Key Takeaways
- Erasing a customer in Shopify redacts their name and address but leaves the order history in your admin — and touches none of the other apps holding their data. Shopify says so plainly: "It's your responsibility to contact any other companies that you've shared the customer's personal data with."
- Under Article 19 of the GDPR, you must communicate an erasure "to each recipient to whom the personal data have been disclosed" — and the ICO confirms a recipient includes every processor, so each connected app counts.
- The customer's data is scattered: a typical Shopify store also runs email/SMS marketing, a helpdesk, reviews, loyalty, subscriptions, analytics, and ad pixels — each with its own deletion mechanics and its own delay.
- Wiring Shopify's customers/redact webhook does not close the loop. It obligates only the app developers who subscribe to it, gives you no verification, and — since a change on May 31, 2025 — a partner-initiated erasure can no longer be cancelled by the merchant at all.
- You have one month to answer an erasure request (Article 12(3)), but the deletion jobs behind it run on their own clocks: Google Analytics 4 takes between 7 and 63 days. Start the moment the request lands.
Introduction
The erasure request lands in your support inbox on a Tuesday: "Please delete all personal data you hold about me." You open Shopify, find the customer, click Erase personal data, and mark the ticket resolved. Thirty seconds, done. Except it isn't. That customer's email is still in Klaviyo, their behaviour is still in Google Analytics, their address may still be in your 3PL's portal, and their profile is still feeding your Meta ad audiences. You have answered the letter of the request in one system and missed it in a dozen others. This guide maps where the data actually goes, what GDPR actually requires you to reach, and how to run a complete erasure across a real eCommerce stack. It builds on our complete guide to GDPR compliance in 2026. This is informational content, not legal advice.
Why Deleting a Customer in Shopify Isn't Enough
Erasing a customer in Shopify only clears the data Shopify holds. Shopify redacts personal fields such as name and address but, in its own words, "the customer profile and order history remain in your admin," and it tells you directly: "It's your responsibility to contact any other companies that you've shared the customer's personal data with." Everything downstream is on you.
That is not a Shopify shortcoming — it is a description of how modern eCommerce works. Your store is the hub, but the customer's personal data has been copied outward to every tool you connected to grow the business. Each of those tools received the data as a separate system with its own database, its own retention settings, and its own deletion process. Erasing the copy in the hub does nothing to the copies at the edges.
Erase, delete, redact — three different buttons
Shopify offers two actions that sound identical and are not. Erasing a customer's personal data redacts the PII but keeps the profile and order history; deleting the customer profile removes the whole record. Erasure is the GDPR-shaped action, because it preserves the transaction facts you may be legally required to keep (invoices, tax records) while removing the personal detail — the same balance we cover in our guide to how long to keep customer data. After you submit an erasure, you have 10 days to cancel it before it completes, so it is reversible right up to the deadline.
What GDPR Actually Requires: Article 17 Meets Article 19
Article 17 gives the right; Article 19 is the part stores forget. Article 17(1) lets a customer demand erasure when their data is "no longer necessary" for its original purpose or when they withdraw consent. But Article 19 governs the reach: you must communicate the erasure "to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort."
The word doing the work is recipient. The ICO defines it broadly — "controllers, processors and persons who, under the direct authority of the controller or processor, are authorised to process personal data." Your email platform, your helpdesk, your analytics provider: each is a processor, each is a recipient, and each is therefore in scope of the erasure you owe. A separate obligation, Article 17(2) and Recital 66, adds a make-it-public layer — if you published the data, you must take "reasonable steps" to tell other controllers to erase their copies too.
There is a matching duty on the tools themselves. Under Article 28(3)(g), a processor must, "at the choice of the controller, delete or return all the personal data" when you tell it to. In practice that means the deletion capability exists in every compliant vendor — you just have to trigger it, tool by tool. The "disproportionate effort" escape hatch in Article 19 is real but narrow; "we have a lot of apps" is not disproportionate effort, it is a data map you have not built yet.
The clock you are actually racing
You have one month to act on an erasure request under Article 12(3), extendable by two further months only for genuinely complex or numerous requests. That is the deadline the customer sees. Behind it sit slower, independent clocks inside each tool — which is why the work starts the day the request arrives, not the day before the month is up.
Where Your Customer's Data Actually Lives
Map a single customer across a normal Shopify stack and the sprawl is obvious. The data was copied to each of these categories the moment you installed the app:
- Email and SMS marketing (Klaviyo, Mailchimp, Shopify Email) — profile, engagement history, and consent state.
- Helpdesk and support (Gorgias, Zendesk) — names, emails, and the full text of past conversations.
