- Short answer
- No — Shopify gives you the erasure tools and notifies your apps, but you generally stay the controller who must answer the customer.
- Shopify's role
- Processor: it follows your instructions rather than deciding, which is why the deadline is yours and not its.
- Deadline
- One month from receipt under GDPR Article 12(3), extendable by two further months where necessary.
- The 72-hour rule
- No official page we read states a 72-hour deadline to confirm a request; 72 hours is the breach rule.
- What the button leaves
- Name and address go; the sale and its date stay, and Shop or Shop Pay data is untouched.
- Apps and other companies
- Shopify notifies installed apps after 10 days or six months; contacting other companies you shared data with is yours.
- When deletion is blocked
- Shopify's Manage customers page lists four conditions blocking deletion, orders among them; erasing personal data is the separate route.
- Scope
- The EU GDPR text and Shopify's own documentation; other privacy regimes are not inventoried here.
- As of
- Shopify Help Center, shopify.dev and the GDPR text read August 31, 2026; admin limits rechecked September 1, 2026.
Who has to answer the customer, you or Shopify?
You do, and Shopify says so itself. Its GDPR page, read August 31, 2026, splits the two roles before any tool is opened.
You're generally the controller of your customers' data.
That word — generally — is Shopify's hedge, not ours: the page stops short of an unconditional rule. The other half of the same page describes the processor side: when Shopify acts as a processor for your customers' data, it follows your instructions on how to handle that data. That is an actor waiting to be told, not one deciding on its own.
Everything below follows from that split. The deadline runs against you, and the next two sections cover the two mechanics that split produces: a button you press, and a webhook Shopify sends to your installed apps on its own schedule.
What the erasure button in your admin actually removes
The admin has a purpose-built request, and it removes less than most merchants expect. From your Shopify admin you click Customers, open the customer profile, then More actions > Erase personal data.
| Data | What an erasure request does to it |
|---|---|
| Customer name and address | Erased — Shopify states it erases personal data such as your customer's name and address. |
| What was sold, and the date and time of the sale | Still visible in your admin after the erasure. |
| Data from the customer's relationship with Shop and Shop Pay | Not erased — the request does not reach it. |
Three things the table does not show. Erasing a customer's personal data is not the same operation as deleting a customer profile, which has its own blocking conditions further down this page. The request is also reversible for a short while: after you submit it, you have 10 days to cancel.
The third is a caution Shopify flags: for a customer with active pre-authorized payments such as pre-orders or subscriptions, the remaining payments aren't charged and subscription contracts are canceled, and you incur a loss on those partial sales if the customer doesn't pay the remaining amount before the erasure request is submitted.
Whether a customer profile you delete outright can ever be brought back is a different question, and our store-backup guide answers it in one section.
Installed apps get notified; everyone else you shared the data with is on you
Copies of the same customer sit outside Shopify, and the admin request does not travel to them by itself. For installed apps there is a mechanism, documented for developers rather than for you.
Store owners can request that data is deleted on behalf of a customer. When this happens, Shopify sends a payload on the customers/redact topic to the apps installed on that store.
Read that as notification, not proof, and not an immediate one: Shopify sends the payload 10 days after you submit the deletion request if the customer hasn't placed an order in the past six months, and otherwise withholds it until six months have passed. Shopify then tells the developer to complete the action within 30 days of receiving the request, and what the app does with it happens on the app's side.
A second topic, customers/data_request, fires when a customer asks for a copy of their data instead — a different request with a different webhook. Which data an app can hold in the first place is its own answer.
Everything else is manual. Shopify states plainly that it is your responsibility to contact any other companies that you have shared the customer's personal data with — your email platform, your accountant, the spreadsheet someone exported last quarter. GDPR Article 19 says the same thing from the legal side: the controller communicates the erasure to each recipient the data was disclosed to, unless that proves impossible or takes disproportionate effort.
How long you actually have to respond
The deadline that counts is the legal one, and it starts the day the request reaches you rather than the day you open the admin. Shopify's own numbers each have a different owner, and one of them can run past that deadline.
When deleting the profile is blocked — and what you erase instead
Sometimes the honest reply is that the profile stays. Shopify blocks deleting a customer under four conditions, read in full on September 1, 2026:
- The customer has pending redaction because of a GDPR erasure request.
- The customer is the recipient of a scheduled gift card that hasn't been delivered yet.
- The customer has ever had a subscription.
- The customer is associated with one or more orders.
The last one covers almost every real customer, which is why erasing personal data is the route that actually runs. The law expects that outcome: GDPR Article 17(3) disapplies erasure to the extent that processing is necessary for compliance with a legal obligation which requires processing by Union or Member State law to which you are subject, and to the extent that it is necessary for the establishment, exercise or defence of legal claims.
How many years those records must be kept is not something to look for in the Regulation. The full GDPR text we read on August 31, 2026 names no number of years for accounting or tax records; that period comes from national law, and this page does not inventory it.
One reply covers most cases: erase the personal data from the profile, contact every other company you sent that data to, and answer the customer inside the month, saying which records stay and why.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy