Should You Build or Buy Protected Customer Data Access on Plus?
Building the custom app wins on Plus when the workflow is yours: a warranty registry, fraud queue or loyalty rule no certified app sells. No app grants protected customer data access to another app. Shopify grants it per app, and custom apps skip the review public apps undergo (verified Sep 2026). Shopify's Plus plan page lists unlimited custom-app access to that data. Budget $25,000 to $75,000 (Deploi estimate, illustrative); buy a certified app that fits.
Your profile — see how the verdict shifts
- Confidence
- Medium — Checked apps.shopify.com/categories/store-management-security on 2026-09-05: 12 apps covering fraud and bot blockers, EU withdrawal, accessibility, B2B locks and GDPR cookie consent, none addressing protected-customer-data access levels; the digital goods and services category likewise. Checked privacy-adjacent vendors in the registry, DataGrail, Comply and Descartes: they automate data subject requests and export screening, not access levels. Protected customer data access is a Shopify-granted scope tied to an individual app's approval rather than a product, so nothing installable grants it to your custom app, which is why the market is empty rather than thin. Shopify's help confirms that listed and unlisted public apps both undergo app review while custom apps are never reviewed, and that App Store apps must complete data subject requests within 30 days. The Plus entitlement wording, unlimited access to custom apps with protected customer data, comes from Shopify's Plus plan page and a single source: every figure verified on that page matched, but the entitlement itself was not cross-checked on a second Shopify page, which is why confidence is Medium rather than High.
- Reference scenario
- $20M–$100M GMV · Shopify Plus · building a warranty, loyalty or fraud-review tool that needs customer name, email, phone and address, not just order data · no certified public app covers the workflow · in-house or agency dev bench · EU and North American customers
- As of
- September 2026
Decision at a Glance
| Your profile | Verdict | Why |
|---|---|---|
| A certified public app already does the workflow (loyalty, helpdesk, subscriptions, reviews) | BUY | Public apps such as Klaviyo, Gorgias or Recharge already operate under Shopify's protected customer data requirements as part of App Store review. Buying one buys the access and the obligations together, and the vendor answers the 30-day data subject requests for its copy of the data. |
| Bespoke workflow on Plus (warranty registry, fraud-review queue, custom loyalty rule) | BUILD | Nothing to buy exists, and Shopify's Plus plan page lists unlimited custom-app access to protected customer data. Build it with the controls a reviewer would have checked, because custom apps skip that review. |
| Bespoke workflow below Plus | CUSTOMIZE | Confirm your plan's custom-app allowance for protected customer data on Shopify's current plan page first. Then let a certified app hold the personal fields and build your logic on order-level data, pulling name or email only where the workflow can't run without them. |
| Regulated or multi-region data (EU customers, health-adjacent or financial products) | BUILD | Shopify stores new European merchants' customer personal data at rest in Europe by default and still relies on international transfers for processing (verified Sep 2026). A certified app's copy lives wherever the vendor puts it; your own app can keep personal fields in-region and log every read. |
What Protected Customer Data Access Actually Drives
| Outcome | Impact | How it works |
|---|---|---|
| Operational efficiency | High | A warranty registry or fraud-review queue that reads customer identity directly removes the spreadsheet where someone pastes names and emails from orders today, and the errors that travel with it. |
| Data & insight | High | Customer identity joined to your own events, in a store you control, is the dataset every later loyalty, retention or risk model is built on; rented, it sits in a vendor's export. |
| Retention & LTV | Medium | A bespoke loyalty or warranty rule that recognizes the customer by identity rather than by order fires on the second purchase, the moment a commodity app's generic rule misses. |
| Customer experience | Medium | Fewer apps holding personal data means fewer permission prompts, fewer exports in the wild and a cleaner answer when a customer asks who has their information. |
Spend ceiling: Size the spend to the workflow, not the access. The access is free and per app; the controls are the cost. If a certified app does the job, its subscription is the ceiling. If not, a $25,000–$75,000 custom app (Deploi estimate, illustrative) is justified only where the joined customer data is a lasting asset rather than a convenience.
What buying enables (top apps)
- + Protected customer data access already granted through Shopify's app review, with the vendor carrying the obligations for its copy
- + Loyalty, helpdesk, subscriptions and messaging workflows live in weeks, with data-protection controls the vendor maintains for every merchant at once
- + Data subject requests completed within Shopify's 30-day window by the vendor for the data it holds (verified Sep 2026)
- + Vendor-absorbed updates whenever Shopify tightens protected-customer-data requirements
What building additionally unlocks
- + A workflow no certified app sells, reading exactly the customer fields it needs and nothing more
- + Customer identity joined to your warranty, fraud or loyalty events in a store you control, queryable without a vendor export
- + Personal data kept in the region the customer lives in, with per-record access logs you can show a regulator
- + One fewer third-party copy of your customer file, and one fewer about page to audit
Find Your Verdict in 3 Questions
Does a certified public app already do the workflow well enough (loyalty, helpdesk, subscriptions, reviews)?
