Skip to main content
POST
Receive a mandatory Shopify privacy webhook

Authorizations

X-Shopify-Hmac-Sha256
string
header
required

Base64 SHA-256 HMAC over the untouched request body.

Headers

X-Shopify-Shop-Domain
string
required
Pattern: ^[a-z0-9][a-z0-9-]*\.myshopify\.com$
X-Shopify-Topic
enum<string>
required
Available options:
customers/data_request,
customers/redact,
shop/redact
X-Shopify-Webhook-Id
string
required
Required string length: 1 - 200

Body

application/json
shop_id
integer<int64>
required
Required range: x >= 1
shop_domain
string
customer
object
orders_to_redact
integer<int64>[]
Maximum array length: 10000
orders_requested
integer<int64>[]
Maximum array length: 10000

Response

The privacy request is durably queued or is an identical replay.