Effective date: September 11, 2026
Spagify runs Google Standard Shopping for your Shopify store. To do that it needs to read your catalog and orders, and to read and change the campaigns inside the Google Ads accounts you connect. This page lists every permission it asks for, by name, what each one is used for, and what it is never used for. The list is the same one you see on the consent screens; if a permission is not here, Spagify does not ask for it.
Spagify connects through the Shopify Admin API, either from the App Store or as a custom app you create. Four access scopes are requested. Three are read-only. The fourth allows exactly one kind of write.
| Permission | Type | What it is used for | What it is never used for |
|---|---|---|---|
read_products | Read | Your catalog: titles, handles, prices, variants, images and product page URLs. This is what campaigns are built from, kept in sync with, and what search terms are judged against. | Editing products. Spagify never changes a product, its price, tags or metafields. |
read_inventory | Read | Stock levels. The stock guard pauses a product's ad group when it sells out and resumes it when stock is back, so you never pay for clicks on something you cannot ship. | Adjusting inventory. |
read_orders | Read | Orders and the Google click id captured on them, so paid clicks can be matched to sales and sent to Google Ads as offline conversions. Only order line items, totals, timestamps and the numeric customer id are stored. | Customer identity. Spagify deliberately does not ask for read_customers: no names, emails, addresses or phone numbers are read. |
write_url_redirects | Write | URL redirects, and only those. When a product handle changes, the old product page 404s for Google's crawler and Merchant Center disapproves the offer within a day. Spagify creates the redirect from the old path to the new one, records it in your activity log, and tells you in an alert. | Pages, blog posts, comments, themes or navigation. Spagify never creates or edits any of them and never deletes a redirect it did not create. |
Stores connected before write_url_redirects was requested keep working; Spagify then cannot create redirects for renamed products and says so in an alert until the store is reconnected. Connections made before 2026-09-24 asked for write_content instead, which the older Shopify API accepted for redirects and the current one does not — those stores need the new scope added and a reconnect.
Google access is granted through OAuth on the accounts you choose. Spagify holds a token for each connection and uses it only inside the accounts that were connected.
| Permission | Type | What it is used for | What it is never used for |
|---|---|---|---|
Google Ads (auth/adwords) | Read + write | Inside the Google Ads accounts you connect: reading performance and structure, and creating and adjusting Shopping campaigns, ad groups, product groups, bids, budgets and negative keywords. Every change is logged per product and reversible. | Other accounts, billing or payment settings, user access, or anything outside the accounts you explicitly connect. |
Merchant Center (auth/content) | Read + write | Reading your offers and their approval status and issues, creating the link between Merchant Center and Google Ads, and asking Google to re-review a disapproved offer after Spagify has verified the fix itself. | Editing your product feed or Merchant Center account settings. Spagify does not write product data into Merchant Center. |
Google sign-in (email, profile) | Read | Creating and signing in to your Spagify login. | Anything else; it is not linked to your Google Ads or Merchant Center access. |
Spagify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions about any permission: legal@spagify.com.