Yes: Your verdict: BUY — the app's protected-customer-data access and obligations come with it; run your process on the vendor's workflow and audit its permissions quarterly.
No: Go to question 2.
Are you on Shopify Plus?
Yes: Go to question 3.
No: Your verdict: CUSTOMIZE — confirm your plan's custom-app allowance for protected customer data on Shopify's current plan page, let a certified app hold the personal fields, and build your logic on order-level data.
Can you run the controls a reviewer would check: encryption at rest, access logging, a retention schedule and 30-day data subject requests?
Yes: Your verdict: BUILD — scope the fields, build the custom app with those controls, and keep the purpose document current ($25,000–$75,000, Deploi estimate, illustrative).
No: Your verdict: CUSTOMIZE — let a certified app hold the personal data and build only the workflow logic on order-level data until the controls exist.
The TCC Scorecard — 12 Dimensions
TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →
| Dimension | Buy | Build | Why |
|---|---|---|---|
| Cost | |||
| Acquisition & implementation | A certified app installs in a day and configures in weeks; a custom app with scoped access, encryption, access logging and retention runs 8–14 weeks (Deploi estimate, illustrative). | ||
| Recurring fees | Certified apps that read customer data price on contacts or orders and never stop billing; the custom app's recurring line is upkeep plus the hosting and logging its controls require. | ||
| Maintenance & upgrades | The vendor absorbs Shopify's scope and API changes on the app path; a custom app tracks protected-customer-data requirement changes itself and bumps API versions inside Shopify's 12-month support window. | ||
| Switching & exit | Leaving a certified app means recovering your customers' data from the vendor's copy and confirming its deletion; a custom app's data model is yours and ports to any future stack. | ||
| Risk | |||
| Vendor risk | Established certified apps are stable vendors; the custom app has no vendor to lose but depends on your team keeping controls alive after the launch excitement fades. | ||
| Security & compliance surface | A public app passed Shopify's review and carries its own obligations; a custom app skips review, so encryption, access logs, retention and 30-day data subject requests are yours to prove (verified Sep 2026). | ||
| Platform-deprecation exposure | Protected customer data requirements have tightened over time and a custom app absorbs each change directly; a certified vendor absorbs them for every merchant at once. | ||
| Value | |||
| Fit to requirement | A certified app fits its own workflow, not your warranty registry or fraud queue; the custom app reads exactly the fields your process needs and nothing else. | ||
| Time to market | Weeks against a quarter, and the build's calendar includes writing the controls, not just the features. | ||
| Performance & scale | A custom app on Plus works against a 1,000 points-per-second GraphQL Admin API limit, ten times the standard 100 (verified Sep 2026), while a public app shares whatever budget its vendor architected. | ||
| Data ownership & AI-readiness | The decisive dimension: customer identity joined to your warranty, fraud or loyalty events stays in a store you control, queryable without a vendor export. | ||
| Focus & opportunity cost | Running data-protection controls is real ongoing work; fund it only where the workflow is a competitive asset rather than a commodity a certified app already ships. | ||
The App Landscape
| App | Status | Pricing | Best for |
|---|---|---|---|
| Certified public apps that already read customer data (Klaviyo, Gorgias, Recharge) | Category — Listed and unlisted public apps both undergo Shopify's app review and can be installed from the App Store (verified Sep 2026). Apps in this class read customer name, email, phone and address as part of their normal job and operate under Shopify's protected customer data requirements through that review. Buying one is buying the access and its obligations together, for the workflow the app ships and nothing else. | Varies by app and tier; verify on each listing | Loyalty, helpdesk, subscriptions, reviews and messaging, where the workflow is a commodity and the vendor carries the data obligations |
| Shopify app permissions and activity review | Native — First-party Shopify. At install, each app declares the personal data it can view, such as customers, store owner and blog contributors, and the store data it can view and edit; after install you can review its activity and permissions from the app's about page. There is no consolidated cross-app permissions view, so a quarterly audit is a manual pass through each app (verified Sep 2026). | Included on every plan (verified Sep 2026) | Knowing which installed apps already read customer personal data before you add another |
| Privacy and data-subject-request tools (DataGrail, Comply, Descartes) | Category — Automate data subject requests and export-compliance screening. None addresses which apps may read protected customer data or at what level, so the category is adjacent to your privacy program and not to this decision. Named here so the search ends sooner. | Not priced here; adjacent category | Fulfilling deletion and access requests across systems once the access decision is made |
| Custom app with protected customer data access | Build lane — Custom apps don't undergo Shopify's app review, so the data-handling controls a reviewer would check are yours to run and document. Shopify's Plus plan page lists unlimited access to custom apps with protected customer data among Plus entitlements; that wording comes from a single Shopify page, so confirm it on the current plan-features page before budgeting. Plus itself is Level 1 PCI DSS and SOC2 certified on Shopify's side (verified Sep 2026); your app's controls are separate. | $25,000–$75,000 to build with scoped access, encryption, access logging, retention and data-subject-request handling (Deploi estimate, illustrative) | A warranty registry, fraud-review queue or loyalty rule that no certified app sells and that needs customer identity, not just order data |
The Build Path
- Minimize before you request: List the personal fields the workflow can't run without, usually a subset of name, email, phone and address, and build the rest on order-level data. Request only those scopes and write down the purpose for each, because that document is what a reviewer would have asked for and what a regulator will. Fewer fields is also less to encrypt, log and delete.
