Help Center

Everything about installing, running, and troubleshooting DropifyXL. Search, expand, and go.

Getting Started

Install DropifyXL on your Shopify store

OAuth flow, the read-only scopes we request, and what happens right after install.

Install via the Shopify App Store → "Add app". Shopify will ask you to approve five read scopes (read_products, read_inventory, read_orders, read_all_orders, read_customers) plus two Plus-only scopes (write_pixels, read_customer_events) which stay dormant until you explicitly enable visitor analytics in Settings. read_all_orders is the one people ask about: Shopify's standard read_orders only exposes the last 60 days, and the win-back rule needs a 60–180 day window to tell a genuinely lapsed customer from a quiet fortnight. It is read-only, just without the time limit. We never get your Shopify password — authentication is OAuth only. After install you land on the embedded admin page; the first backfill kicks off in the background and typically completes in 5–30 minutes depending on catalog size.

Open the DropifyXL listing on the Shopify App Store

Your first 48 hours with DropifyXL

What to expect from install → first action plan.

Minute 0 — you see the onboarding modal explaining the product. Minutes 1–30 — we pull your last 90 days of orders plus your customers, products, and abandoned checkouts in the background. The dashboard shows a "We're scanning your store" state. Within the first hour your first action plan is ready, and it's a full Plus-tier preview regardless of your plan: up to 10 polished recommendations, your store score, and every opportunity we found sized in your currency, so you see the whole product once. You'll also get a "First plan ready" email. From week two onward your plan's own limits apply — 1 a week on Free, 5 a week on Pro, 10 a day on Plus. Scans run at 9am in your store's local timezone.

Your weekly action plan

How the weekly scan works

Scheduling, idempotency, and what triggers a scan.

The scan runs on a schedule: Pro stores get it weekly on Monday at 9:00 in the store's local timezone (set via your Shopify admin). Plus stores get it daily at 9:00 local. Each scan queries your data through a deterministic rules engine, picks the top 3–5 by priority, and polishes the copy with an LLM. The result is saved to your dashboard and — on paid plans with email enabled — sent as a digest. Scans are idempotent by ISO week: running it twice in the same week doesn't generate duplicate recommendations.

The notifications inbox

What lands there, and how read state works.

The Notifications tab is an in-app inbox for everything that happens outside your action plan: scan completed, scan found nothing actionable, scan failed, initial import finished, trial ending, and plan changed. Filter by status (all, unread, dismissed) or by category (scan, sync, billing, plan) — both filters live in the URL, so a filtered view is bookmarkable. Read state is per-row and click-driven like an email client: opening the page doesn't mark everything read, clicking a row does. The unread count shows in the app's left-hand navigation. Dismissed notifications are kept for 60 days and then cleaned up automatically.

Recommendations

The 14 recommendation types

Six core rules, four cash-on-delivery rules, and four Plus-only behavioral rules.

Core (every plan, including Free): (1) Restock alert — top-selling product running low; (2) Winback campaign — customers past their typical reorder cadence; (3) Pricing adjustment — margin gap against your store average; (4) Hidden hero — high-performer missing from your homepage collection; (5) Abandoned cart — checkout-start to conversion gap; (6) Ad creative brief — structured hook + audience + platform recommendation for a product worth promoting. Cash on delivery (every plan, and only if we detect COD in your orders): (7) Return-to-origin losses — what dispatched-and-refused orders cost you monthly; (8) Pre-dispatch review — unfulfilled COD orders carrying refusal patterns; (9) Repeat refusers — buyers with two or more failed COD deliveries; (10) Prepaid shift — your COD failure rate against your prepaid one. Plus-only (requires Web Pixel): (11) PDP conversion — product pages with high views but low add-to-carts; (12) Ad-channel leak — a traffic source sending visitors but not converting; (13) Time-of-day — when your visitors actually land vs. when you post; (14) Mobile bounce — mobile-specific funnel drops.

How a recommendation gets its dollar figure

Ranges, confidence levels, the store cap, and honest blanks.

Each rule does its own arithmetic against your real numbers, and the card shows you those inputs. Three guardrails keep the figures believable. First, every estimate is a range with a confidence level (high = money visible directly in your store data; medium = a measured gap applied to your real volume; low = directional only), never a single number. Second, no single opportunity may claim more than 20% of your trailing 30-day revenue — this stops rate-gap arithmetic on a small store producing an absurd figure. Third, when a signal is real but its size can't be defended, the recommendation ships with no number at all rather than an invented one. Your headline total counts each product or customer segment once, at its largest opportunity, and excludes low-confidence estimates entirely.

Understanding your store score

One number, seven sub-scores, and why some read as unrated.

