What MARKETIA does
- Imports the store's orders, products, inventory and customers for sales dashboards and the CRM.
- When the sales agent or a person closes an order over WhatsApp, Messenger or Instagram, it is created in the Shopify store with the customer's name, phone, email and delivery address.
- Recovers abandoned carts and measures store performance alongside advertising.
What it does not do
- It does not charge customers or store card data.
- It does not access stores the business has not connected.
How authorization works
- The business administrator enters their
*.myshopify.comdomain in MARKETIA → Connections → Shopify, or installs the app from Shopify. - Shopify shows its official consent screen with the scopes; the merchant approves them.
- Shopify redirects to the callback URL with a signed
state(expires after 10 minutes) and an HMAC signature that MARKETIA verifies before exchanging the code. - The store token is encrypted and stored; from then on order webhooks arrive.
Permissions and what they are used for
Main store scopes
| Permission | Used for |
|---|---|
read_orders, write_orders, read_all_orders, write_draft_orders, write_order_edits | Read orders for dashboards and create orders closed in chat. |
read_products, write_products, read_inventory, write_inventory | Catalog and inventory for the sales agent and catalogs. |
read_customers, write_customers | Customer contact details for the CRM and delivery. |
read_fulfillments, write_fulfillments, read_locations | Fulfillment status and store locations. |
read_discounts, write_discounts, read_returns, write_returns | Discounts and returns for orders managed from MARKETIA. |
read_content, write_content, read_themes, write_files | Store content and files when the business uses the store tools. |
What data is stored
- Orders: amount, products, city and the contact details needed for delivery.
- Products, variants, collections and inventory.
- Store customers (name, phone, email, address) when needed for the order and delivery.
Encryption and security
- Store token encrypted at rest (Fernet: AES-128-CBC + HMAC-SHA256); it never reaches the interface or the API.
- HMAC verification of the OAuth callback and every Shopify webhook.
- Tenant isolation: a store belongs to a single business.
Disconnection, retention and deletion
- Mandatory compliance (GDPR) webhooks:
customers/data_request,customers/redactandshop/redact.customers/redactdeletes or anonymizes that customer's data;shop/redactdeletes the store's data. - Uninstalling the app (
app/uninstalledwebhook) or disconnecting the store in MARKETIA deletes the connection and its token, and no new data comes in.
Related documents: privacy · data deletion · terms · security
Callback and webhook URLs
| Purpose | URL |
|---|---|
| OAuth callback | https://fapi.marketia.cerebria.co/api/v1/connections/shopify/oauth/callback |
| Order webhooks | https://fapi.marketia.cerebria.co/api/v1/connections/shopify/webhook |
| Compliance (GDPR) webhooks | https://fapi.marketia.cerebria.co/api/v1/connections/shopify/webhooks/compliance |
| MARKETIA privacy policy (Spanish) | https://fapi.marketia.cerebria.co/legal/privacidad |
Contact
For any question about the Shopify integration, test accounts or data requests: developer@cerebria.co
Privacy and deletion requests: developer@cerebria.co