August 4, 2026
Consent Records and the Audit Trail
3 MIN READ
Letting one person order in another person's name is a sensitive thing to do. The app records every session so that you can always answer the question: who acted for whom, when, and on what basis. This article explains what is recorded, where it lives, and how to use it.
What Gets Recorded
The first time an agent acts for a customer, three things are stored on that customer's record: the consent date the agent entered, an optional free-text note, and the responsible sales agent. The consent date and note are updated on later sessions. The responsible agent is written once, on the first session, and is never overwritten — so the record of who originally established the relationship stays intact even if other reps act for that customer later.
Where It Is Stored
The records are written as metafields on the customer inside your own Shopify account. They are not held on our systems. This matters for two reasons. You own the data and can read, export or delete it in Shopify at any time, using the admin, the API, or any export tool you already use. And if you ever uninstall the app, the records stay — they are part of your customer data, not part of ours. You can see them on the customer's page in your Shopify admin.
What Consent Actually Means Here
The app records that consent was obtained. It does not obtain it for you, and it cannot judge whether what you obtained is sufficient. Getting the customer's agreement, and deciding what form that agreement should take, is your responsibility as the merchant. For most B2B relationships a documented verbal agreement on a recorded call, or a clause in your terms of trade, is what this looks like in practice. If you are unsure what is adequate in your jurisdiction, ask your legal advisor. What the app gives you is the durable record: a date, a note, and a named person, attached to the customer, available years later.
Using the Note Field
Good notes are short and factual: the channel the agreement came through, and anything that identifies it later. For example, that it was agreed during a call on a given date, or that a signed trading agreement is on file. Do not record health information, or any other special category of personal data, in this field. It is a free-text box in a system that is not designed for sensitive data, and doing so creates obligations you almost certainly do not want. Tell your reps this explicitly when you onboard them. It is the one part of the flow where a well-meaning rep can create a problem.
Answering a Question About an Order
When someone asks who placed a particular order — a customer, an auditor, or your own finance team — the trail is: open the order, see which customer it belongs to, then open that customer to see the consent date, note and responsible agent. Shopify's own order timeline records changes made to an order, including the point at which it was assigned to the customer, so the order history and the consent record on the customer together give you the full picture.
Data Protection
Under the GDPR you are the controller of your customers' data and we are a processor acting on your instructions. If a customer asks you for their data, or asks you to delete it, you handle that in Shopify as you would for any other customer data — the consent records are included, because they live on the customer record. Our Data Processing Agreement sets out the full arrangement, and the privacy policy describes exactly what the app accesses. Both are available on our site, in English and German.