Help · Audience
Profiles
A profile is your record of one person. It holds their email address, their name if you know it, what they have done with your store, what they have spent, and whether they have said yes to marketing email.
A profile is a record about a person. It is not a promise that the person can be emailed — plenty of profiles deliberately cannot be. Consent decides that, and it is a separate fact with its own page.
The profiles screen
Every profile your store holds is here, whether or not it is confirmed and subscribed.
The order is fixed: most recent activity first. There are no sort controls, on purpose. The question this screen exists to answer is "who is around now", and the Last activity column is the answer. Last activity is the last thing your store recorded this person doing — including opening or clicking one of your emails.
Search by name or email. Type any part of a first name, a surname or an address to find one person. Type more than one word and every one of them has to match, wherever each falls — Jeremy @example.com finds the Jeremy at that domain, and the order you type them in does not matter. The screen shows a page of profiles rather than all of them, so searching is how you reach someone specific.
Two filters sit beside the search box.
- Consent — narrow to Subscribed, Unsubscribed, Do not email, or No consent recorded. The options are the same words the Consent column uses.
- Show — Everyone, Paused only, or Not paused. Pausing is your own reversible decision to stop emailing someone for a while; it is not consent, which is why it has a filter of its own rather than four more options in the first one.
The columns are Email, Name, Last activity, Consent, and Identity.
- Dates are shown compactly, with the whole moment on hover, always in your store's time zone.
- A Paused mark rides beside the person's name when you have paused emails to them.
- The Identity column says Verified identity or Not confirmed yet. That is not consent — see below.
If nothing comes back, the screen tells you which kind of empty it is: no profiles match your search, or you have no profiles yet. Paging. Under the table you choose how many to show at a time — 25, 50 or 100 per page — and step through with Previous and Next. The line beside them says where you are: Page 3 of 5. Type a number in the box to jump straight to a page. The page you are on is part of the address, so opening something and coming back puts you back where you were, and the size you choose is remembered the next time you open this screen. Searching or changing a filter takes you back to the first page. Very occasionally we cannot count your profiles quickly enough to say how many pages there are; when that happens the line says Page 3 and nothing more, rather than guessing.
One person, several addresses
One person often shops with more than one email address — a work one, an old one, the one they used the year they changed providers. Shopify keeps those as separate customers, and so do we. There is no way to force somebody to shop with one address, and nothing here joins two records into one.
What we can do is show you when two of your records are the same person.
When they share a phone number, they are shown as one entry. The entry leads with the address that has been active most recently, and a small control beside the name says how many addresses there are — 3 addresses. Press it and the others open underneath, each with its own last activity and its own consent. Press it again to close them. Each address still opens its own profile.
On a profile's own page, the others are named under the header. Also this person lists every other record in your store carrying the same number, with each one's consent beside it, and each is a link.
A weaker match is offered as a guess, and only there. If two records share a first name, a last name and a town but no phone number, the profile page says Possibly the same person. That never groups anything on the profiles screen: a shared phone number is something your store collected twice, and a matching name is a guess, which is not enough to decide what a screen shows you.
Consent belongs to the address, always. If Andrea unsubscribes one mailbox, that mailbox is unsubscribed and the others are not. Grouping changes nobody's consent and nobody's confirmed identity — it is a way of seeing, not a decision. Nothing is written when these rows appear, and there is no button here that joins two records.
Two things this does not do. It does not group people who share a number for an ordinary reason — a couple, or a family, all using one phone — because from your store's side those records look exactly like one person with two addresses; press the entry open and you will see both, each with its own consent. And it never reaches across stores: the same number in somebody else's store is somebody else.
A profile's own page
Click an email address to open one person.
The header
The person's name, then a line of email · phone · location — with only the parts you actually have, so there is never a stray separator. The email address has a copy button beside it. The location comes from your store's own pixel and is shown as codes, as they were recorded.
Underneath sits the identity line: Verified identity with the date it was confirmed, or Not confirmed yet. If the person has ever placed an order, "Has placed an order" appears here too.
