Skip to content
Rava ReviewsRava Reviews.
Back to help
Privacy

Handle privacy and data requests

Route access, deletion, export, and correction requests for merchant, shopper, reviewer, or staff data with the right verification steps.

Updated

Identify the requester

Confirm whether the request is from a merchant account owner, staff user, shopper, reviewer, or authorized representative. The right workflow depends on that role. Merchant account requests can often be handled through the store owner or authorized admin. Shopper and reviewer requests may need the merchant to verify the customer relationship.

Do not disclose account, order, or reviewer data until the requester is verified. If identity or authority is unclear, pause and ask for the minimum information needed to route the request safely.

Route correctly

Route the request based on data type and authority. Merchant configuration, billing, and app account requests should go through authorized merchant support channels. Shopper review access, correction, or deletion requests should be coordinated with the merchant when needed because the merchant owns the customer relationship.

  • Merchant account data: verify store ownership or authorized staff status.
  • Reviewer content: confirm the review and associated product or order context.
  • Billing data: route through authorized Shopify billing workflows when applicable.
  • Security requests: send to the team responsible for security review.

Handle deletion, correction, and export requests

For deletion requests, confirm exactly what should be removed: account access, review content, media, email address, or another record. For correction requests, preserve the meaning of customer-authored reviews and avoid changing sentiment. For export requests, provide only the data the requester is authorized to receive.

Document the request date, requester identity, verification method, action taken, and completion date. If the request affects published reviews, confirm storefront widgets no longer show removed content after the change.

Escalate sensitive cases

Escalate requests involving legal notices, minors, payment details, security incidents, disputed authorization, or large data exports. Do not improvise policy for sensitive requests in the moderation queue.

For public policy references, use privacy, cookies, security, and subprocessors. If the request is not covered by normal support handling, contact Rava through the contact page.