- Run the controls a reviewer would have checked: Custom apps skip Shopify's app review, so build the review into the app: encryption at rest for personal fields, per-record access logging, a retention schedule that actually deletes, and a data-subject-request path that completes within 30 days, the window Shopify sets for App Store apps. Shopify's Level 1 PCI DSS and SOC2 certification on Plus covers Shopify's side of the line, not yours.
- Keep personal data where the law expects it: Shopify stores new European merchants' store, order and customer personal data at rest in Europe by default and still relies on international transfers for processing. Your app's database region is your choice: keep EU customers' fields in-region, and prefer reading from Shopify at request time over keeping a second copy at all.
- Effort band
- $25,000–$75,000 for a custom app with scoped protected-customer-data access, encryption, access logging, retention and data-subject-request handling — Deploi estimate (illustrative); lands in the $25–75K contact-form band
- Typical timeline
- 8–14 weeks, with the scope and purpose document finished before the first line of code (Deploi estimate, illustrative)
- Maintenance, honestly
- ~15–20% of build cost per year (Deploi estimate): roughly $4,000–$15,000/yr (Deploi estimate, illustrative) covering protected-customer-data requirement changes, log review, retention runs, and moving the app forward before an API version sunsets on Shopify's 12-month support window.
- What you own — and what you take on
- You own: the workflow, the customer identity joined to your events, and the evidence that you handle it properly. You take on: every obligation a certified vendor would otherwise carry, including answering data subject requests for your app's copy within 30 days.
3-Year Total Cost of Capability
| Buy (app path) | Build (custom path) | |
|---|---|---|
| Year 0 (setup) | $2,000–$10,000 (implementation and data mapping) | $25,000–$75,000 |
| Years 1–3 (recurring) | $10,800–$54,000 | $12,000–$45,000 (upkeep and hosting) |
| 3-year total | ≈$12,800–$64,000 | ≈$37,000–$120,000 |
- † All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
- † Buy column: one certified public app on a mid-market tier, $300–$1,500/month (illustrative band, since the fitting app depends on the workflow), plus implementation; the vendor carries the protected-customer-data obligations for its copy.
- † Build column: custom app with scoped access, encryption, access logging, retention and data-subject-request handling, plus hosting; three-year horizon.
What the Sticker Price Hides
On the buy path
- — A certified app grants nothing to your other apps; its protected-customer-data access is its own, tied to its review (verified Sep 2026)
- — Buying an app for the PII access alone leaves you running its workflow instead of yours, with the customer join living in the vendor's database
- — Every additional app that reads personal data is another about page to audit; Shopify offers no consolidated cross-app permissions view (verified Sep 2026)
- — Contact- or order-tiered pricing on data-heavy apps climbs with the customer file you're trying to protect
On the build path
- — Custom apps skip Shopify's app review, so no one checks your encryption, logging or retention unless you do (verified Sep 2026)
- — The Plus entitlement wording is a single Shopify source; confirm your plan's custom-app allowance for protected customer data before the budget is approved
- — Data subject requests must be completed within 30 days for App Store apps, and your custom app's copy of the data inherits the same clock (verified Sep 2026)
- — ~$4,000–$15,000/yr upkeep for requirement changes, log review and retention runs (Deploi estimate, illustrative)
What Merchants Say
Developers describe a custom integration that read every customer field in a development store and returned redacted personal fields in production, with the fix being a protected-customer-data request they didn't know existed.
Low-star reviews on data-heavy apps flag permission requests that reach further than the feature explains, and support answers that can't say where the exported customer file ends up.
If You Change Your Mind Later
If you bought and outgrow it
Leaving a certified app means recovering your customers' data from the vendor's copy, confirming its deletion in writing, and rebuilding the workflow elsewhere. The customer records themselves stay in Shopify untouched. Ask at signup what you get back, in what format, and how deletion is evidenced, because the answer at exit is rarely better than the one at signup.