Verified identity and consent are two different facts. Verified identity means we are confident this is a real person your store knows — it says nothing about permission. Consent means the person said yes or no to marketing email — it says nothing about whether the identity is real. Someone can have a verified identity and still not be subscribed, and that is the normal case, not a fault.
Pause, on the Email row
Pause emails sits in the ⋮ menu beside the Email row of Channel consent, with Resume emails in its place once they are paused. A paused profile shows the Paused mark under that row, with who paused them, when, and the note whoever paused them typed.
A pause and consent are two different facts, and the row keeps them apart: the consent pill is the person's own answer, and the Paused mark and the name beside it are your decision. A pause is yours and you can undo it; consent is theirs and you cannot. Full details are on the pause and resume page.
Marketers, managers and owners can pause and resume. A viewer is offered no menu at all.
This is a person
Under the two channels a third row, Person, appears on the profiles where it is a real question, and the decision on it is one only you can make. Its ⋮ offers This is a person: choose it when you have looked at a profile and satisfied yourself there is a real human being behind it. The row then reads who confirmed it and when, and the menu offers Not a person after all, so a mistake takes two presses to undo.
You will not see the row on most profiles, and that is deliberate. It is drawn on the records your Suspected bots segment currently collects — and on anybody already confirmed, so the name of whoever vouched for them never disappears. Somebody who has placed an order, whether your store told us about it or you imported it, is not in that segment and is asked no question: a customer who has bought from you is obviously a person, and saying "not confirmed" over their order history would be an insult to both of you.
Owners, managers and marketers can set the mark and lift it again. A viewer sees the mark and is not offered the menu.
Confirming asks first, and what it asks is really a reminder of what the mark does not do:
This changes nothing about consent, and nothing about who you can email. It only changes which segments this person falls into.
The place it matters today is the built-in Suspected bots segment, which is where most people meet this button: you read through the records that look like nobody at all, recognize somebody real among them, and say so. The Segments page explains what that segment collects, and why a real person can land in it.
Nothing else ever writes this mark. It is not a profile property, so no data arriving from your store and no import can set it — somebody on your team pressing the button is the only way it is ever true.
The numbers
Six numbers in two families, with a hairline between them. On the left, what happened in your store: Total spent, Orders, and Last order. On the right, what happened with the email you send: Emails sent, Opens, and Clicks.
Total spent is gross: it includes tax and shipping, and refunds are not subtracted, so it is a total of what was ordered rather than a lifetime value. No average order value is shown, because the order count includes orders whose value could not be read and an average of the two would be a smaller number than the truth presented as a precise one.
Hold your pointer over any of them to read where the number came from — From your store, or As imported with the day it was read. On somebody you imported, the store numbers are their order history as the file gave it, and their email numbers are the history the other service counted. The two are never mixed: as soon as your store tells us about an order of its own, all three store numbers are your store's and the imported ones step aside.
Channel consent
One row per channel — Email and Text messages — always both, each with its state, the reason if the state is Do not email, and the day it was recorded. A channel with nothing recorded shows "No consent recorded" rather than disappearing, because silence is not a decision the person made.
Recording what somebody told you
Not every answer arrives through a form. A customer replies to a receipt asking to be taken off the list; somebody hands you a card at a market and says to sign them up. The menu at the end of each consent row is where you write those down.
Mark as unsubscribed records that this person asked to stop. Their marketing email — or their text messages, if it is that row — stops right away, and your Shopify store is told too, so the two do not drift apart. That last part waits until your store knows who this person is: somebody who only ever filled in a form here, or arrived in a file you uploaded, is not a customer in your store yet, and the message goes as soon as they are.
Mark as subscribed records that they gave you permission. Before it saves, you confirm one sentence saying exactly that, and the sentence is kept with the change: this is your store's own record that the permission existed. It brings back somebody who unsubscribed, and it can start email reaching a person who was never asked. Your store is not changed by this one — telling Shopify somebody opted in would be making a permission claim on your behalf, which is yours to make, so update them there too if you keep a list.
Either way the change shows on the row afterwards with who recorded it — "Marked unsubscribed by Jane Chen" — and the day.
What this menu cannot do, at any role.
