Agent skill

Shopify Data Handling

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks.

MITAuto-check passedLegal & Compliance

Install Shopify Data Handling

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-data-handling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace shopify-data-handling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/shopify-data-handling .claude/skills/shopify-data-handling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shopify-data-handling
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
359 words
Files
4 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks.

  • Works in 4 steps: Understand What Data Shopify Shares → Implement Mandatory Privacy Webhooks → Data Minimization and PII Detection → …
  • Building apps that store customer data
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls curl

What it does

Shopify Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks. Use when building apps that store customer data, preparing for App Store review, or implementing deletion workflows. Trigger with phrases like "shopify data", "shopify PII", "shopify GDPR", "shopify customer data", "shopify privacy", "shopify CCPA", "shopify data request".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/data-minimization-and-pii-detection.md`, `references/data-retention-policy.md` and `references/gdpr-privacy-webhooks.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR, Webhooks and App store release. It works with Shopify. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Building apps that store customer data
  • Preparing for App Store review
  • Implementing deletion workflows
  • With phrases like shopify data

Example prompts

  • “shopify data”
  • “shopify PII”
  • “shopify GDPR”
  • “/shopify-data-handling”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Understand What Data Shopify Shares
  2. Implement Mandatory Privacy Webhooks
  3. Data Minimization and PII Detection
  4. Data Retention Policy

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • shopify.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Shopify Data Handling loads about 1.1k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 359 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 359 words, ~1,062 tokens.

Download SKILL.mdSave it as .claude/skills/shopify-data-handling/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
shopify-data-handling
description
Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks. Use when building apps that store customer data, preparing for App Store review, or implementing deletion workflows. Trigger with phrases like "shopify data", "shopify PII", "shopify GDPR", "shopify customer data", "shopify privacy", "shopify CCPA", "shopify data request".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ecommerce, shopify

Shopify Data Handling

Overview

Handle customer PII correctly when building Shopify apps. Covers the mandatory GDPR webhooks, data minimization, and the specific privacy requirements Shopify enforces for App Store submission.

Prerequisites

  • Understanding of GDPR/CCPA requirements
  • Shopify app with webhook handling configured
  • Database for storing and deleting customer data

Instructions

Step 1: Understand What Data Shopify Shares

When a merchant grants your app access, you may receive:

Data TypeSourceSensitivityRetention Obligation
Customer email, name, phoneread_customers scopePII — encrypt at restDelete on customers/redact
Shipping addressesread_orders scopePII — encrypt at restDelete on customers/redact
Order details (amounts, items)read_orders scopeBusiness dataDelete on shop/redact
Product dataread_products scopePublicDelete on shop/redact
Shop owner emailread_shop scopePIIDelete on shop/redact
Step 2: Implement Mandatory Privacy Webhooks

Shopify requires three GDPR webhooks for App Store apps. Your app will be rejected without them: customers/data_request (customer wants their data), customers/redact (delete a customer's PII), and shop/redact (delete all shop data 48h after uninstall).

See GDPR Privacy Webhooks for the complete implementation of all three handlers.

Step 3: Data Minimization and PII Detection

Only fetch the fields you actually use in GraphQL queries. Add PII redaction middleware to prevent customer data from leaking into logs — detect emails, phone numbers, and credit card patterns.

See Data Minimization and PII Detection for query examples and redaction middleware.

Show full SKILL.md (133 more words)Show less
Step 4: Data Retention Policy

Automate cleanup with a daily cron job: delete API logs after 30 days, webhook logs after 90 days, and keep audit logs for 7 years (regulatory requirement).

See Data Retention Policy for the complete implementation.

