Home Features

Features

Everything Inner Circle does

The whole list, grouped by what you are trying to get done instead of by which screen it lives on. Anything marked with a plan needs that plan. The rest is on every plan, including the free one.

Locks

The rule that says what is gated and how it looks while it is.

The Create lock screen in the Shopify admin. A "What this lock covers" card with a name and an "Applies to" menu set to All products, and a "How it looks while locked" card with the price set to "Hide the price entirely" and tick boxes for gating the buy button and showing the access code and request buttons.
The lock behind that page, in your Shopify admin. Every choice the storefront above is making is one of these.

Gate one product, or the whole store

A lock points at exactly one of seven things — the whole store, every product, collections, products, products matching conditions, pages, or URL patterns — and any of them can carry exceptions. They are set out below. Any number of locks live at the same time.

Replace the price with your own words

Per lock. Replacement text is yours: “Price on request”, “Members only”, “Trade pricing on approval”.

Gate the button and the price separately

Hide the price but keep the button, or the reverse, per lock. Gating the button is more than a change to the page: Shopify refuses the sale at the cart too. Leave it ungated and buying stays open, which is the setting working rather than failing.

The lines around the price

“Tax included”, “Shipping calculated at checkout” and the instalments banner are hidden with the price by default. That banner otherwise states the price outright, divided by four. Keep them if you’d rather.

Choose the ways in

Access code, request, or both, per lock. Also available as a standalone theme block for a header, footer or landing section.

See it before you save it

The editor draws what a locked-out visitor sees beside the settings that decide it, and redraws as you change them. It follows what is on screen rather than what is saved, so you can look at a change before committing to it. A sketch rather than your theme, which it says underneath.

Pause or archive locks in bulk

Pause, resume or archive locks in bulk once you have more than a handful. Archiving is undoable: an archived lock comes back exactly as it was.

What a lock can cover

Seven ways to say what is gated, one per lock, each of them able to carry exceptions.

The whole store

Every page of the storefront, with no list of targets to keep up to date as the catalogue changes.

All products

Every product page, and the collection and search grids that list products. Pages and blog posts are left alone.

Specific collections

Collections chosen by name from a search over your own. It matches the collection page and any product sitting in one, so a gated collection’s products stay gated on their own pages too.

Specific products

A hand-picked set, chosen by name from a search over your own catalogue rather than by finding an ID.

Products matching conditions

Rules instead of a list: tag is equal to vip, vendor contains Acme, title starts with Sample. Over a product’s tag, type, vendor or title, joined by all or any — the same shape as the conditions on Shopify’s own automated collections.

Specific pages

Pages chosen by name from a search over your own. The way to gate a wholesale terms page or a lookbook rather than a product.

URL patterns

Paths with wildcards, where * matches within one segment and ** across segments, so /collections/vip/** covers everything beneath it. The way to reach anything the other six cannot name.

Exceptions to any of them

A lock can name products, collections and pages it never applies to, mixing all three, so “the whole store except the lookbook and these two products” is one lock rather than three at different priorities.

Access codes

The fast route in. No account, no email round trip. The page unlocks where they stand.

The "What kind of code?" step in the Shopify admin, offering Shared, Single use and Limited, each with a sentence on when to use it, and a summary reading "Shared, 1 code".
Choosing what a code does. The type decides how long it keeps working.

One code for an audience, or one each

One string for a whole audience; a code that burns on redemption; or one that stops after a number of uses, a date, or both.

A code opens exactly what you choose

A code can open one lock, a set of products, or the whole store, independently of what it was created alongside.

One-tap unlock links

A link that redeems on arrival, then strips the code from the address bar so it can’t be bookmarked, shared or burned twice on a refresh.

Fix a code without reissuing it

Change a code’s cap, dates or scope in place. Correcting one no longer means deleting it and telling everybody a new string.

Every redemption names where it came from Growth

Each redemption records the campaign or creator it came from. That record is what makes the scoreboard below possible.

Take access back in one place

Disable a code and the access it granted goes with it. Access already earned survives a code being re-scoped or tidied away. Only a deliberate disable pulls it back.

The Access codes tab in the Shopify admin, listing two shared codes with the number of times each has been used, the campaign it carries, its expiry and an active status, each with Edit, Disable and Delete beside it.
Every code in one list, with the count of what it has opened. Edit changes a live code in place; Disable takes back the access it granted.

Requests and interest lists

For when you want to know who is asking before you let them in.

The Request access dialog over a product page: the visitor's interest list with the product they collected, a search box for adding more, name, email, phone with a dial-code picker, country, a "How did you hear about us?" menu, a free-text box, tick boxes for creating an account and for marketing email, and a Submit request button.
The other way in, and the form is yours. What you ask here is what tells you whether somebody belongs on the other side of the door.

