---
title: "Update customer privacy settings"
method: PATCH
path: "/v3/customer-privacy"
tags: ["Customer Privacy"]
---

# Update customer privacy settings

`PATCH /v3/customer-privacy`

Requires business:update. Send only revision and both complete country lists. Updates are optimistic: fetch the current settings, submit that revision, and refetch on 409 before reconciling changes. Valid codes are normalized to sorted unique lists. Saving increments revision, records an administrative audit and schedules invalidation of affected cached public pages/configuration across the business's domains. Cache propagation is asynchronous; success is not a guarantee that every edge has already refreshed. Do not echo the whole GET response or send owner-acceptance metadata.

## Request body

- CustomerPrivacySettingsUpdate — Replace both country lists together. Include a country to require consent for that category; omit it to stop requiring consent there. Empty lists are allowed. Extra fields, including read-only GET metadata, are rejected.
  - `revision` integer, required — The revision returned by the most recent GET. A successful update increments it by one.
  - `analytics_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.
  - `marketing_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.

## Response `200`

Success

- CustomerPrivacySettings
  - `business_id` integer, required
  - `revision` integer, required — Current settings revision. Read it immediately before an update.
  - `marketing_generation` integer, required — Read-only revision for material marketing configuration changes.
  - `notice_version` string, required — Current notice identifier.
  - `analytics_enabled` boolean, required — Read-only legacy owner-acceptance metadata; not a writable analytics switch and not a prerequisite for event ingestion.
  - `analytics_legal_acceptance` CustomerPrivacyLegalAcceptance, required — Read-only compatibility metadata about the current owner. It is not an event-ingestion authorization requirement.
    - `required_version` string, date, required
    - `terms_version` string, nullable
    - `terms_accepted_at` integer, nullable — Unix timestamp in seconds.
    - `privacy_version` string, nullable
    - `privacy_accepted_at` integer, nullable — Unix timestamp in seconds.
  - `analytics_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.
  - `marketing_consent_countries` CustomerPrivacyCountryCode[], required — Use the supported codes returned by GET /v3/customer-privacy. Unsupported or lowercase codes are rejected. Duplicate valid codes are accepted and normalized to a sorted unique list.
  - `country_codes` CustomerPrivacyCountryCode[], required — All supported country codes.

## Other responses

- `400` — Invalid body: invalid_customer_privacy_settings. Supply a non-negative integer revision and both complete lists of supported uppercase country codes; extra fields are rejected.
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `409` — The settings changed since the supplied revision. Fetch current settings and reconcile before retrying.
- `429` — Too Many Requests. Storefront public requests using `X-Scalev-Storefront-Api-Key` or `X-Scalev-Guest-Token` are rate-limited as direct client/browser requests. Machine-authenticated business requests are rate-limited per API key or OAuth installation. Rate-limit responses may be plain text instead of the normal JSON error shape.

## Changes

- **2026-09-20** `af4231e0cad9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/scalev/apis/nexus-commerce-api/changes/v3/customer-privacy/patch.md)

---

[API](https://skmtc.dev/scalev/apis/nexus-commerce-api.md) · [All operations](https://skmtc.dev/scalev/apis/nexus-commerce-api/llms.txt) · [OpenAPI document](https://skmtc.dev/scalev/apis/nexus-commerce-api/revisions/215156c4eee0?raw)
