Customer data permissions, location scope, and privacy

Give staff only the access they need and understand which customer information is store-wide rather than tied to one shop.

Customers and enquiries use separate permissions

In Settings → Roles & permissions, Customers and Enquiries are separately protected sections even though Enquiries appears under Customers in the navigation. Give View or Manage access only to staff who need it.

Customer profiles are store-wide

Customer accounts are associated with the store, not a single location. A staff member's location assignment does not narrow the Customers directory. Staff who can view Customers can see the store-wide profile list; order and inventory pages apply their own location scope.

Saved addresses remain customer-owned

Merchant customer profiles do not expose the shopper's saved-address book. Staff see an address when it is part of an order they are authorised to fulfil.

Use and share the minimum data

Search by contact detail only for a business task, avoid copying private information into notes or chat, and do not export customer data through unsupported workarounds. Customer CSV import and export are not currently available.

Review permissions regularly

Remove access when a staff member changes duties, suspend people who no longer work for the business, and use Activity logs to investigate sensitive dashboard actions.