IonxSupply
Shop partsSellersSell on IonxSupply
Sign in
IonxSupply

The parts market that knows your bike. Verified sellers, fitment-first search, buyer protection.

Marketplace
All partsBatteriesMotorsUsed partsSeller directory
Sell
Become a sellerSeller AgreementProhibited itemsDMCA / IP claims
Trust & legal
Buyer protection & refundsTerms of ServicePrivacy PolicyAcceptable useAll legal documentsHelp & supportContact support
© 2026 IonxSupply. All rights reserved.Sold by independent sellers · IonxSupply is a marketplace venue

What we can (and can’t) see in your Shopify

Short version: we ask for four permissions, all about products and stock. We never ask for your customers, and Shopify itself blocks anything you don’t tick.

Why it’s not “full access”

The app lives in your Shopify admin, and you choose its permissions when you create it. Shopify’s servers enforce that list — an app physically cannot read data outside the boxes you ticked. It isn’t a promise we make; it’s how the Shopify API works. Shopify’s access-scope documentation →

On top of that, when you paste your token we ask Shopify what that token is actually allowed to do. If it can read customer data, we refuse the connection and tell you to untick it. If we can’t read the permission list at all, we refuse too — we won’t connect a store we haven’t checked.

Your ShopifyIonxSupplyShopify's wall✓ Products & stock counts✓ “One sold” → stock drops by 1✕ Customers · orders · payoutsYou own thisWe only get the green

The four permissions, in plain English

See your product listread_products

Titles, prices, photos and variants — so your catalogue can come across without you retyping it.

See your stock countsread_inventory

How many of each item you have, so we never list something you've already sold.

Lower a stock count when we sell onewrite_inventory

A sale on IonxSupply drops that item's Shopify count by exactly the quantity sold. This is the whole point — it's what stops the same part selling twice.

See which warehouse a stock count belongs toread_locations

Shopify requires this to adjust stock at all. It reads location names only — nothing about you or your customers.

What we can never touch

  • Your customers — names, emails, phone numbers, addresses. We never request customer permissions, and our system refuses a token that has them.
  • Your Shopify orders and their contents (unless you separately switch on automatic fulfillment, which is off by default and entirely your choice).
  • Your payouts, bank details, revenue or Shopify billing.
  • Editing, renaming, repricing or deleting your products.
  • Your theme, apps, staff accounts or store settings.
  • Your discount codes, marketing, or anything on your storefront.
BeforeShopify: 5 in stockIonxSupply: 5 in stockSomeone buys 1 hereShopify: 5 in stockIonxSupply: 4 leftSeconds laterShopify: 4 in stockIonxSupply: 4 in stockThat last arrow is the one permission that writes. Without it, your Shopify keeps selling a part that's gone.

Straight talk about the one that writes

Yes, “write inventory” really does change a number in your store. When someone buys your part on IonxSupply, we lower that item’s Shopify stock by the amount sold — nothing else. We can’t raise it arbitrarily, edit the product, or touch anything around it. Without this, your Shopify would keep offering a part you already sold here, and one of those two buyers ends up disappointed. If you’d rather not grant it, that’s completely fine — list your parts here manually and manage stock yourself.
This is the screen you’ll see in ShopifyAdmin API access scopesread_productstickread_inventorytickwrite_inventorytickread_locationstickread_customersleave offread_ordersleave offIf a customer box is ticked, our system refuses the token.

Check it yourself, and switch it off whenever

In your Shopify admin: Settings → Apps and sales channels → Develop apps → your IonxSupply app. The Configuration tab shows the exact permission list — no hidden extras are possible. Hit Uninstall app and our access ends that second; your listings here stay put and simply stop syncing.

Your token is stored encrypted (AES-256-GCM) and is never shown again, not even to us in plain text.

Is this normal?

It’s the standard way Shopify inventory-sync tools work. Apps like Syncio and Stock Sync on Shopify’s own App Store use the same product and inventory permissions for the same reason. Creating an app inside your own admin is Shopify’s documented method for connecting one store to one integration.

Connect my storeQuestions? Talk to us first