Reference

CRM Sync — Shopify App Platform Changes

For: Product managers, operations teams, and business stakeholders tracking Shopify app compliance Date: 2026-05-18


The Problem

Shopify has fundamentally changed how apps are built, authenticated, and reviewed. Apps built under the old rules will fail submission under the new requirements — and some deadlines have already passed.

If your app was created in the legacy Partner Dashboard, uses non-expiring access tokens, or manages customer data without declaring specific field-level access, it needs to be updated before it can be published or pass re-review.

These are not optional enhancements. They are platform requirements with enforcement dates.


What Changed

AreaOld Way (Partner Dashboard)New Way (Dev Dashboard)Deadline
Access tokensNever expire — store once, use foreverExpire every 60 minutes — must refresh automaticallyApril 1, 2026 (mandatory for new public apps)
Customer data accessRequest "read customers" → get everythingRequest specific fields: name, email, phone, address — each justified separatelyEnforced on submission
App configurationWeb forms in dashboard — no version historyConfig file in code repository — version controlled, reviewableCurrent standard
GDPR complianceOptional checkbox for data deletion webhooksMandatory — must handle data requests, customer deletion, and shop deletionEnforced on submission
Consent managementNot required by platformCustomer Privacy API required — consent signals before data collection2025-2026 enforcement
BillingREST API for chargesGraphQL API for subscriptions with upgrade/downgrade supportCurrent standard
App reviewSubmit and wait weeks for opaque feedbackAI-assisted self-review, structured submission, test credentials requiredApril 2026
ExtensionsCreated and managed in web dashboardManaged via command-line tool, stored in code repositoryCurrent standard

CRM Sync — Current Compliance Status

RequirementStatusNotes
App registered in Dev DashboardDone
Config file (shopify.app.toml) in repositoryDone
Expiring tokens with automatic refreshDoneRefreshes before expiry, not after failure
GDPR deletion webhooks implementedDoneAll three handlers with signature verification
Privacy policy publishedDoneHosted at crm-sync-docs.netlify.app
Protected customer data level requestedNeededMust request Level 1 (name + email) in Partner Dashboard
GDPR webhooks declared in config fileNeededVerify in shopify.app.toml
Billing via GraphQLNeededNot yet implemented
Minimum required scopes verifiedNeededAudit for unnecessary permissions
App listing completeNeededScreenshots, demo video, test credentials
Emergency contact providedNeededEmail + phone for Shopify review team

Key Dates

DateWhat HappensWhat You Need to Do
Already passed (Feb 2025)Scopes reviewed for necessity on every submissionRemove any permissions the app doesn't actively use
Already passed (Dec 2025)Customer data scopes enforced for tracking pixelsPixels accessing customer data need field-level approval
Already passed (Apr 1, 2026)Expiring tokens mandatory for new public appsApps with never-expiring tokens will be rejected — CRM Sync already compliant
Current (Mar 2026)Role-based access for partner organizationsMulti-user partner orgs need role setup
Current (Apr 2026)New submission experience with AI self-reviewPre-submission automated checks flag common issues

What Each Change Means for Your Business

Expiring Tokens

Before: Your app got a permanent key to the store's data. If that key was ever leaked, it worked forever.

Now: Keys expire every 60 minutes and must be refreshed. This means:

Business impact: Better security with no change in functionality. But apps that don't implement refresh will simply stop working.

Protected Customer Data

Before: Request "read customers" and get everything — names, emails, phones, addresses.

Now: You must declare exactly which customer fields you need and justify why. There are three levels:

Business impact: CRM Sync needs at least Level 1. Testing must happen on a real store (not a development store) because development stores bypass these restrictions.

Mandatory GDPR Webhooks

Before: Handling data deletion requests was optional.

Now: Your app must handle three specific requests from Shopify:

  1. "Give us all the data you have for this customer" (data access request)
  2. "Delete this customer's personal data" (deletion request)
  3. "This store uninstalled your app — delete all their data within 48 hours" (shop deletion)

Business impact: CRM Sync already handles all three. Each request is verified for authenticity before processing.

Configuration as Code

Before: App settings lived in web forms. No history, no review process, no way to compare versions.

Now: Settings live in a file (shopify.app.toml) in the code repository. Changes are version-controlled and reviewable.

Business impact: You can see exactly what changed, when, and who approved it. Same config file is used across development and production.


Migration Checklist

For teams migrating from the old Partner Dashboard to the current Dev Dashboard:

Authentication:

Customer Data:

GDPR Compliance:

Billing:

App Listing:

Configuration:


Downloadable Audit Checklist

A comprehensive checklist covering all 10 requirement areas (100+ items) is available for download:

File: docs/shopify-app-checklist.llm.md

This checklist can be:


Technical reference: FEATURE-SPEC-UA-MIGRATION.md Audit checklist: shopify-app-checklist.llm.md