The interest list

A cart’s stand-in on a store where nobody can check out. It survives a reload, and can replace the bag icon in your header.

Built-in form fields

Name, email, phone, company and country out of the box, with country and dial-code pickers, location prefill and opt-in checkboxes.

Custom form fields Starter

Add any questions you want. What you ask is what tells you whether someone belongs on the other side of the door.

Approve into a customer record

Approving creates the Shopify customer, with marketing consent recorded if they gave it, and issues them a code.

Interest list → draft order Starter

Turn what they asked for into a Shopify draft order in one click, and invoice it at your own pricing. Their access code can ride along in the invoice message.

Context on every request

Which page they submitted from, which campaign sent them, what was in their list, and any note you add afterwards.

Access tiers Growth

Access stops being in-or-out. Named, ordered levels, most exclusive first, and a lock can ask for a tier and above.

Levels you name

Gold, Silver, Trade, Press: whatever your store actually calls them. Order them, and the ordering does the rest.

Codes grant a tier

Issue a Gold code and everyone who redeems it holds Gold. A lock requiring Silver lets them in; a lock requiring Gold does not let Silver in.

Each tier writes a Shopify customer tag

Each tier writes a customer tag on redemption, so Shopify segments, discounts and Flow can key off “Gold” without knowing this app exists.

The highest tier someone holds wins

The highest tier someone holds wins, across every code they have ever redeemed. Nobody holds Gold and gets turned away from a Gold door because it came from the wrong code.

Being in scope is not enough

A code that opens “everything” but grants no tier does not satisfy a tier requirement. Otherwise one untiered code in circulation makes tiers decorative.

Renaming a tier never demotes anyone

A grant records the tier it was earned at. Renaming, re-ordering or deleting a tier later never silently demotes somebody who already has it.

Drops and scheduling Growth

Launches that happen without you being awake for them.

Start and end dates on a lock

Set when it opens and when it closes. Nothing to republish, no theme edit at midnight.

A live countdown

Before a drop opens, locked visitors see the time remaining on the page itself. A number going down is what makes people come back instead of leaving.

“Tell me when it opens”

Visitors leave an email against the drop. Asking twice, or from two pages the same lock covers, is one reminder, not two emails.

The announcement sends itself

Once a drop has opened, the reminders go out on the next daily send. The queue you built before the launch hears about it without you writing anything.

Expiring codes

Codes with their own date windows, so an early-access window really does close.

Open means open

After the end date the content is simply unlocked for everyone. A drop that has happened does not need anyone holding a code.

The waitlist Growth

What happens when you are full. People queue instead of bouncing, and the queue recruits for you.

A place in line

Someone who can’t be let in yet joins the queue and is told where they stand, instead of being turned away with nothing.

Skip-the-line referrals

Each person gets a link. Everyone who joins through it moves them up. More referrals first, and among equals, whoever joined earlier.

Release as many as you want

Let in the front ten, or the front two hundred. Everyone released is issued access and emailed in one action.

Built for deciding how many to let in

The queue screen is about deciding how many to let in. Finding one particular person is a job for the requests list, and it is there.

You are never trapped by it

Releasing people is never blocked by your plan. If you downgrade with two hundred people queued, you can still let every one of them in. Only filling the queue further is gated.

Nobody is told a stale position

Where someone stands is worked out when they ask. Nothing is stored and left to go stale as the queue moves around them.

Member invites Growth

The people already inside are the best route to the people who should be. Give them a few invitations each and let them do the asking.

A few invites each, not a free-for-all

Members hold a small, fixed number of single-use invites. Scarcity is the point: an invitation somebody can hand out forever is a public link with extra steps.

The member sends it, not us

They copy a link and send it themselves, in whatever they already use. Nobody is emailed by your store who never gave your store their address.

Every arrival is credited

You can see who brought whom. Only members you can actually name are offered invites at all, because an invitation nobody can be credited for is just a code.

Take one back, or stop them issuing more

Revoke an unused invite, or stop a member handing out any others, from the Invites screen.

Members

Who is actually inside, and a way to take one person back out without taking everybody who arrived alongside them.

Everyone who is inside, on one screen

How they got there, what tier they hold, when they were last on your store and when their access runs out. With a search box, for when you are looking for one of them.

Remove one person, not the whole code

Taking somebody's access back closes the storefront for them, stops them at checkout, and takes back any invites they had not handed out. Everyone else who came in on the same code is untouched.

