---
title: "Get customer privacy settings"
method: GET
path: "/v3/customer-privacy"
tags: ["Customer Privacy"]
---

# Get customer privacy settings

`GET /v3/customer-privacy`

Requires business:read. Returns the authenticated business's consent-required country lists, current revision, supported country codes and read-only compatibility metadata. Country lists independently control store statistics and marketing consent requirements. Countries absent from a list do not require consent for that category.

## Response `200`

Success

- CustomerPrivacySettings
  - `business_id` integer, required
  - `revision` integer, required — Current settings revision. Read it immediately before an update.
  - `marketing_generation` integer, required — Read-only revision for material marketing configuration changes.
  - `notice_version` string, required — Current notice identifier.
  - `analytics_enabled` boolean, required — Read-only legacy owner-acceptance metadata; not a writable analytics switch and not a prerequisite for event ingestion.
  - `analytics_legal_acceptance` CustomerPrivacyLegalAcceptance, required — Read-only compatibility metadata about the current owner. It is not an event-ingestion authorization requirement.
    - `required_version` string, date, required
    - `terms_version` string, nullable
    - `terms_accepted_at` integer, nullable — Unix timestamp in seconds.
    - `privacy_version` string, nullable
    - `privacy_accepted_at` integer, nullable — Unix timestamp in seconds.
  - `analytics_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.
  - `marketing_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.
  - `country_codes` CustomerPrivacyCountryCode[], required — All supported country codes.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `429` — Too Many Requests. Storefront public requests using `X-Scalev-Storefront-Api-Key` or `X-Scalev-Guest-Token` are rate-limited as direct client/browser requests. Machine-authenticated business requests are rate-limited per API key or OAuth installation. Rate-limit responses may be plain text instead of the normal JSON error shape.

## Changes

- **2026-09-20** `af4231e0cad9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/scalev/apis/nexus-commerce-api/changes/v3/customer-privacy/get.md)

---

[API](https://skmtc.dev/scalev/apis/nexus-commerce-api.md) · [All operations](https://skmtc.dev/scalev/apis/nexus-commerce-api/llms.txt) · [OpenAPI document](https://skmtc.dev/scalev/apis/nexus-commerce-api/revisions/215156c4eee0?raw)