- Reviews and UGC (Yotpo, Judge.me) — names and review content, often public.
- Loyalty and subscriptions (Smile.io, Recharge) — identity linked to points balances and recurring billing.
- Analytics (Google Analytics 4) — behavioural data tied to a user identifier.
- Advertising (Meta pixel and Conversions API, Google Ads) — customer-list audiences built from your data.
Not every app holds erasure-relevant personal data, and part of the job is knowing which do — that is what a record of processing activities is for. If your list of "who has this customer's data" lives only in your memory, the erasure will be as complete as your memory is on a busy Tuesday.
The customers/redact Webhook: What It Does and Doesn't Do
Shopify's compliance webhooks help app developers, not merchants completing a request. Every app in the Shopify App Store must subscribe to three mandatory topics — customers/data_request, customers/redact, and shop/redact — and on receiving one, the developer must "complete the action within 30 days," unless legally required to retain the data. It is a genuine, useful backbone.
But read the scope carefully, because it is narrower than it feels. The webhook obligates only the apps that both subscribe to it and receive the erasure signal from Shopify's flow; it hands you no confirmation that Klaviyo or Yotpo actually purged anything, and it does not reach tools you connected outside the App Store (a raw pixel, a custom integration, a spreadsheet export). Since a Shopify change on May 31, 2025, an erasure request initiated by a partner "cannot be cancelled by merchants in the admin" — only the initiator can cancel it, which tightens the process but also underlines that the webhook is a developer-to-developer mechanism you are standing next to, not driving.
The trap is treating the webhook as the whole answer. Wiring it satisfies an app developer's obligation; it does not satisfy yours as the controller under Article 19. Those are two different duties on two different parties, and only one of them has the customer's letter in hand.
How Each Tool Actually Deletes: A Reality Check
The mechanics differ per tool, which is exactly why a single "delete" button was never going to exist. A few concrete examples from the vendors' own documentation:
| Tool | How erasure works | What to know |
|---|---|---|
| Shopify | Admin "Erase personal data" redacts PII | Order history stays; 10-day cancel window |
| Klaviyo | Manual "Delete Profile" in Klaviyo, separate from Shopify | Data replaced with "redacted"; not triggered by the Shopify erase |
| Google Analytics 4 | Data-deletion request in the GA admin | Takes 7 to 63 days; data must be over 12 days old; 7-day grace to cancel |
| Meta (custom audiences) | Delete the uploaded custom audience | Removed immediately across shared ad accounts; not a per-person endpoint |
The GA4 line is the one that catches stores out. A Google Analytics 4 deletion request "can take between 7 and 63 days to be processed," and data "must be more than 12 days old before it can be deleted." (Ignore the "72 hours" figure that circulates on blogs — it is not in Google's documentation.) Meta is the other trap: you can delete an uploaded customer-list audience, but there is no verified per-individual erasure endpoint for data ingested through the Conversions API, so removing someone often means rebuilding audiences from a cleaned source list rather than deleting one row.
Even a clean, instant deletion has a tail. The ICO acknowledges erasure "can be instantly fulfilled in respect of live systems, but ... the data will remain within the backup environment for a certain period of time until it is overwritten" — the standard there is to put the backup data "beyond use," not to restore-and-scrub every archive.
A Practical Cross-App Erasure Checklist
Run the same sequence every time, and the one-month deadline stops being a scramble:
- Log the request and start the clock. Record the date received; your Article 12(3) month runs from there.
- Verify identity before deleting anything — erasing the wrong person is itself a breach.
- Erase in Shopify (the "Erase personal data" action, not just "delete profile" if you need the order record for tax).
- Work down your app list, tool by tool: email/SMS, helpdesk, reviews, loyalty, subscriptions, analytics, ad platforms. Trigger each vendor's own deletion.
- Handle the slow ones first. Submit the GA4 request early — 7 to 63 days can outrun a lazy start.
- Record what you did. Note each system erased and the date, so you can evidence compliance if a regulator or the customer asks.
- Confirm to the customer within the month, naming the categories of recipient you contacted.
For a store handling more than a handful of these a month, running it by hand from a checklist is how apps get missed. Automating the intake, the routing, and the audit trail is the point at which this stops being a personal reliability project — the same argument we make for automating data subject requests generally.
Common Mistakes, Worst First
The single most expensive mistake is believing the Shopify erase was the whole job. It is the most common and the least visible: the ticket looks closed, the data lives on, and nobody notices until the customer files a complaint or you go looking. Every other mistake is a variation of it.
- Trusting the webhook as proof. The customers/redact webhook obligates developers; it does not confirm deletion to you. Absence of an error is not evidence of erasure.
