Order status and returns
Let your agent answer "where is my order?" from your Shopify or WooCommerce store, and take return and exchange requests: setup, how visitors are verified, what the agent sees, limits and notifications.
With an order connection, your agent can look up a visitor's order in your Shopify or WooCommerce store and tell them its status, what it contained, its total and, when the order has one, its tracking number. With Returns and exchanges switched on, it can also take a return or exchange request and pass it to you. The agent only reads orders. It never changes anything in your store.
Before you start
Open your agent and go to the Actions tab. The Orders card is below Booking. Under Store, choose Shopify or WooCommerce.
Shopify with the intoCHAT app
Enter your store's .myshopify.com address under Store address and click Install on Shopify, then approve the app in Shopify. intoCHAT asks only for read access to orders, and keeps the connection up to date by itself. See Install the Shopify app for what the app can access and how to uninstall it. The button appears only once the intoCHAT Shopify app is available on your intoCHAT site; until then, use a custom app.
Shopify with a custom app
- Under Store address, enter your store's permanent
.myshopify.comaddress, for examplemy-store.myshopify.com. Use it even if customers know your store by its own domain. You find it in the Shopify admin under Settings, Domains. - Click Use a custom app instead.
- In Shopify's Dev Dashboard, for the organization that owns this store, create an app with the Admin API scope
read_orders. Addread_all_orderstoo if visitors should find orders older than 60 days; Shopify grants that scope on request. - Release a version of the app with these scopes and install it on your store.
- Copy the app's client ID and client secret into Client ID and Client secret, and click Test and connect.
intoCHAT exchanges the client ID and secret for an access token that lasts 24 hours, keeps it encrypted and gets a new one on its own before it runs out. Shopify only issues these tokens for a store in the same organization as the app; for any other store, the card says so.
WooCommerce
- Under Store address, enter your WordPress site's
https://address, for examplehttps://shop.example.com. Plainhttp://addresses are refused, because your keys would travel unencrypted. So are addresses on a private or internal network. - In WordPress, open WooCommerce, Settings, Advanced, REST API, and click Add key. Choose a user who can manage orders, set Permissions to Read, and click Generate API key.
- Copy the consumer key and consumer secret into the card and click Test and connect.
What connecting checks
Test and connect asks your store for its name and the ID of one recent order. No customer data is shown. If the store refuses, the card says why, for example that the credentials weren't accepted, that the app lacks the read_orders scope, or that the address has no WooCommerce REST API. You can check credentials up to 10 times in 10 minutes.
For Shopify, it also checks that Shopify returns the email address on orders. Shopify hides customer emails from apps that don't have access to protected customer data. When Shopify refuses the email field, no visitor could ever be verified, so the card refuses to connect and says: "Shopify didn't return customer emails: grant protected customer data access (email) to the app." When your latest order simply comes back without an email, the card connects but warns you: either that order has no email, or Shopify hides emails without saying so. Orders without a readable email are never shown to visitors.
The client secret, consumer key and consumer secret are stored encrypted and are never shown again. The card shows only the last four characters of the client ID or consumer key.
Manage the connection
Once connected, the card shows the store, its address and how it is connected.
- The On / Off switch in the card's header stops order lookups without disconnecting.
- Returns and exchanges lets the agent take return and exchange requests. It is off at first. See Returns and exchanges.
- Test connection runs the same check as connecting, with the saved credentials.
- Replace credentials connects again with new credentials. If the card says the saved credentials can't be read any more, the button reads Reconnect.
- Disconnect stops lookups and return requests and deletes the saved credentials. Return requests already made stay in the Returns list on the Leads tab.
For a Shopify app without the read_all_orders scope, the card notes that only orders from the last 60 days can be found.
How visitors are verified
The agent looks an order up only with an order number and an email address, and shows it only when the email is the one the order was placed with. The email is compared without regard to upper and lower case or spaces around it.
- Visitors your site has signed in. With identity verification, when your page passes the visitor's email, that email is used and the agent doesn't ask for one. An email the visitor types in the chat is then ignored, so a signed-in visitor can't look up someone else's order by typing their email.
- Everyone else. The agent asks for the order number and the email address. Both must match the order.
When the email doesn't match, the agent gets exactly the same answer as for an order number that doesn't exist: no order matches this order number and email address. It asks the visitor to check both, without saying which one is wrong. So nobody can find out which order numbers exist.