Nobody comes back from Do not email. An address that bounced, was reported as spam or is not a real address is permanent, and both verbs are offered grayed out with the reason rather than quietly hidden. If what you want is a temporary stop, that is Pause, which is reversible and leaves consent alone.
That holds even where the row itself looks empty. If an address was erased at some point, it stays refused for good — so a profile that arrived yesterday, on an address somebody erased last year, reads "No consent recorded" and still grays both verbs with that reason. The refusal belongs to the address, not to the record in front of you, and it is the same for a telephone number.
And nothing is recorded on a profile you have erased. An erasure is a promise you made about somebody's data; what stays behind is a husk, kept so your other records still add up. Its consent rows are gone, so both rows read "No consent recorded" — and both verbs are grayed with that reason, because there is nobody left at that record to have told you anything.
While an erasure is still being carried out, the profile is all still there — the address, the consent rows, the pill — and so is the person's right to be left alone. Mark as unsubscribed stays available for exactly that reason. Mark as subscribed does not: certifying that somebody gave you permission, about somebody who has just asked you to forget them, is not a claim to put in your own records. Pausing them, and saying this is a person, are not offered either — those are your decisions about somebody, and there is no longer anybody to decide about.
Nobody is signed up for text messages by hand. Only the person can agree to texts — by replying to one, or by entering the code they were sent. That is the phone carriers' rule, not ours, and it is why Mark as subscribed on the text row is always grayed out with that reason beside it. Recording that somebody asked to stop texting is offered whenever there is a number to stop texting: on a profile with no telephone number both verbs are grayed, because there is no handset for either of them to be about.
And a row needs an address before it can say anything about one. A customer who gave your store a telephone number and no email address is an ordinary profile, not a broken one — but there is no address for an email consent to be about, so both verbs on that row are grayed with that reason. It is the same rule as the missing telephone number, on the other row.
And the verb that matches the row is grayed too. Marking somebody unsubscribed who is already recorded as unsubscribed would change nothing about their consent and would quietly replace the record of where it came from — so the row offers you the direction you do not already have.
And recording consent does not confirm who somebody is. Those are two different facts. A profile that is not confirmed yet stays out of every audience whatever its consent says, and the card tells you so while you are looking at it. The verified identity page covers what confirms a profile.
A viewer sees every consent row and is offered no menu.
Properties
Facts a profile has collected — a preference they clicked, an answer they gave, the tags your Shopify customer record carries. Segment rules can use them. A profile with none says so.
They arrive from your own form fields, from the columns of a spreadsheet you import, and from an integration writing through the events API; the Profile properties page covers what you can then do with one.
Activity
Everything this person has done, newest first, with the whole moment shown on every row in your store's time zone.
It is paged, not capped. Under the feed you choose how many rows to show at a time — 25, 50 or 100 — and step through them, or type a page number. Nothing is hidden: a profile with four years of page views has all four years here, a page at a time. Your choice of page size is remembered for this screen.
Show narrows the feed to one kind of thing. The pulldown lists the events this person has actually produced, with how many of each — Placed Order (12) — so every choice in it leads somewhere. Choosing one shows those events and nothing else, automations included: the list is a list of events, and an automation row is not one of them. Choose Everything to get the whole feed back. The page and the filter are both in the address, so a link to what you are looking at is the address bar.
Each row carries a small mark showing where the record came from: the Shopify bag marks events from your store — both what the store recorded and what the person did on your storefront — events from an integration you wired up carry their own, and anything this app recorded carries the Carpe mark. That last group covers both the email you send and what happened on your signup forms, and the words beside the mark tell them apart: a form row reads from one of your forms, because the form is yours even though the record is ours. Rows with more behind them — an order with its line items and total, a page view with its path — open to show it. Rows with nothing more behind them do not pretend to open.
Your automations are in the feed too. A row says that this person entered an automation, that they finished it, or that they left it before the end, and the automation's name opens its page — unless that automation has been deleted, and then the name is there but is not a link. The row has just told you it was deleted, and a link inviting you back into it would be the row arguing with its own sentence; every row for that automation reads the same way, not only the one that says they left. A deleted automation does still have a page, and Automations explains what is on it. Those rows carry the Carpe mark and nothing else to open, because the row is the whole fact.
