04.6 — LEGAL

Shopify permissions

Every scope the application requests on install, what each one is used for, and what it is not used for.

VERSION 1.0EFFECTIVE 2 September 2026ISSUED BY [LEGAL ENTITY]DRAFT FOR COUNSEL REVIEW
6.1

Scopes requested

read_productsLists your catalogue in the app and loads the source images attached to a product.
write_productsAttaches a selected photograph to a product's media. Used only after you confirm a selection. Shopify does not offer a narrower media-only scope, so this permission is broader than what Dambl does with it: no listing text, price, inventory value or variant is ever written.
write_filesUploads a generated photograph into the store's file library so it can be attached to the product.
6.2

What is not requested

The application does not request access to orders, customers, checkouts, discounts, fulfilment, inventory, payment data, or Shopify Payments records.

If a future feature needs a new scope, Shopify will ask you to approve it explicitly. We will not gain a scope silently.

6.3

When access is used

Reads happen when you open the app, open a product, or start a session.

A write happens only in response to an explicit confirmation in the review sheet. Nothing is written to a listing automatically and no listing text, price or inventory value is ever changed.

All API calls are logged with a request identifier that support can trace on request.

6.4

Revoking access

Uninstalling the app from your Shopify admin revokes the access token immediately. Further reads and writes fail from that moment.

Shopify sends us an uninstall webhook; we mark the account for deletion under the Images and data policy.

Photographs already written to your product media stay in your store. Uninstalling does not remove them.

Questions about this document go to support@dambl.app. Where a term here conflicts with the Shopify Partner Program Agreement or the Shopify Terms of Service, those terms prevail for matters they govern.