Permissions

Effective date: September 11, 2026

Spagify runs Google Standard Shopping for your Shopify store. To do that it needs to read your catalog and orders, and to read and change the campaigns inside the Google Ads accounts you connect. This page lists every permission it asks for, by name, what each one is used for, and what it is never used for. The list is the same one you see on the consent screens; if a permission is not here, Spagify does not ask for it.

1. Shopify

Spagify connects through the Shopify Admin API, either from the App Store or as a custom app you create. Four access scopes are requested. Three are read-only. The fourth allows exactly one kind of write.

PermissionTypeWhat it is used forWhat it is never used for
read_productsReadYour catalog: titles, handles, prices, variants, images and product page URLs. This is what campaigns are built from, kept in sync with, and what search terms are judged against.Editing products. Spagify never changes a product, its price, tags or metafields.
read_inventoryReadStock levels. The stock guard pauses a product's ad group when it sells out and resumes it when stock is back, so you never pay for clicks on something you cannot ship.Adjusting inventory.
read_ordersReadOrders and the Google click id captured on them, so paid clicks can be matched to sales and sent to Google Ads as offline conversions. Only order line items, totals, timestamps and the numeric customer id are stored.Customer identity. Spagify deliberately does not ask for read_customers: no names, emails, addresses or phone numbers are read.
write_url_redirectsWriteURL redirects, and only those. When a product handle changes, the old product page 404s for Google's crawler and Merchant Center disapproves the offer within a day. Spagify creates the redirect from the old path to the new one, records it in your activity log, and tells you in an alert.Pages, blog posts, comments, themes or navigation. Spagify never creates or edits any of them and never deletes a redirect it did not create.

Stores connected before write_url_redirects was requested keep working; Spagify then cannot create redirects for renamed products and says so in an alert until the store is reconnected. Connections made before 2026-09-24 asked for write_content instead, which the older Shopify API accepted for redirects and the current one does not — those stores need the new scope added and a reconnect.

2. Google

Google access is granted through OAuth on the accounts you choose. Spagify holds a token for each connection and uses it only inside the accounts that were connected.

PermissionTypeWhat it is used forWhat it is never used for
Google Ads (auth/adwords)Read + writeInside the Google Ads accounts you connect: reading performance and structure, and creating and adjusting Shopping campaigns, ad groups, product groups, bids, budgets and negative keywords. Every change is logged per product and reversible.Other accounts, billing or payment settings, user access, or anything outside the accounts you explicitly connect.
Merchant Center (auth/content)Read + writeReading your offers and their approval status and issues, creating the link between Merchant Center and Google Ads, and asking Google to re-review a disapproved offer after Spagify has verified the fix itself.Editing your product feed or Merchant Center account settings. Spagify does not write product data into Merchant Center.
Google sign-in (email, profile)ReadCreating and signing in to your Spagify login.Anything else; it is not linked to your Google Ads or Merchant Center access.

Spagify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. What every change looks like

  • Every write to Shopify or Google is recorded in your activity log with what it was, why, and what it changed.
  • Autopilot has a preview mode that shows the decisions it would make without applying them.
  • Changes are made only through the connected accounts' official APIs, never by logging in as you.

4. Revoking access

  • Shopify: disconnect in Spagify under Settings, or uninstall the app in your Shopify admin under Apps. Syncing stops immediately.
  • Google: disconnect in Spagify under Settings, or remove Spagify under your Google account's third-party access. Campaigns Spagify created stay in your Google Ads account and remain yours.
  • Stored data is deleted on request as described in our Privacy Policy.

Questions about any permission: legal@spagify.com.

© 2026 Spagify. All rights reserved.

Spagify — The Standard Shopping SPAG operating system for Shopify.