Built for Shopify app developers
GDPR and CCPA requests hit your app as compliance webhooks. We handle them.
Route Shopify's three mandatory topics to Delink — HMAC verified on arrival, every 30-day fulfillment window tracked, every event in an exportable log. Or forward through to your existing handler — same signed POST, same headers.
7-day free trial. No card required. From $8.99/mo after.
Already have a handler? Forward the same signed Shopify POST to your URL — same body, same headers, included on every plan. How Forward works
- HMAC verified on the raw body
- Raw webhook body never stored
- Live in minutes — one URL per app, no SDK
Your event log
See what lands in your event log
A compliance webhook that reaches Delink and is successfully verified and persisted becomes a row you can track and export. Fulfillment — exporting or deleting customer data — still happens in your app.
Event log
my-app · sample dataData requestacme-brand.myshopify.comReceivedFeb 12, 2026, 2:32 PM · Due Mar 14, 2026, 2:32 PM · Customer 8049479638721
Feb 12, 2026, 2:32 PM · Due Mar 14, 2026, 2:32 PM · Customer 8049479638721
- Customer ID
- 8049479638721
- Shop
- acme-brand.myshopify.com
- Received
- Feb 12, 2026, 2:32 PM
- Workflow due
- Mar 14, 2026, 2:32 PM
- Orders to redact
- —
- Shop ID
- 6123456789
- Topic
- Data requestcustomers/data_request
- Status
- Received
- Event ID
- evt_sample_data_request
Customer redactacme-brand.myshopify.comCompletedJan 8, 2026, 9:15 AM · Completed · Customer 8049479638721
Jan 8, 2026, 9:15 AM · Completed · Customer 8049479638721
- Customer ID
- 8049479638721
- Shop
- acme-brand.myshopify.com
- Received
- Jan 8, 2026, 9:15 AM
- Workflow due
- Feb 7, 2026, 9:15 AM
- Orders to redact
- 450789469, 450789470
- Shop ID
- 6123456789
- Topic
- Customer redactcustomers/redact
- Status
- Completed
- Event ID
- evt_sample_customer_redact
Webhook body
Verified and parsed for limited metadata in memory — not intentionally written to disk
{ "shop_domain": "acme-brand.myshopify.com", "customer": { "id": 8049479638721,"email": "jane@example.com","phone": "+1 555 0100"}, "orders_requested": [450789469] }
- →customer.id maps to Customer ID in your log
- —Email, phone, and raw JSON are not saved
Webhook bodies include customer emails and order details — verified and parsed for limited metadata in memory, not intentionally written to our database. This minimizes additional stored copies but cannot eliminate security risk.
Set up in minutes, not weekends
Register your app, paste the TOML snippet, and point Shopify at Delink — no webhook server to build or host.
- 1
Register your app
Webhook URL and signing secret in ~5 minutes.
- 2
Point Shopify at Delink
Copy the TOML snippet and run shopify app deploy.
- 3
Ship and prove receipt
HMAC ingest, workflow clock, event log, and exportable compliance event record when you need it.
OptionalKeep your handler
Already built one? Turn on Forward — Delink relays the signed POST after verification, on every plan.
Keep your handler
Already built one? Turn on Forward — Delink relays the signed POST after verification, on every plan.
Pricing
Simple plans for Shopify app developers
HMAC ingest, event log, and workflow tracking — hosted so you do not have to build it.
7-day free trial — no card required. $8.99/mo (Solo) · $19.99/mo (Multi) after trial.
Compliance events remain visible through 90 days after the workflow due date on all plans.
Solo
Shopify compliance webhook toolkit for one app
$8.99/mo
Try the full console free for 7 days — subscribe anytime to keep access.
1 app · Event history through 90 days after the workflow due date
Track recorded compliance requests against a 30-day Shopify workflow target
7-day free trial. No card required.
- HMAC-verified webhook ingest
- Live event log + 30-day Shopify workflow clock
- TOML snippet + webhook test tool
- Update client secret after Shopify rotation
- Complete / reopen workflow
- Exportable compliance event record (CSV)
- Forward — optional relay to your HTTPS endpoint
- Uninstall monitor — count + history per app
- Daily workflow digest email
Multi
Same features, three apps on one dashboard
$19.99/mo
Try the full console free for 7 days — subscribe anytime to keep access.
3 apps · Event history through 90 days after the workflow due date
Track recorded compliance requests against a 30-day Shopify workflow target
7-day free trial. No card required.
- Everything in Solo
- Up to 3 apps on one account
- Combined dashboard across apps
Team
Need more than three apps?
Custom
4+ apps on one account
Overview
How Delink works
Mandatory webhooks, setup timeline, workflow roles, optional Forward relay, and retention — plus optional uninstall monitor on every plan. Quick start guide.
FAQ
Shopify compliance webhook failures — and how to fix them
Answers on mandatory privacy webhooks, HMAC verification, app review, workflow tracking, and how Delink helps Shopify app developers.
Why are my Shopify mandatory compliance webhooks failing?
What does Shopify webhook HMAC verification failed mean?
How do I fix compliance_topics in shopify.app.toml?
Does Delink work with non-Remix Shopify apps?
Do I need to change api_version in shopify.app.toml for Delink?
Shopify app review: must implement mandatory compliance webhooks — how do I fix it?
Why is my Shopify compliance webhook returning 401?
How do I rotate my Shopify client secret with Delink?
What happens when a Shopify compliance webhook delivery fails?
How does Delink help at launch and with live compliance requests?
Do I need to host my own Shopify compliance webhook endpoint?
What is Delink Forward?
What are Forward retry and timing expectations?
Does Forward work with localhost?
When am I charged for Delink?
How long does Delink keep compliance event data?
Still stuck on compliance webhooks or HMAC errors? Email support or start free trial on Solo.