- Forgetting the tools outside the App Store. Raw pixels, custom API integrations, CSV exports on someone's laptop, and your data warehouse never got the memo.
- Deleting what you must keep. Over-eager erasure that wipes an invoice inside its statutory retention window trades a GDPR problem for a tax one — erasure does not override a legal retention duty.
- No record of what you erased. Accountability is an obligation, not a nicety; "we think we deleted it everywhere" is not a defensible answer to a supervisory authority.
How PrivacyForge Helps
A complete cross-app erasure needs two things a checklist alone cannot give you: a current map of which systems hold a given customer's data, and a durable record that you erased them everywhere. PrivacyForge's data-mapping and record-of-processing tools keep the inventory of processors current, so "who has this person's data" is a lookup, not a memory test. Its DSAR workflow logs each erasure request, tracks the response against the one-month deadline, and captures an audit trail of what was actioned and when. The tools' own deletion buttons still do the deleting — PrivacyForge makes sure none of them get skipped and that you can prove it later.
Frequently Asked Questions
Does erasing a customer in Shopify delete their data everywhere?
No. Erasing a customer in Shopify redacts personal data such as name and address within Shopify, but the order history stays and no connected app is touched. Shopify states it is your responsibility to contact any other company you shared the data with. You must trigger deletion separately in each tool, such as Klaviyo, your helpdesk, and analytics.
What is the difference between "erase personal data" and "delete customer" in Shopify?
Erasing a customer's personal data redacts the PII (name, address) but keeps the customer profile and order history in your admin — useful when you must retain the transaction for tax. Deleting the customer profile removes the entire record. For GDPR erasure that must respect legal retention, the erase action is usually the correct one.
Does Shopify's customers/redact webhook make me GDPR compliant?
No. The customers/redact webhook obligates App Store developers to delete their copy of the data within 30 days, but it gives you no confirmation, does not reach tools connected outside the App Store, and does not satisfy your own duty as controller under Article 19 to inform every recipient. It is a developer mechanism running alongside your obligation, not a substitute for it.
How long do I have to complete a GDPR erasure request?
Under Article 12(3), you must respond without undue delay and within one month of receiving the request, extendable by two further months only for complex or numerous requests. Start immediately: some tools are slow — a Google Analytics 4 deletion request can take between 7 and 63 days to process.
Do I have to delete a customer from Google Analytics and my ad platforms?
Yes, where they hold that customer's personal data. GA4 offers a data-deletion request that takes 7 to 63 days and requires data to be over 12 days old. Meta lets you delete uploaded custom-audience lists but has no verified per-individual erasure endpoint, so you often rebuild audiences from a cleaned source list instead.
Conclusion
The right to erasure is not a button; it is a route through your stack. The store that treats it as one click in Shopify is the store that, months later, discovers the customer it "deleted" still receiving its emails. Build the map of where customer data actually goes, run the same erasure sequence every time, start the slow jobs early, and keep a record you could hand a regulator. Do that and a "delete everything about me" request becomes a routine task instead of a quiet liability. If you want the map and the audit trail handled for you, see how PrivacyForge automates data subject requests.
Sources
- GDPR Article 17 — Right to erasure — grounds for erasure; Article 17(2) reasonable steps to inform other controllers (primary, statute)
- GDPR Article 19 — Notification obligation — communicate erasure "to each recipient to whom the personal data have been disclosed"
- GDPR Article 28 — Processor — Article 28(3)(g): processor deletes or returns data at the controller's choice
- GDPR Article 12 — Transparent information and modalities — one-month response deadline, extendable by two months
- GDPR Recital 66 — Right to be forgotten — obligation to inform other controllers about copies and replications
- Shopify Help Center: Processing customer data requests — erase vs delete; PII redacted, order history kept; "contact any other companies"; 10-day cancel
- Shopify dev docs: Privacy law compliance — mandatory customers/data_request, customers/redact, shop/redact webhooks; 30-day developer window
- Shopify changelog: Standardized Customer Data Erasure for Third-Party Apps — May 31, 2025; partner-initiated erasures not cancellable by merchants
- Klaviyo Help Center: Delete a profile — manual deletion, separate from Shopify; "redacted" replacement
- Google Analytics Help: Data-deletion requests — 7 to 63 days; data must be over 12 days old
- Meta Business Help Center: Delete a custom audience — deletion removes the audience immediately across shared ad accounts
- ICO: Right to erasure — must contact each recipient; recipient includes processors; backup "beyond use"
- Shopify Community: Delete personal data request — merchant erasure-across-apps confusion, June 1, 2026 (demand)