AgentReady
By Dylan HuntJune 11th, 2026ShopifyAIGuides

Is Shopify Sidekick Safe? What It Can Touch and Where Your Data Goes

Is Shopify Sidekick Safe? What It Can Touch and Where Your Data Goes

Every merchant who opens Sidekick eventually asks some version of the same question: this thing can see my whole business, so what exactly can it do with that access, and where does my data end up?

It is the right question to ask of any AI you give the keys to. Here is the grounded answer: what Sidekick can read, what it can change, what happens to your data, and the specific places where healthy caution is still warranted.

The boundary that matters most: read and propose, never commit

Sidekick's defining safety property is that it does not make changes on its own. It operates on a read-and-propose model. Ask it to create a 15 percent weekend discount and it will build the discount, then show it to you for approval. Ask it to bulk-edit prices and it stages the edit. Nothing is written to your store until you confirm.

This is not a courtesy setting you can accidentally disable. It is the design principle behind the whole assistant, and it extends to Sidekick app extensions, where third-party tools answer questions inside Sidekick but the merchant approves any action. The practical consequence: the blast radius of a bad Sidekick suggestion is a bad suggestion, not a broken store.

What Sidekick can see

Sidekick reads your store the way your admin does: products, orders, customers, analytics, content, settings. That grounding is the entire value, and it is why Sidekick answers "which products had the highest return rate last quarter" with your actual numbers instead of a generic essay. We mapped the full visibility surface in what data Shopify Sidekick can see, including the places where its view is fresher or staler than you might expect, a wrinkle we tested in does Sidekick use real-time store data.

Two scoping facts worth knowing:

  • Conversations are store-scoped. Sidekick runs inside your authenticated admin session. Your questions and its answers are not visible to other merchants, and nothing about your store leaks into another store's Sidekick.
  • Staff permissions carry over. Sidekick does not become a side door around your roles. What a staff account can learn from Sidekick tracks what that account could already access in the admin.

Where your data goes, and the training question

The sharper version of the safety question is about training: does asking Sidekick things mean your business data ends up baked into someone's model?

Here is what is verifiable. Shopify's AI features process your store data to serve you, and Shopify publishes privacy controls at privacy.shopify.com where you can review and manage how your data is used, including in connection with AI features. If your tolerance here is low, that settings page is worth ten minutes, and the current policy text is the source of truth as it evolves.

For third parties, the line got explicitly sharper this year. As of February 27, 2026, Shopify's partner program rules prohibit apps from using merchant or customer data to train AI or ML models without explicit consent. Before that update the boundary was blurrier, and plenty of merchants never thought to ask what their installed apps did with order data. Now the default is no.

Sidekick extensions get a further layer: Shopify validates extension descriptions, instructions, and input schemas at deploy time, and checks the data tools return at runtime before it enters the conversation. That is aimed at a real class of attack, prompt injection through tool responses, and it is more diligence than most AI plugin ecosystems apply.

The honest risk list

Safety is not the same as infallibility. The risks that remain are about quality, not access:

Wrong answers, confidently delivered. Sidekick has documented weak spots on tax and regulatory questions, where it can produce plausible, incorrect guidance. Anything with legal or financial consequences deserves a professional, not a chatbot, no matter whose chatbot it is.

Imprecision on complex asks. Multi-step analytical questions sometimes come back subtly off: the wrong date window, a filter interpreted loosely. The approve-before-save model catches bad writes, but nothing stops you from making a decision on a slightly wrong read. Spot-check numbers that will change what you do.

Over-delegation. The failure mode is not Sidekick going rogue, it is a merchant approving staged changes without reading them. The approval step only protects you if it is an actual review. Ten bulk edits approved on autopilot are ten unreviewed changes with your name on them.

A five-minute safety checklist

  1. Visit privacy.shopify.com and review your data and AI settings against your own comfort level.
  2. Audit your installed apps' access scopes in Settings, then Apps and sales channels. Uninstall what you no longer use, since dormant apps retain their grants.
  3. Check your staff roles. Sidekick respects them, which only helps if they are set thoughtfully.
  4. Adopt a personal rule: read every staged change before approving, every time.
  5. Route tax, legal, and compliance questions to humans. Use Sidekick to prepare for those conversations, not to replace them.

The bottom line

Sidekick is about as safe as an admin-embedded AI assistant can currently be: it cannot commit changes without you, it inherits your permission model, and the platform now draws a hard line on third parties training models with your data. The remaining risk is the ordinary kind that comes with any powerful tool, which is using its output without judgment.

If you are comfortable with the boundary and want more from the assistant, start with our practical Sidekick guide for merchants. And if your next question is what AI systems outside your admin can see about your store, that is a different surface with different rules, and our free AI readiness checker will show you exactly what the agents on the open web can and cannot read in about a minute.

The same confirm-first boundary applies to what we ship into the assistant: AgentReady's 16 data tools are read-only, and the one action stages a plan you approve yourself, all laid out on the Sidekick integration hub.

Quick answers

Frequently asked questions

Can Shopify Sidekick change my store without my approval?
No. Sidekick works on a read-and-propose model. It can analyze your data and stage a change, like a discount, a bulk edit, or a theme tweak, but it presents the change for you to review and approve before anything is written to your store. You remain the one who commits every mutation.
Does Shopify use my store data to train AI models?
Shopify's AI features are grounded in your store data to answer your questions, and Shopify provides privacy controls at privacy.shopify.com where you can review and manage how your data is used, including for improving Shopify's AI. For third parties the line is explicit: as of February 27, 2026, Shopify's partner rules prohibit apps from using merchant or customer data to train AI models without explicit consent.
Can Shopify apps feed my data to their own AI?
Only within Shopify's rules. Apps see the data you grant through access scopes, and Shopify's updated partner terms bar them from training AI or ML models on merchant and customer data without explicit written consent. Sidekick app extensions face additional review: Shopify validates them at deploy time and checks the data they return at runtime.
Is it safe to trust Sidekick's answers?
For store data questions, Sidekick reads from your actual orders, products, and analytics, which makes it far more reliable than a general chatbot. It can still get complex things wrong, and it has documented weak spots on tax and regulatory questions. Treat consequential answers as a starting point and verify anything with legal or financial impact.
Can customers or other merchants see what I ask Sidekick?
No. Sidekick conversations happen inside your authenticated admin session and are scoped to your store. Staff access follows your existing permissions model, so what a staff member can get from Sidekick tracks what their role could already see in the admin.

See where your store stands

Get found and recommended by AI shopping assistants.

Run the free AI-Readiness Checker to see, in about ten seconds, how ChatGPT, Perplexity, and Google read your store today and exactly what is holding it back. Then AgentReady fixes the gaps for you, adding Schema.org structured data, an llms.txt directory, and an ongoing audit. Install free; every software feature is $29/mo.

Comments

Every comment here comes from a verified email. Write yours, confirm from your inbox, and it's live.

Loading comments…

Leave a comment

ShareXLinkedInFacebook

Written by Dylan Hunt, Founder, AgentReady. AgentReady measures what AI says about Shopify stores and helps teams improve the answer. See plans.