Privacy and Security
Guide status: Shared-responsibility framework. Last reviewed 14 August 2026. Qualified privacy, security and legal review is required before publication or reliance for a particular jurisdiction.
Purpose
Privacy and security are shared responsibilities between the merchant, Shopify, Liva 7 and any authorised service providers. This guide gives the operating questions a team should answer around customer data, consent, retention and access. It is not legal advice and does not replace current contracts, policies or professional review.
Start with purpose and minimisation
Define why information is needed before collecting or using it. Use the minimum level of detail that supports that purpose, prefer aggregated information where suitable, and do not retain information merely because it may become useful later.
Keep observed data, derived fields and inferred classifications distinct. Avoid sensitive attributes and proxies unless there is an explicit, legitimate and reviewed requirement.
Consent and customer expectations
Identify which uses depend on consent or other lawful basis in each relevant market. Respect changes to eligibility and consent across Smart Content, Customer Intelligence, measurement and exports. Unknown consent or identity should use an approved non-personalised experience rather than a guessed state.
Access and security
- Use individual accounts, least privilege and the security controls provided by the platforms.
- Restrict customer-level data and policy administration to roles with a current need.
- Never put passwords, access tokens, recovery codes or secret keys in content, screenshots or support requests.
- Review staff, contractor and support access throughout its lifecycle.
- Keep exports controlled, minimised and removed when their purpose ends.
Retention and deletion
Define retention by data category, purpose and obligation. A deletion or customer-rights process should consider source data, derived or inferred data, exports, logs and downstream systems as applicable. Historical decision records should minimise personal data so accountability can be retained without keeping unnecessary customer detail.
Unexpected access or disclosure
Follow the merchant's incident process. Preserve relevant evidence, limit further exposure, involve authorised privacy and security owners, and use current contractual or legal notification procedures. Do not investigate by copying more customer data into uncontrolled channels.
You are finished when
- purpose, source, access, consent and retention are documented;
- unknown or non-consenting states have a useful default;
- support and exports minimise sensitive information; and
- qualified reviewers have approved the applicable public claims and operating policy.