Your store score is a 0–100 roll-up of seven sub-scores: revenue, conversion, products, customers, marketing, inventory, and delivery. Each is scored against a target (for example, conversion targets a 3% rate; customers targets a 40% repeat rate) and weighted, then the total is the weighted mean over whichever sub-scores are actually measurable on your store. Sub-scores with too little data behind them read as unrated with the reason shown — conversion and marketing need visitor tracking, customers needs at least 10 buyers with an order, delivery is only measured on stores using cash on delivery. The total can move at most 5 points between snapshots, so a single event can't swing it.

How we measure whether a recommendation worked

14 and 28 day re-reads against a matched window before you acted.

When you mark a recommendation done, the opportunity behind it becomes measurable. We re-read the driving metric 14 and 28 days later and compare each against an equal-length window before you acted. Three types get 28 and 56 days instead, because their fix takes real-world time to land: restock (supplier lead time is 7–21 days, so a 14-day read would land while stock is still in transit), win-back (a lapsed customer returning isn't a same-week behaviour), and cash on delivery (each order has to travel out, be accepted or refused, and travel back). Every window is a whole number of weeks so day-of-week seasonality cancels out. Important: this is a measurement, not an attribution. We can't run a holdout on your store, so a positive delta means the metric improved after you acted, not necessarily because you did.

Mark recommendations done, snoozed, or dismissed

Three states plus how the system learns from your choices.

Every recommendation has three buttons. Done — logs the action; the recommendation disappears from the active list and is counted in your weekly completion stats. Snoozed — hidden for a week; it reappears on the next scan if still relevant. Dismissed — hidden and the rule is deprioritized for this store going forward. All three states write to an audit log. The next scan will never duplicate a recommendation already marked done or dismissed for the current ISO week.

Plans & Billing

Plans & pricing (Free, Pro $19, Plus $39)

What each plan includes and how to upgrade.

Free — 1 recommendation per week, in-dashboard only, no email. You still get your store score, sized opportunities, and any cash-on-delivery diagnosis. Good for kicking the tires. Pro ($19 USD/month) — up to 5 recommendations per week, weekly email digest on Monday, first-scan email right after install, the cash-on-delivery review queue, and full action history with one-click reactivation. Plus ($39 USD/month) — everything in Pro, plus 10 fresh recommendations every morning, a daily email digest, ready-to-send draft emails, and the four behavioral recommendation types (PDP conversion, ad-channel leak, time-of-day, mobile bounce) powered by the opt-in Web Pixel. Upgrade any time from the Plan page inside the app — Shopify Billing handles the charge.

Free trial, billing, and cancellation

7-day trial, Shopify Billing, and how cancel works.

Paid plans include a 7-day free trial. Billing runs through Shopify Billing and appears on your regular Shopify invoice — no separate card capture. You'll get a trial-ending reminder email roughly 48 hours before the trial converts, so nothing catches you off-guard. Cancel any time from the Plan page: cancellation takes effect at the end of the current billing cycle and you keep access until then. Uninstalling the app from Shopify admin also cancels the subscription.

Change where notification emails are sent

Use a custom notification email instead of the Shopify owner email.

By default we send all DropifyXL emails to the email Shopify has on file for your store. To route them somewhere else (e.g. a shared inbox), go to Settings → Notification email → enter the address → Save. Reset to default returns you to the Shopify email. This is a DropifyXL-side setting — Shopify's own notifications still go to the Shopify email.

Unsubscribe from DropifyXL emails

One-click unsubscribe or in-app toggle.

Every DropifyXL email has a one-click unsubscribe link in the footer — clicking it immediately disables all DropifyXL email for your store. You can also toggle "Send me email notifications" off in Settings inside the app. Shopify's own emails (billing notifications, app install confirmation) are separate and are managed from Shopify admin, not by us.

Cash on delivery

Cash on delivery: what you get and when it appears

Auto-detected, on every plan, invisible if you don't take COD.

If your store takes cash on delivery, DropifyXL adds four rules and a dedicated review page without you configuring anything. They appear once COD is at least 5% of your order volume and you have at least 20 COD orders, so a one-off manual payment never triggers them. If you don't take COD, none of this ever shows up: no tab, no recommendations, no empty state. The four rules are available on every plan including Free, because a merchant losing money to refused deliveries should get the diagnosis rather than a paywall. The review queue itself needs Pro or Plus; Free sees the counts and the totals.

How we detect a cash-on-delivery order

Gateway-name matching, and why we'd rather miss than guess.

Shopify has no cash-on-delivery flag, so we match against the payment gateway names recorded on your orders — both Shopify's own manual payment methods and the many regional COD apps, each of which names itself differently. We match confidently or not at all. In particular, a gateway called simply "manual" is deliberately excluded, because plenty of stores use it for bank transfer, invoicing, or in-person pickup, and telling you your prepaid orders are failing would be worse than staying quiet. We store the raw gateway names alongside each order, so if your custom gateway isn't recognised, open a ticket at /contact with the gateway name and we can add it without re-syncing your store.

Using the pre-dispatch review queue

How orders are scored, and why the page is read-only.

