Skip to content
All blog
Shopify Data Malaysia Operations

Customer data on your own store

Masni 6 min read

The strongest commercial argument for running your own store is that you get the customer. Names, contact details, purchase history, and the ability to sell again without paying for the introduction a second time — see moving from a marketplace to your own store.

That asset arrives with an obligation. You are now the party holding personal information about Malaysian consumers, and how you hold it is your responsibility rather than a platform's.

What you are actually holding

Worth enumerating, because stores routinely hold more than they realise.

Identity and contact details. Name, email, phone number.

Delivery addresses, often several per customer, which is location information about where people live.

Purchase history, which is a behavioural record and more revealing than any single field in it.

Payment references. Not card numbers, which stay with your gateway, but tokens and last-four digits — see recurring payments on your own store.

Communications. Support conversations, order notes, and whatever staff have typed into a record.

Spread across your store, your accounting system, your email tool, your support inbox, your courier's system and any app with customer access — see Shopify apps and the costs they add.

That last point is the one worth pausing on. Most stores could not produce an accurate list of every place a customer's details are held, and that list is the starting point for handling any of this properly.

The principles that carry most of the weight

Malaysia has a personal data protection regime and this is not legal advice on it. What follows is the operational discipline that sits underneath most data protection expectations anywhere, and it is worth applying on its own merits.

Collect what you need. A checkout asking for a date of birth for no reason is holding data it has no use for and carrying the risk of holding it.

Say what you will do with it, and do that. A plain privacy notice, findable, in language a customer can follow.

Keep it accurate, and let customers correct it.

Hold it only as long as you need it. Order records have a retention basis. A marketing list of people who unsubscribed four years ago does not.

Protect it proportionately. Access limited to people who need it, credentials not shared, exports not sitting in someone's downloads folder.

Honour requests. A customer asking what you hold, or asking you to stop marketing to them, should get a straightforward answer from a process rather than an improvised search.

The practical exposures

Four places where ordinary operations create real risk, all of them mundane.

Exports. A customer list downloaded to a laptop for a mailing, and never deleted. This is the most common way retail customer data actually leaks, and it has nothing to do with hacking.

Shared logins. One admin account used by several people means no record of who did what, and an account that outlives the person who left.

Apps with access nobody reviewed. Installed for one purpose, holding broad customer access years later.

Messaging. Order details and addresses pasted into group chats to coordinate fulfilment, then sitting in message history indefinitely.

None of these require sophistication to fix. Individual logins with appropriate access, a rule that exports are deleted after use, a twice-yearly app permission review, and a fulfilment process that does not run through personal chat accounts covers most of it — see segregation of duties when software posts.

What the accounting system needs, which is less than you think

Relevant because it reduces your exposure.

Reconciliation runs on amounts, references and dates. It does not need a customer's name, phone number or address to match a payment to an order and a payout to a bank credit — see the three-way match a Malaysian store needs.

Where customer identity does matter is receivables: a business customer paying against invoices needs to be identifiable, and that is a legitimate and narrow use — see bank transfers and manual payments you still receive.

So a system that requests customer personal information for an accounting purpose should be asked what it does with it. Sometimes the answer is good. Sometimes it is habit, and an integration that avoids holding the data avoids an approval process, reduces its own risk surface and reduces yours — see Shopify access scopes and protected customer data.

Using the asset without abusing it

The commercial and the responsible answer coincide more often than people expect.

Marketing to people who bought from you and want to hear from you works. Marketing to a purchased list, or to customers who never agreed to it, performs badly, damages the brand you opened the store to build, and is the least defensible thing you can do with the data.

The store's advantage is a relationship with people who chose you. Treating the list as an asset to be preserved rather than a resource to be extracted from is both the better business decision and the one that keeps you out of trouble.

Common questions

What customer data does an online store hold?

Identity and contact details, delivery addresses, purchase history, payment references such as tokens and last-four digits, and communications including support conversations and order notes. It is typically spread across the store, the accounting system, an email tool, a support inbox, the courier's system and any installed app with customer access.

What is the most common way retail customer data actually leaks?

Exports. A customer list downloaded to a laptop for a mailing and never deleted, rather than anything resembling an attack. Shared admin logins, apps holding access nobody has reviewed, and order details pasted into group chats account for most of the rest, and all four are fixed by process rather than by technology.

Does an accounting system need customer personal information?

Mostly not. Reconciliation runs on amounts, references and dates, and does not require a name, phone number or address to match a payment to an order and a payout to a bank credit. The legitimate exception is receivables, where a business customer paying against invoices has to be identifiable — a narrow and specific use.

How long should customer data be kept?

As long as there is a reason for it. Order records have a retention basis; a marketing list of people who unsubscribed years ago does not. Setting a retention position deliberately, rather than keeping everything indefinitely because storage is cheap, reduces both the risk and the amount of work involved in answering a customer request.


Related: segregation of duties when software posts · Shopify access scopes and protected customer data · Shopify apps and the costs they add


See what you could build

Start a free trial and describe what your business needs in plain language — SmartB Studio builds the module for you.

Start free trial
Get started

No credit card · Cancel anytime · Your data stays yours