If you built and want out
Nothing strands. The workflow data and the customer join live in a store you control, the app can be uninstalled without touching Shopify's customer records, and a later move to a certified app is an import rather than a negotiation. The exit cost is the controls you no longer need to run, which is a saving rather than a bill.
When This Answer Changes
We're watching for:
- ▸ Shopify publishing a per-plan allowance for custom apps with protected customer data on its plan comparison, which would replace this page's single-source caveat with a number
- ▸ Shopify shipping a consolidated cross-app permissions view, which changes the cost of governing who reads personal data
- ▸ Changes to shopify.dev's protected customer data requirements, which a custom app must absorb directly and a certified vendor absorbs for you
Verdict change log:
No changes since first publication (September 2026).
Common Questions
Does a custom Shopify app need approval to access protected customer data?
Protected customer data access is granted per app by Shopify, not installed from the App Store. Listed and unlisted public apps earn it through app review; a custom app is never reviewed, so its controls are yours to run and document (verified Sep 2026). Shopify's Plus plan page lists unlimited custom-app access to that data; confirm your plan's allowance on the current page. Budget $25,000–$75,000 for an app built to that standard (Deploi estimate, illustrative).
Is there a Shopify app that grants protected customer data access to my custom app?
No. A check of the App Store's Store management > Security category on 2026-09-05 found 12 apps covering fraud blockers, cookie consent, accessibility and B2B locks, none addressing protected-customer-data access levels. Privacy tools such as DataGrail, Comply and Descartes automate data subject requests and export screening, not access. Access belongs to the individual app Shopify approved, so the only paths are building your own app or buying a certified one that already does the job.
Should I build or buy a tool that needs full customer PII on Shopify Plus?
Build when the workflow is yours and no certified app sells it; buy when one does. A certified app such as Klaviyo or Gorgias already operates under Shopify's protected customer data requirements and answers data subject requests for its copy within the 30-day window Shopify sets. A custom app on Plus reads exactly the fields your warranty, fraud or loyalty process needs, with encryption, logging and retention you prove yourself, for $25,000–$75,000 (Deploi estimate, illustrative).
Your Next Steps
If you're going with BUILD(matches your selected profile)
- List the personal fields the workflow can't run without and write the purpose for each before any code
- Confirm your plan's custom-app allowance for protected customer data on Shopify's current plan-features page
- Audit every installed app's about page for personal-data permissions, so the new app doesn't duplicate a copy that already exists
- Build encryption at rest, per-record access logging, a retention job that deletes, and a data-subject-request path that completes within 30 days
- Prefer reading from Shopify at request time over keeping a second copy, and keep any copy in the region the customer lives in
If you're going with BUY
- Shortlist certified apps whose workflow matches yours, not apps chosen for the data access alone
- Read each listing's personal-data permissions at install and reject any that reach past the feature
- Ask the vendor, in writing, where customer data is stored, how deletion is evidenced, and what an export at exit contains
- Diary a quarterly pass through each installed app's about page, since no consolidated permissions view exists
Official Docs & Sources
- Shopify Plus plan features — Shopify Help Center
- Custom apps — Shopify Help Center
- Installing apps and reviewing permissions — Shopify Help Center
Official documentation linked for verification — our verdicts and estimates are our own.
Related Decisions
Can You See Every App's Access Scope in One Place?
Shopify discloses an app's data-access scopes at install and afterward one app at a time from its about page, with no consolidated view across the app fleet.
Can You Trust Every App Store App to Honor GDPR Deletion?
Shopify rejects any App Store app that fails to answer the mandatory compliance webhooks, with a 30-day action window. Custom apps sit outside that scope.
Does 'Built for Shopify' Mean an App Passed Security Review?
Built for Shopify certifies Core Web Vitals, admin latency and 50 net installs. No security or data-handling requirement appears anywhere in the criteria.
Do Custom Apps Inherit Any of Shopify's Compliance Vetting?
Shopify's app review covers both public app types, listed and unlisted. Custom apps are never described as reviewed, and compliance webhooks follow the App Store.
Shopify Theme Sections: Buy Premium or Build a Section Library?
A custom theme section library wins at mid-market campaign tempo; below the floor, a premium theme is the right call.
Ready to build on customer data without inheriting a compliance mess?
We scope the fields your workflow needs, build the custom app with the encryption, access logs and retention a reviewer would have checked, and hand you the document that proves it.
Contact us todayVerdict scored for the reference scenario above. Estimates are not quotes; app pricing carries its verification date and gets re-verified quarterly. Full scoring anchors: see the TCC methodology.
Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.