Quick Start for Retail & E-commerce
Getting Started for Retail Businesses
This guide helps retail and e-commerce businesses get up and running with SAR Portal quickly. Whether you run a Shopify store, WooCommerce site, or multi-location retail chain, follow these steps to be DSAR-ready today.
Step 1: Know Where Your Customer Data Lives (5 minutes)
Before processing any DSARs, map out where you store customer data:
Common Retail Data Sources
| System | Data Types |
|---|---|
| E-commerce Platform (Shopify, WooCommerce, Magento) | Orders, accounts, addresses, payment history |
| Email Marketing (Mailchimp, Klaviyo) | Subscriber lists, open/click history, segments |
| Customer Service (Zendesk, Freshdesk) | Support tickets, chat logs |
| Loyalty Programme | Points, rewards, purchase patterns |
| POS System | In-store transactions |
| Analytics (GA4) | Browsing behaviour (often anonymised) |
| Reviews | Customer reviews with personal details |
Action: Make a checklist of your systems. You’ll need to export data from each when handling DSARs.
Step 2: Configure SAR Portal (10 minutes)
Organisation Settings
- Go to Settings > Organization (Settings is Admin-only)
- Enter your company details:
- Business name as it appears to customers
- Contact email for DSAR communications
- Business address
Public Portal Setup
- Go to Settings > Integrations
- View your Public Portal Access URL (and generate the token-based link)
- Upload your logo and set your brand colour
- Preview how customers will see it
Your portal URL will look like: https://app.sarportal.com/subjectaccess?token=your-portal-token
Notification Preferences
- Go to Settings > Notifications
- Enable email alerts for:
- New requests received
- Deadlines approaching (7 days, 3 days)
- Request status changes
Step 3: Add Your Team (5 minutes)
If others will help manage DSARs:
- Go to Users (Admin-only)
- Click Invite User
- Enter their email and select a role, then click Send Invitation:
- Admin: Full access
- Case Manager: Can manage cases but not settings
- Reviewer: Can view, update status, attach documents, and request info — cannot create or close cases
- Read Only: View and export only
Tip for retail: Consider giving store managers Case Manager access so they can help with employee DSARs.
Step 4: Link from Your Privacy Policy (5 minutes)
Update your privacy policy to include your new DSAR portal:
To exercise your data rights (access, deletion, or correction),
please submit a request through our secure portal:
[Your Portal URL]
We will respond within one month as required by GDPR.
Also update:
- Website footer link
- Customer service response templates
- Order confirmation emails (optional)
Step 5: Handle Your First DSAR (10 minutes)
When a customer submits a request:
1. Review the Request
- Check the request type (access, deletion, correction)
- Note the deadline (one month from receipt)
- If identity isn’t already confirmed, click the one-click Mark Verified button on the case (the method is recorded automatically — there’s no method dropdown or notes field)
2. Gather Customer Data
Export data from each system:
Shopify:
- Admin > Customers > Find customer > Export customer data
Mailchimp:
- Audience > Find contact > Export data
Zendesk:
- Search by email > Export tickets
3. Attach Exports to the Case
- Open the case, then open a case action — Request Info, Submit Info (shown when the case is Awaiting Information), or the Close Case dialog
- Use the file picker to add your exports (hold Ctrl/Cmd to select several). There’s no standalone upload button or drag-and-drop
4. Let AI Process
- Redactable files are scanned automatically — you land on the Review Detected PII screen
- Select the entities, click Redact Selected, and review (the AI flags other customers’ information)
- Click Confirm & Attach to Case (or Skip Redaction to attach unchanged)
5. Complete the Response
- Send the redacted files to the customer via secure portal or email
- Close the case using the red Close Case button and choose Completed & Fulfilled
Retail-Specific Tips
Handling Order Data
Customer order histories often include:
- Other people’s names (gift recipients, shared addresses)
- Payment card last 4 digits (usually fine to include)
- Delivery driver names (redact)
SAR Portal’s AI handles most of this, but review the redaction results.
Marketing Unsubscribe Requests
If someone asks to “be removed from marketing,” that’s not a DSAR — it’s an unsubscribe request. Handle it through your email platform directly.
But if they ask for “all data you hold on me” or “delete my data,” that IS a DSAR.
Former Employee Requests
Retail staff may submit DSARs after leaving. These require:
- HR records
- Payroll data
- Email communications
- Performance records
- Training records
The same SAR Portal workflow handles employee DSARs.
Loyalty Programme Considerations
Loyalty data is personal data. Include:
- Points balance and history
- Rewards redeemed
- Purchase patterns used for personalisation
- Any profiling or segmentation
Common Retail DSAR Scenarios
“Send me all my order history”
→ Export from e-commerce platform, upload, process, deliver
“Delete my account”
→ Create erasure case, delete from all systems, document what was deleted
“What marketing segments am I in?”
→ Export from email platform including segment data
“Stop using my data for recommendations”
→ Objection case, disable personalisation, confirm to customer
Getting Help
- Documentation: /docs/
- Email Support: support@sarportal.com
- Retail-Specific Questions: Contact us via /contact/
Ready to process your first DSAR? Open SAR Portal and follow the steps above.
New to SAR Portal? Start your free trial — no credit card required.