Reviewed, sourced guidance

Keep repair intake data relevant and necessary

Direct answer

Before adding a repair intake field, write down its purpose and who needs it. ICO guidance says personal data should be adequate, relevant and limited to what is necessary for that purpose. Review app permissions separately.

A repair form should collect enough information to manage the job, not every detail a tool can store.

Key takeaways

  • Name the purpose for each personal-data field.
  • Collect only details the repair process needs.
  • Check which staff and apps can see the information.
  • Review retention and delete data no longer needed.

Give each field a job

For each field, record its purpose, who uses it and when it can be removed.

Possible repair details include the customer’s chosen contact route, exact model and reported symptoms. Keep only fields that the shop needs for its stated process.

Sources for this section: ICO, UK GDPR data minimisation guidance (observed 2026-09-25)

A receive, inspect, quote and return sequence

Use the stages below as optional prompts for fields a shop may choose to record, not as fixed requirements.

Keep customer-reported symptoms separate from what the shop observes on inspection, and keep only fields with a stated operational purpose.

Leave device passwords, access codes and other credentials out of the intake record.

  • Receive — record the customer’s reported symptoms, chosen contact route and the device details the shop needs to identify the job. Label these as customer-reported until inspection.
  • Inspect — record the shop’s own observations, such as the fault found, parts needed and any test result, and keep them distinct from the customer’s description.
  • Quote — record the agreed scope and amount, and the customer’s approval before chargeable work starts.
  • Return — record the collection event and the work described to the customer at handover.

Sources for this section: ICO, UK GDPR data minimisation guidance (observed 2026-09-25)

Review app access before installation

Shopify says apps should request only the access scopes they need. Read the requested access and check it against the app’s advertised job.

Ask what data is stored outside Shopify, who can access it and how the shop can retrieve or remove it. Do not infer answers from an app-store rating.

Sources for this section: Shopify developer docs, App Store requirements (observed 2026-09-25)Shopify Help Center, finding and choosing apps (observed 2026-09-25)

Use test information while evaluating

Use fictional records when checking an app workflow, unless your approved test environment requires another method.

Keep customer contact details and device credentials out of screenshots, demonstration stores and comparison notes.

Next steps

  1. Remove fields without a stated operational purpose.
  2. Check the shop privacy notice and internal access rules before launch.

Sources

Review the workflow sources