GDPR Webhook
Background
Across multiple jurisdictions globally, individuals hold legal rights regarding how their personal data is collected, stored, and utilized. The General Data Protection Regulation (GDPR) establishes legal requirements for businesses that collect, store, or process the personal data of European residents. If your app handles the personal data of European residents, you must comply with the following legal requirements under the GDPR:
-
Under the GDPR, European residents have the legal right to access, rectify, and erase their personal data, as well as restrict its processing. Consequently, your app must implement workflows to receive and respond to these data processing requests effectively.
-
Transferring the personal data of European residents outside of Europe requires compliant data protection measures in line with GDPR standards. When designing your app architecture, you must ensure that at least one of the following conditions is satisfied:
- The data recipient is located in a country or territory granted an adequacy decision by the European Commission under GDPR.
- The enterprise owning your app has signed Standard Contractual Clauses (SCCs) with the data recipient to guarantee data protection.
- Your app has publicly committed to adhering to recognized compliance mechanisms, such as the EU-U.S. Data Privacy Framework.
-
If your app involves the large-scale processing of personal data, the GDPR mandates that your organization must appoint a Data Protection Officer (DPO) to oversee and monitor the compliance of all data processing activities.
SHOPLINE app compliance requirements
To ensure data security and privacy compliance, SHOPLINE enforces the following mandatory requirements for all apps:
- All user data collected by apps listed on the SHOPLINE App Store is subject to mandatory GDPR data standards, regardless of whether the users are located in Europe. Therefore, any app listed on the SHOPLINE App Store must comply with GDPR regulations, even if it does not currently collect personal data.
- SHOPLINE provides mandatory webhooks to help you manage the user data collected by your app. If you do not provide callback URLs for these webhooks, or if your app fails to respond to webhook requests as required, your app listing will be rejected. You must resolve all identified compliance issues before resubmitting your app for listing review.
When your app receives a mandatory webhook request, your app must perform the following actions:
- Acknowledge receipt: Immediately return an HTTP
200status code to confirm that your app has successfully received the request. - Data deletion deadline: Complete the data deletion within 30 days of receiving the request. You must complete the deletion unless applicable law explicitly requires you to retain the relevant data.
How to integrate mandatory webhooks
To allow SHOPLINE to assist in managing user data collected by your app, public apps listed on the SHOPLINE App Store must subscribe to the following webhook events. Additionally, the callback URLs for receiving these webhooks must use the HTTPS protocol. Custom apps are not required to subscribe to these webhook events.
| Event | Event identifier |
|---|---|
| Customer data deleted | customers/redact |
| Store data deleted | merchants/redact |
Customer data deleted
This webhook is used to notify your app to delete a customer's personal data from your database. For more information about this webhook, refer to Customer data deleted (GDPR compliance).
- Trigger condition: SHOPLINE automatically triggers this webhook when a merchant initiates a data deletion request on behalf of a customer, provided that your app already has permission to access the customer data of the corresponding store.
- Payload description: The request body of this webhook contains the ID of the customer whose data needs to be deleted. Upon receiving this request, your app must erase that customer's personal data from your database.
- Callback URL configuration: Refer to Configuration method.
Store data deleted
This webhook is used to notify your app to delete all relevant store data from your database. For more information about this webhook, refer to Store data deleted (GDPR compliance).
- Trigger condition: SHOPLINE automatically triggers this webhook 48 hours after a merchant uninstalls your app.
- Payload description: The webhook request body contains the
store_idandstore_domainparameters. Upon receiving this request, your app must delete all data related to the corresponding store from your database. - Callback URL configuration: Refer to Configuration method.
Configuration method
Perform the following steps to configure the callback URLs for the mandatory webhooks so that SHOPLINE can push data processing requests to your app:
-
Log in to the Partner Portal.
-
Click Apps in the left navigation bar. Then, select the app that needs to be submitted for SHOPLINE App Store listing review to go to the app overview page.

-
Click App Settings to go to the app settings page.

-
In the GDPR Required Webhooks section, enter the respective callback URLs in the Deleted endpoint of customer data and Deleted endpoint of store data fields (the protocol must be HTTPS). Then, click Save.
