The merchant connects an external service they already use, with their own credentials.

No Shopify-derived data is transmitted to that service or any third party.

Shopify-side functionality planned:

Results written into Shopify via marketingEngagementCreate so activity appears in the merchant’s Growth tab.

A Shopify Flow trigger using custom fields only, no reference fields, so merchants can wire our events into their own workflows.

Embedded surface: connection setup and configuration, job configuration, live status and progress, and results. Deeper configuration remains in our external dashboard, consistent with the pattern in “Integrating with the Shopify admin” for cross-platform SaaS.

Questions:

1- Since the app reads no Merchant Data from Shopify, we understand API Terms 2.3.19 does not apply. Please confirm.
2- Is the combination above sufficient under 2.2.1 and 2.2.2, or would App Review consider it a thin shell given the core workflow originates outside Shopify?
3- If not sufficient, what specifically would we need to add? We could build a customer_reference Flow trigger or a marketing automations trigger, but both require read_customers and move us into protected customer data review. We’d rather not request customer data we don’t otherwise need. Is that scope what review would expect here?

Billing, confirming our understanding: App Store merchants billed through Shopify App Pricing at prices matching our site; existing direct customers who later install stay on current billing.

Hey @Pjexec1 - based on what you’ve described, this sounds aligned with 2.2.1/2.2.2, while deeper workflows can remain external.

You shouldn’t add read_customers solely for review, I’d only request it if the functionality genuinely needs it. For 2.3.19, though, I’d just note that Merchant Data isn’t specifically limited to Shopify-derived data, and you do need to keep external billing completely separate for non-Shopify-sourced merchants (and vice-versa, Shopify-sourced merchants should use Shopify Billing: About billing for your app). If you do have existing customers who add the Shopify app later, we do offer exceptions to our billing policies, but this is on a case by case basis.

I can’t confirm exactly how App Review will rule before submission, so I’d also just recommend to document these flows clearly in your review notes and screencast.

Hope this helps/makes sense - let me know if I can clarify anything more on our end here.

Thanks Alan, that’s helpful. One follow-up on 2.3.19.

Understood that Merchant Data isn’t limited to Shopify-derived data. In our case the merchant connects an external service they already use and pay for, with their own credentials, and we act on their data inside their own account there. Nothing is shared with any party the merchant isn’t already a customer of.

Does operating on a merchant’s data inside the merchant’s own account at a service they already use constitute “providing Merchant Data to a third party” under 2.3.19, or is the third-party test about disclosure to a party outside that existing relationship?

Also noted on billing. What’s the process for requesting the exception for existing customers, and is it best raised before submission or during review?

Hey @Pjexec1, happy to clarify. A merchant’s existing relationship with the external service doesn’t by itself mean it isn’t a third party. For 2.3.19, the key question is whether the app’s primary purpose involves providing Merchant Data to that service. If the app only acts on data already held there and sends no Merchant Data to the service, that distinction could matter. Hope this makes sense!

On billing, existing direct customers who connect an existing account generally don’t need to change billing (though approval of an exception is still up to our App Review team). New merchants acquired through the Shopify App Store need to use Shopify Billing. Any broader exemption request should be included at the top of the submission’s Test Instructions for review.

Could you share:

  • The app ID and external service
  • Exactly what, if anything, the app sends to that service
  • How you distinguish existing customers from new Shopify-sourced customers

I’m happy to set up a DM if you’d prefer to share privately. I can’t guarantee what App Review would decide, but I can reach out on our end and see if there’s anything more specific we can share once I have that context.

Thanks Alan, that distinction is exactly what I was trying to pin down. A DM would be great, I’ll share the specifics there. No app ID yet, we’re confirming architecture before building.

For sure - sending you a DM @Pjexec1 !