What Can a Label App Read in Your Store?

LabelCraft - barcode labels for Shopify that print at exactly the size you set.

EN · FR · DE · ES
The guarantees behind every label
Exact to ±0.1 mm

Every label prints at the size you set - measured, not approximate.

Never a silent failure

Overflow or a missing barcode always raises a visible warning before you print.

Whole-dot barcodes

Modules snap to your printer's dots, so codes stay crisp and scan first time.

Your barcodes, untouched

We never overwrite or reassign a product's existing barcode.

Every Shopify app you install asks for a set of access scopes - the categories of store data it may read or write. It pays to understand what a given app actually needs, because the install screen groups permissions broadly, and a printing tool and an inventory-management tool sit at opposite ends of how much they need to see. This guide explains, in plain language, what a barcode-label app needs, what broader apps need, and how to read a permission request for yourself.

Least privilege: an app should read only what it needs

The security principle is least privilege: an app should request the narrowest access that still lets it do its job. Less access means a smaller surface for mistakes and less of your data leaving Shopify. When you weigh an app, the useful question is not only whether the app is trustworthy, but whether the job it does actually requires the data it asks for.

What a barcode-label app needs

Printing a label is a narrow job. To put the right barcode, title, price and size on a sticker, a label app needs to read your product catalogue - and, if it prints from an order or a received shipment, the product lines on that document. The core of it:

What inventory, purchase-order and accounting apps need

Apps that manage purchase orders, sync accounting, or run fulfilment do a much larger job, so they legitimately need much broader access. That is not a criticism - it is the nature of the work. Such an app typically needs to read:

How to read a permission request

  1. Open the app's install screen and read the list of data it will access. Shopify shows this before you approve.
  2. Match each category to the job. A label printer asking to read customer personal data is worth a second look; an inventory or accounting app asking for it usually is not.
  3. Prefer apps that request sensitive scopes optionally and in context - only when you first use the feature that needs them - over apps that demand everything up front.
  4. Check the app's privacy policy for where your data is hosted and what is deleted when you uninstall.
  5. Remember you can review and revoke an app's access at any time under Settings → Apps and sales channels in your Shopify admin.

How LabelCraft applies this

LabelCraft is a label printer, so it asks for a label printer's access. The base install requests your products and inventory - including permission to write back the barcodes it generates onto your product variants, so your catalogue and your labels stay in sync; it makes no other changes to your products. Order and return access is optional: you grant it in-context, only when you open those pages, and you can revoke it there. LabelCraft never reads a customer's name, email or address, hosts your data on servers in the EU, and deletes everything when you uninstall. The privacy policy sets out exactly which fields are read, field by field.

Install free - 200 labels per month →

Deciding between tools? See the honest comparison with Shopify's built-in label app, or contact LabelCraft support with any privacy question.

Related guides