Identity verification signs only the visitor's user ID. The email beside it is what your page passes. It is therefore not stronger proof than an email the visitor types, and the limits on failed lookups apply the same way.
What the agent sees
From an order, the agent gets only:
- the order number and date,
- the payment status and the fulfillment status, and whether the order was cancelled,
- each item's title, variant and quantity,
- each shipment's carrier, tracking number and tracking link,
- the total and its currency.
It never gets addresses, phone numbers, payment details, customer notes, the email address or any other order of the same customer. intoCHAT doesn't ask your store for most of these at all, and what the agent receives is built from the list above only.
In the conversation's "Why this answer", an order lookup appears as Order lookup with the order number when it succeeded, and without one when it didn't. No other order details are stored with it.
Limits on failed lookups
A lookup fails when the number and email match no order. After 5 failed lookups in one conversation, or 20 from one IP address on the agent, within an hour, the agent stops looking up orders and tells the visitor to contact you directly. Lookups that find the order don't count, and neither do lookups that failed because your store couldn't be reached.
Returns and exchanges
With Returns and exchanges on, a visitor can ask the agent to return or exchange items of an order. The agent asks which items, how many, whether they want a return or an exchange, and why. It then checks the order again exactly like a lookup, with the same limits, and checks that each item is on the order and that the quantities aren't more than were ordered. When a product was ordered in several variants, the visitor must say which.
The request is recorded and the agent tells the visitor it was received and that you will follow up. The agent never promises that a request will be approved, a refund, a replacement or a return label. Nothing changes in your store: you handle the return there as usual.
Each conversation can send one request per order. If the visitor asks again for the same order, the agent tells them the first request was already sent, and nothing new is recorded or sent.
Where requests show up
- Returns on the Leads tab lists every request, newest first: the date, the order, the email, return or exchange, the items, the reason and the status. Mark handled marks a request done (team members need the Editor role or higher); the arrow undoes it. Export CSV downloads all requests. The chat icon opens the conversation.
- Email: the people who get lead alerts get an email for each new request, while lead alerts are on. Replying to it answers the customer at the order's email address.
- Webhook: the
return.requestedevent. See Webhooks. - Slack: Return request in the Slack alerts.
Access log
intoCHAT logs each time order data is looked up, without emails or order contents, and keeps the log for 90 days. Open Recent order lookups in the Orders card to see the last 25 entries, or click Export CSV for all of them. Everyone on your team can see it.
Each entry shows the time, the action (an order lookup, a return request, or a connection test when you test or connect the store), the order number and the outcome, and who: Visitor, or the name of the person on your account who tested or connected the store. For an order that wasn't found, the entry shows the number the visitor gave, and the outcome says why: Not found (no order with that number), Email didn't match, or Order has no readable email (the order has no email, or your store hides it). The visitor gets the same answer in all three cases. A lookup that never reached your store, such as one still waiting for the visitor's email, isn't logged.
Entries older than 90 days are deleted every day. When the Shopify app is uninstalled, or Shopify asks intoCHAT to delete a customer's or a store's data, the matching entries are deleted too.
When the agent offers orders
The agent looks up an order when a visitor asks where it is, about its status, delivery or tracking, or what it contained. It is never offered in a temporary chat: there, the agent tells the visitor to leave the temporary chat and ask again. Lookups in the Playground are real lookups in your store and count toward the limits.
Limits
- The agent only reads orders. It can't cancel, change or refund an order, or create a return label.
- Shopify: with only the
read_ordersscope, orders older than 60 days aren't found. Addread_all_ordersto the app for older orders. - WooCommerce keeps no tracking numbers itself. The agent sees them only when your store uses the WooCommerce Shipment Tracking extension, or a plugin that saves tracking the same way. Otherwise it can share the order's status, items and total.
- WooCommerce order numbers: intoCHAT first looks for the order with that ID. If your store gives orders their own numbers through a plugin, it searches for the number and uses only an exact match; whether the search finds plugin numbers depends on the plugin.
- One store per agent.
Next steps
- Know who your visitors are: Identity verification.
- Get return requests in your own tools: Webhooks.
- Let visitors book meetings in the chat: Booking with Cal.com or Calendly.