Fehrist
Customer privacyMenu

Customer privacy

Consent choices, verified personal-data requests, exports, correction, and scheduled deletion.

Configure the storefront privacy experience

Open Settings → Customer privacy. You can show the banner to every visitor, only selected two-letter country codes, or disable it. All visitors can reopen choices from the permanent Privacy choices button.

  • Write the banner title and plain-language explanation customers will see.
  • Enable or disable analytics, marketing, preferences, and data-sharing opt-out controls.
  • Add your public privacy-policy URL and privacy contact address.

Saving settings creates a new consent version. Existing optional consent no longer applies until the visitor confirms the updated choices. Global Privacy Control always opts the visitor out of marketing/data sharing, and Do Not Track disables analytics.

What is blocked before consent

Optional first-party analytics, the live visitor map, Facebook/TikTok/Google scripts, enhanced conversions, and server-side advertising purchase events stay off until the matching purpose is allowed. Checkout, login, security, saved consent, and other essential store functions keep working.

Customer data requests

Every store has a public /privacy page for access, correction, and deletion requests. The platform emails a single-use confirmation link when the address matches a customer or order, without revealing whether a match exists on screen.

Signed-in, verified customers can use My account → Privacy to download their data immediately, create requests, review deadlines/status, and cancel active requests.

Process requests as an owner

  1. Open the request from Settings → Customer privacy and click Start.
  2. Use Export data for a structured customer package.
  3. Complete access/correction work, or reject it with a reason stored in the audit trail.
  4. For deletion, cancel active subscriptions first and schedule the redaction. A 10-day cooling period lets the customer cancel before the hourly worker permanently processes it.

Deletion removes or anonymizes direct identifiers while retaining redacted financial records where the merchant may need an accounting ledger. Installed apps receive a customer-redaction event and must delete any separate copy they control.

Important

These controls support privacy operations, but they are not legal advice or a compliance guarantee. Confirm identity, deadline, retention, and disclosure rules for every market where your store operates.