A store that sells mugs holds a name, an address and an order history. A store that sells courses holds all of that plus how far a student got, what they answered, what they wrote about their own life, and what an instructor said back. That is a materially different pile of personal data, and it is one most course sellers have never inventoried.
Alva Courses is a Shopify app for building and selling online courses. This article covers what a course seller actually holds, what Shopify's compliance webhooks oblige you to do, what an erasure has to destroy, and the genuinely hard question of coursework you want to keep as a teaching record.
What a course seller actually holds
Start by writing the list down, because the answer is longer than most merchants expect. Selling a course generates a behavioural record of a named person over weeks or months, and several parts of it are free text the student wrote themselves. That is the material a data request is about.
- Enrolments and progress — which courses, when, how far through, which lessons completed, where a video was paused.
- Quiz attempts and answers — including free-text answers, scores, pass or fail, and how many attempts it took.
- Written reflections — often the most personal thing in the pile. A reflection prompt asks a student about their own work, health, clients or goals, and they answer honestly.
- Instructor feedback — what you wrote back about their work, attached to their name.
- Lesson discussion — comments a student posted inside a course.
- Email history — which course emails were sent to them, when, and whether they bounced.
- Contact properties — anything you recorded about them yourself, which is free text and entirely under your control.
- Order-linked records — the purchases and refunds that granted or ended their access.
Two of these deserve special attention because merchants forget they exist. Reflections are diary entries, not form fields. And contact properties are personal data that you authored about someone else, which is a category people rarely think of as data they hold.
Shopify's compliance webhooks are an obligation, not a checkbox
Shopify requires every app to receive three privacy webhooks and act on them: a customer data request, a customer erasure request, and a store erasure when an app is uninstalled and the shop's data must go. They are not advisory. They carry a deadline, and they arrive whether or not the merchant is watching.
Alva Courses records each one so it stops being invisible plumbing. A Customer privacy requests page lists the data and erasure requests Shopify has forwarded for your store, with what kind of request it was, the customer's email, when it arrived and where it got to. A failed request can be retried from there.
When requests are outstanding, the members area shows a banner saying so and stating the window: you have 30 days from the request to respond. That number is the point of the banner. A privacy request that nobody noticed is the failure mode this surface exists to prevent.
Responding to a data request
A data request asks you to hand over the personal data you hold about a named customer. For a course store, answering it from memory is not realistic — the data is spread across enrolments, quizzes, reflections, comments, email logs and orders, and an answer that omits a category is an answer that under-reports.
Alva Courses assembles that store's own record of the customer as a single dated document: enrolments and progress, quiz attempts and the individual answers, reflection entries, lesson comments, course email history, order-related records and the contact properties you added yourself. It is scoped to your store, so it never contains another merchant's data about the same person.
Two honest limits
Each section of the document is capped, and when a cap is reached the document says so and reports how many rows there were. A very heavy student can exceed a cap, and the point of flagging it is that you know a manual follow-up is needed rather than shipping a silently short answer.
The document also excludes the student's own course access credential deliberately. It is a key to their account, not something they told you about themselves, and reproducing it in a document that gets emailed around would be a security problem rather than a compliance win.
Alva Courses is one source among several. Shopify itself holds the customer, order and payment record, and anything you keep in a mailing platform or a spreadsheet is yours to answer for. The steps for handling one in the app are in customer data requests.
What erasure has to destroy
An erasure request is stronger than deleting a member. Alva Courses acts on it for your store automatically and removes the student's record rather than hiding it: enrolments and progress, reflection entries, video positions, lesson comments, quiz coursework, email and bounce history, purchase and refund records, and the contact properties you wrote about them.
Two properties of that erasure are worth understanding, because they are the ones merchants ask about.
It is scoped to your store, and only your store
The same person can be a customer of many stores that use the app. An erasure request from your store erases what your store holds about them and nothing else. Another merchant's record of the same customer is not touched, which is the correct answer in both directions.
An unsubscribe survives the erasure, on purpose
If a student had unsubscribed from your monthly digest, that suppression stays after their data is erased — stored as a one-way hash of the address rather than the address itself. Erasing every trace of the unsubscribe would silently re-subscribe the very people who asked to be left alone, which is the opposite of what an erasure is for.
The hard question: coursework you want to keep
There is a real tension here, and it is worth stating rather than smoothing over. A merchant who assesses students has a legitimate reason to keep what they graded: it is evidence that a certificate was earned, and it is the only record of what a student submitted. But the student is a person with erasure rights over the same material.
Alva Courses resolves it by separating the two ways a student leaves. When you remove a student yourself — unenrolling them, or deleting the member — the graded coursework is kept as a teaching record. When a privacy erasure arrives, it is destroyed along with everything else. Retention is a convenience; erasure is an obligation, and the obligation wins.
The retained record is deliberately narrow. Only submitted work is kept — attempts that were passed, failed, expired or are awaiting review. An attempt the student was still typing is not evidence of anything and is not retained. What is kept stays readable: the wording of each question is stored alongside the answer, so editing or deleting the quiz later does not turn your archive into orphaned text.
If you rely on that archive, the practical advice is to be explicit with students about it in your own terms, and to understand that it is not a way to keep data past an erasure request. Keeping coursework after removing a member covers the mechanics.
What to do before a request arrives
Privacy work is much cheaper done in advance. None of the following is legal advice, and all of it is the sort of thing a merchant wishes they had done the week before their first request rather than the week after.
- Write down what you hold, using the list above as a starting point, including anything that lives outside your store.
- Collect less. A reflection prompt that invites health or financial detail creates an obligation you did not have to take on. Ask for what you will teach from.
- Decide your coursework retention position before someone asks, and say it in your terms rather than improvising in a support reply.
- Watch the privacy requests page, and treat the 30-day window as a real deadline rather than a soft one.
- Check your exports. A member CSV sitting in a downloads folder is a copy of this data that no erasure will ever reach — see exporting members to CSV.
Getting this right is not only defensive. Students share more, and reflect more honestly, when they believe a store is careful with what they write. The stores that handle privacy well tend to be the ones whose courses ask the best questions.
Frequently asked questions
More than a typical product store. Alongside the customer and order record, a course store holds enrolments and progress, quiz attempts and free-text answers, written reflections, instructor feedback, lesson comments, course email history and any contact properties the merchant added themselves.
Shopify requires every app to receive and act on three requests: a customer data request, a customer erasure request, and a store data erasure. Alva Courses records each one on a Customer privacy requests page for your store, showing what was asked, the customer email, when it arrived and its status.
Alva Courses shows a banner in the members area stating that you have 30 days from the request to respond, and lists the open requests so they are not missed. A failed request can be retried from that page.
Not in the same way. Deleting a member removes them from your store, but graded coursework is kept as a teaching record. A customer erasure request forwarded by Shopify is stronger: it destroys the store's record of that student, including the retained coursework.
Yes, when you remove them yourself. Alva Courses keeps submitted attempts that were passed, failed, expired or are awaiting review, along with the wording of each question so the archive stays readable if the quiz changes. Work a student was still drafting is not kept.
No, and that is deliberate. The suppression is kept as a one-way hash of the address rather than the address itself, so an erased student is not silently re-subscribed to your monthly digest if they are ever added to the store again.