We’re updating how customer personally identifiable information (PII) appears in web pixel events. Starting on December 10th, 2025, apps will only receive PII in pixel payloads if they are approved for Shopify’s Protected Customer Data access scopes. Apps without approval will continue to receive events, but PII fields will be null. Event structure remains the same.
What’s changing
-
Runtime filtering applies across storefront, checkout, and customer accounts
-
Gated fields include name, email, phone, and address
-
Custom pixels are out of scope for this change
Protected scopes enforced
-
read_customer_name
-
read_customer_email
-
read_customer_phone
-
read_customer_address
-
read_customer_personal_data
What you need to do
-
Review scopes: Confirm you have approval for any protected scopes your app needs.
-
Handle nulls: Update code paths and analytics pipelines to gracefully handle null values for gated fields.
-
Test surfaces: Verify behavior on storefront, checkout, and customer accounts.
If you require access to this data, follow the steps outlined in the Protected Customer Data documentation to request access for your app.
FAQ
Q: Will my app stop receiving events?
A: No. Events still fire. Gated fields are set to null when not approved.
Q: Which pixels are affected?
A: App web pixel extensions. Custom pixels are not in scope.
Q: Does this affect server pixels?
A: Not in this phase.
Q: What happens if we apply for scopes later?
A: Once approved, gated fields will populate automatically on subsequent events.
Q: How long does the Protected Customer Data approval process take?
A: We can’t offer a specific time frame, but we recommend submitting your request as soon as possible to ensure you have the permissions you need before changes start happening on December 10th.
Q: What if I don’t finish the approval process before December?
A: Your app will continue functioning normally, but PII fields will be null until approval is granted. Once approved, data will flow automatically with no code changes needed.
Q: What happens to analytics data I’ve already collected?
A: Historical data is unaffected. This only applies to new events after this change takes effect starting on December 10th, 2025. Cross-device attribution may be impacted if it relies on email or phone number to match customers.
Q: Is there a way to know if my app is already approved?
A: Check your app’s settings in the Partner Dashboard.
Thank you for helping keep customer data safe and compliant.