Output

  • GDPR mandatory webhooks implemented and tested
  • Data minimization in API queries
  • PII redaction in all log output
  • Retention policy with automatic cleanup

Error Handling

IssueCauseSolution
App Store rejection for GDPRMissing webhook handlersImplement all 3 mandatory webhooks
Customer data not foundData already deletedReturn empty response (not an error)
shop/redact not receivedApp reinstalled before 48hShopify cancels redact if reinstalled
PII in logsMissing redactionAdd redaction middleware to all loggers

Examples

Test GDPR Webhooks
bash
# Simulate a customers/data_request webhook locally
curl -X POST http://localhost:3000/webhooks/gdpr/data-request \
  -H "Content-Type: application/json" \
  -H "X-Shopify-Topic: customers/data_request" \
  -H "X-Shopify-Shop-Domain: test.myshopify.com" \
  -d '{
    "shop_domain": "test.myshopify.com",
    "customer": {"id": 123, "email": "test@example.com", "phone": "+1234567890"},
    "orders_requested": [1001, 1002],
    "data_request": {"id": 999}
  }'

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/.curated/shopify-data-handling of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/data-minimization-and-pii-detection.md
  • references/data-retention-policy.md
  • references/gdpr-privacy-webhooks.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Shopify Data Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shopify Data Handling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shopify Data Handling this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Privacy Pagamenticcplugins/awesome-claude-code-plugins970—~845Automated safety check: PassApache-2.0
Privacy Policygustavscirulis/snapgrid1161 repos~3kAutomated safety check: PassCustom licence
Privacy Publishrshankras/claude-code-apple-skills787—~911Automated safety check: NotesMIT
ShopifyShopify/Shopify-AI-Toolkit592—~4.2kAutomated safety check: PassMIT
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone

Similar skills

  • Privacy Pagamenti

    ccplugins/awesome-claude-code-plugins

    Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione.

    970 GitHub stars~845 tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Privacy Policy

    gustavscirulis/snapgrid

    Generate privacy policies, terms of service, and EULAs for Apple platform apps.

    116 GitHub starsUsed in 1 repo~3k tokens
    Legal & ComplianceAuto-check passed
  • Privacy Publish

    rshankras/claude-code-apple-skills

    Turn drafted legal docs (privacy policy, terms) into hosted pages and set the App Store Connect Privacy Policy / Support / Marketing URLs via the ASC REST API.

    787 GitHub stars~911 tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check: notes
  • Shopify

    Shopify/Shopify-AI-Toolkit

    Official

    Build anything on Shopify. An agent skill from Shopify/Shopify-AI-Toolkit.

    592 GitHub stars~4.2k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Shopify Data Handling

What does Shopify Data Handling do?

Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks. Shopify Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Handle Shopify customer PII, implement GDPR/CCPA compliance, and manage data retention with Shopify's mandatory privacy webhooks.

When should I use Shopify Data Handling?

Shopify Data Handling fits situations like: building apps that store customer data; preparing for App Store review; implementing deletion workflows; with phrases like shopify data.

How do I install Shopify Data Handling in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-data-handling -a claude-code`. Or copy the skill folder (skills/.curated/shopify-data-handling in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/shopify-data-handling in your project. Claude Code loads it when a task matches its description.

How do I install Shopify Data Handling in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-data-handling -a codex`. Or copy the skill folder (skills/.curated/shopify-data-handling in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/shopify-data-handling in your project. Codex loads it when a task matches its description.

Can I use Shopify Data Handling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-data-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shopify-data-handling, .gemini/skills/shopify-data-handling, .github/skills/shopify-data-handling and .opencode/skills/shopify-data-handling in your project.

What does Shopify Data Handling need to run?

Going by SKILL.md and its folder, Shopify Data Handling needs the command-line tools its instructions call (curl). Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Shopify Data Handling access the network?

SKILL.md names 1 domain. As links in the text: shopify.dev. This is read from the text; nothing was executed.

Is Shopify Data Handling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shopify Data Handling use?

Shopify Data Handling is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shopify Data Handling use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Shopify Data Handling?

Skills that share tags, products or a category with Shopify Data Handling: Privacy Pagamenti (ccplugins/awesome-claude-code-plugins, 970 stars), Privacy Policy (gustavscirulis/snapgrid, 116 stars), Privacy Publish (rshankras/claude-code-apple-skills, 787 stars) and Shopify (Shopify/Shopify-AI-Toolkit, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shopify Data Handling?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.