The Cash on delivery tab ranks your unfulfilled COD orders by the patterns that precede a refused delivery on your store: order value against your store average, the buyer's own COD history (settled vs. returned), whether they have any completed orders at all, repeat COD orders inside 48 hours, unusually large line quantities, and the local hour the order was placed. Each row lists the specific reasons it was flagged and deep-links into the Shopify admin. The page is deliberately read-only — we don't cancel, tag, or hold fulfilment, which is why the whole feature ships without asking for write access to your orders. The intended workflow is: scan the high-risk rows, call or message those buyers before dispatch, ship the rest.

Set your cost per failed COD delivery

Why we ask, and what to include in the number.

Nothing in Shopify's data knows what a refused delivery costs you, and it varies enormously by market and parcel size. Until you tell us, we use a mid-range default and every figure built on it is labelled a medium-confidence estimate. Enter your real number on the Cash on delivery page (Settings for cost per failed attempt) and every COD figure sharpens to high confidence. Include forward shipping, return shipping, packaging, and handling. Do not include the lost margin on the sale — the goods come back and get resold, so counting it would roughly double every figure we print. Accepted range is 0.50 to 200 per failed attempt, which is there to catch a slipped decimal.

Why some COD risk signals show as unavailable

Protected customer fields we don't hold approval for.

Two of the strongest cash-on-delivery signals are phone-number validity and delivery-address quality, including whether a given address sits behind repeated failures. Both are Shopify protected customer data, granted field by field, and our current approval covers name and email but not phone or address. Rather than score those signals as clean — which would silently mark risky orders safe and be worse than shipping nothing — they abstain, and the score is renormalised over the signals we can actually evaluate. The page shows a coverage percentage so you know how much of the picture you're seeing. If Shopify grants those fields later, the same page sharpens automatically with no change on your side.

Visitor analytics (Plus)

Enable visitor analytics (Plus)

How to turn on the Web Pixel and what it unlocks.

The four behavioral-data rules (PDP conversion, ad-channel leak, time-of-day, mobile bounce) need the Plus-only Web Pixel to be active. Go to Settings → Visitor analytics → toggle "Collect visitor analytics" on. We provision the pixel in your Shopify admin automatically — you don't touch theme code. First events arrive within minutes; the behavioral rules need 7–14 days of data before they fire reliably. Toggle the switch off at any time to stop collecting.

What the Web Pixel tracks (and what it doesn't)

Five events, session-scoped IDs, no cookies, consent-aware.

The Web Pixel sends five Shopify-standard events: page_viewed, product_viewed, product_added_to_cart, checkout_started, checkout_completed. Each event carries a daily-rotating session ID and coarse page/device metadata. It doesn't set any cookies, doesn't cross-session track, and respects every visitor's consent state through Shopify's Customer Privacy API — if a visitor declines analytics, nothing is sent. Raw events live in our database for less than 36 hours, then are rolled into anonymized daily summaries (traffic-source totals, product-funnel totals, page-type metrics) and deleted.

Troubleshooting

I don't see any recommendations yet

Most common reason: backfill is still running or the store is too new.

If the dashboard shows "We're scanning your store" — we're still pulling your data and the first plan is on its way (typically within 30 minutes of install; longer for stores with tens of thousands of products). If the dashboard shows "All clear for this week" — the rules ran but none triggered for your store this scan. That's usually a sign the store is very new (no order history yet) or already well-tuned. Give it 1–2 weeks of selling activity. If it still looks empty, open a ticket at /contact and include your shop domain.

Data looks stale or incomplete

How we sync, and what to check first.

We sync from Shopify in two ways: the one-time backfill at install (90 days of orders, full catalog, all customers) and incremental webhooks from Shopify for subsequent changes (orders/create, products/update, etc.). If something looks out of sync: (1) confirm the app still has the expected scopes in Shopify admin → Apps; (2) check Settings to confirm the shop is still marked active; (3) open a ticket at /contact with the Shopify product or order ID and we'll re-sync manually.

Data & Privacy

Uninstall & data retention

What happens to your data when you uninstall.

Uninstalling from Shopify admin immediately cancels any active subscription through Shopify Billing and marks your shop inactive in our database — no more scans, emails, or Shopify API calls on your account. Your data is retained for 90 days (in case you reinstall, so we don't have to re-pull everything) and then permanently deleted by a daily purge job. You can request earlier deletion via our contact form at /contact.

Privacy & security overview

TLS, AES-256, least privilege, and how data flows.

All traffic to the app and database uses TLS 1.2+. Data at rest is encrypted with AES-256 on Supabase Postgres. Shopify webhooks are HMAC-signature verified. Our cron server authenticates with a rotating bearer secret. Human access is 2FA-gated and least-privilege. Full details at /security; subprocessor list at /subprocessors; DPA at /dpa.

Still need help? Open a ticket — average first response under 24 hours.

Don't have DropifyXL yet? Install it from the Shopify App Store — free plan, no card required.

For legal and compliance pages see Terms, Privacy, DPA, and Subprocessors.