A person who left reads stopped matching Automation filter. That rule has to stay true of somebody the whole way through an automation — it is checked before every step — and theirs stopped being true. What is recorded is that it stopped, not which part of it did, so the row says that and no more. Somebody who left because the automation was deleted says that instead.
An email an automation did not send to this person is a row as well, with the reason: no consent, an address marked Do not email, an identity not confirmed yet, no address at all, or that you have paused them. The Refusals page covers what each of those means and which of them are yours to act on.
Why a text-message row says "Awaiting confirmation"
Beside Subscribed on the text-message row, a profile says one of four things when that row is not confirmed yet:
- the code has not been sent back — they gave you the number on one of your forms, and the six-digit code we texted has not come back yet.
- imported without a confirmed opt-in — you imported them from another service, and that service's own record does not say how they agreed. Nothing is missing and nothing has to be redone; that row confirms by itself the next time the person fills in one of your forms. If the whole list agreed with a text provider you used before, you can certify that in Settings → Text messages instead — the Text messages help page says how.
- no usable text number on file for this profile — their agreement is confirmed, and there is no number here a text could go to. The profile may still show a number — your store keeps what it was given, and what it was given is not always a number a text can be sent to. The next number this person gives you on one of your forms fixes it.
- Awaiting confirmation on its own, with no clause after it — the number reached you somewhere that leaves no step to wait for: your store's own checkout, a text somebody sent you, or a record that carries a number and nothing about how it was given. On a store that has never run an import this is the usual one, and there is nothing outstanding to chase. That row confirms by itself the next time the person fills in one of your forms.
In every case that person stays out of every marketing text you send until the row is confirmed.
Deleting a profile
If you are the store's owner, a profile's own page carries Delete this profile, in its own box at the foot of the page. It deletes everything held about the person, keeps the record that a campaign was delivered to them as a number only (their opens and clicks go with them), and — if they are a customer in your store who has never placed an order — deletes them in your store too. There is no undo, and you are taken back to this screen, where they no longer appear. To delete everybody in a segment or a list at once, use Settings → Delete profiles. The Deleting profiles help page covers both, and what happens if the same person comes back.
When somebody asks to be erased
You do this in Shopify, not here. Erasing a customer in your Shopify admin is what starts it: your store passes the request to the app on its own, the app carries it out, and there is nothing for you to do here and no control for it. Delete this profile is not the same act. It erases the same things, but it keeps an address from ever being emailed again only when the person had unsubscribed or was already on Do not email — a person who asked to be forgotten is owed that guarantee whatever their consent was, and the request from your store is what gives it. Shopify holds a request for about ten days before it sends it, and longer — up to six months — if the person has ordered recently, so a record you can still see is not a request that went missing.
What the erasure removes. Everything the profile held about the person: their address, their name, their phone number, anything your store knew about them, everything they did and everything they looked at, their consent and the record of how it was given, any pause you set and the note you wrote on it, and every open and click. The link between the profile and the customer record in your store goes too, so what is left cannot be matched back to anybody.
The line in your sending history stays, with the address and the subject taken out of it. It is the record that a send happened, and a store has to be able to say what it sent.
One thing survives, on purpose: the fact that this address must never be emailed again. It is kept as a one-way fingerprint rather than as the address itself, so it can be checked against and never read back. Without it, the same address arriving tomorrow in an order or a signup would be a new profile with nothing against it, and somebody who asked to be left alone would hear from you again.
If somebody asks for a copy of what you hold instead of asking to be erased, that request reaches the app the same way. The app gathers what it has about that person and the answer comes back to you through us; there is no screen for it yet.
What this screen never does
It does not hide profiles. Profiles that are not confirmed yet are shown here and marked, never removed — a profile you cannot see is a profile you cannot understand. The one profile that is not shown is one you deleted: it no longer names anybody, so there is nothing left to list. They are left out of every audience and are never emailed, which is explained on the verified identity page.