Creators and campaigns Growth

Who is bringing people in, what their link is, and whether they were worth it: one place rather than three.

A screen for the creators themselves

Add, rename or delete a creator, and copy, replace or switch off their link, without going near the codes table.

One creator’s numbers

Unlocks, people, requests and draft orders for a single person, over a period you choose. The same figures the scoreboard totals.

Retiring is not deleting

Retiring keeps everything they brought in, switches their link off and stops offering their name when you make a code. They can come back. Deleting is the other one, and the screen says which it is about to do.

The creator scoreboard

Everyone compared and totalled, by campaign, over a range you choose. “Which creator was worth it” becomes a number, not an argument.

Automation and reporting

The parts that stop a busy gate from becoming a second job.

The Reports screen in the Shopify admin over the last 30 days: a "Creator scoreboard" table of campaigns with codes, unlocks, people, requests and draft orders, a "Most requested products" table of what was asked for and never bought, and the beginning of a "Where requests come from" section.
The two questions a gated store can answer and an open one cannot: which campaign brought people in, and what the people you turned away wanted.

Auto-approve rules Starter

Match on country, email domain, or the campaign a request came from, and let those through on their own. The queue then holds only the ones you need to think about.

Rules issue real access

A rule can decide what kind of code the approved request gets, and which tier it grants. It is the same approval you would have done by hand.

New rules start off

Every rule is created switched off. You write the conditions, look at them, and then turn it on. Nothing starts admitting people the moment you save it.

The demand report Starter

What the people who asked were asking for: the products piling up in interest lists that nobody has been let in to buy. The clearest signal a gated store produces.

Where requests come from

Which pages are actually producing requests, so you know which product is doing the persuading.

Email

The honest version, because this is where access-control apps quietly fail: an approval nobody receives is an approval that did not happen.

The emails send themselves

Access codes, unlock links, request confirmations and drop announcements are sent by Inner Circle directly. Shopify offers apps no general way to email a customer, so nothing here depends on you wiring one up.

They arrive from your shop, not from us

The sender name is your shop and replies go to your address. Only the technical address behind the name is ours.

Make them look like your shop

Your logo, your brand and button colour, one of four typefaces that survive an inbox, a real footer, and a light or dark set. One set of choices covers all six emails, including ones you have already rewritten.

Editable templates Starter

Rewrite what each email says. The wording around being let in to a private store matters more than most transactional email.

Written, not coded Starter

Bold, links, headings, lists and a call-to-action button. What the toolbar offers is what survives Outlook, rather than everything an editor could do.

See it before they do Starter

A live preview beside the words as you write them, and a test send of that same email to your own inbox.

Your own provider Growth

Send through your own SMTP server or Resend account instead. Your domain, your reputation, your deliverability record.

Shopify Flow triggers

Every event also fires a Flow trigger, which is how you pipe requests and redemptions into Postscript, a helpdesk or your own automation. Klaviyo has a direct connection of its own, below.

Nothing is dropped silently

Anything that cannot be delivered is shown to you in the admin with its subject and body, to send by hand. A failure you can see beats one a customer tells you about.

What each email is actually doing

The list of templates counts what each one sent and what failed over the last thirty days, so a template failing quietly on a customer’s request is visible in the place you go to write the words. Sends, not opens: nothing here tracks whether anybody read it.

Inventory

Two things a store that controls who sees what keeps asking for. Both on every plan.

Hide sold-out products

Sold-out cards are dropped from collection and search grids. Found by your theme’s own sold-out badge rather than by asking you to name a CSS selector.

Show a low stock badge

A badge on the product page at or below a threshold you set, in wording you write. Showing the exact number left is off by default, and counts above ten never reach the page at all, so the real figure cannot be read out of it.

Integrations and developers

Where Inner Circle stops being the only thing that knows who is in.

Captured leads go to your Klaviyo Growth

Connect your own Klaviyo account, pick one of your own lists, and everyone this app captures lands in it carrying where they came from: a request, an interest list, the waitlist, or a member already inside. Only people who ticked the marketing box on your request form are ever sent, and a revoked key or a Klaviyo outage never stops a request being taken.

An API your own systems can read Growth

A named credential lets your server, your ERP or your agency’s middleware ask who is unlocked and read back your grants and access requests over HTTPS. Read-only, scoped to the shop that minted it, rate limited, and it never hands back a redeemable code — codes come back by label, tier and use count. The answers come from the same decision your storefront gives a shopper. The API reference has every endpoint and field.

A theme can ask whether this visitor is in

Put data-ic-show="unlocked" — or locked, member, guest, or tier:Gold — on any markup and it appears only for the right visitor, with no flash of the wrong version and no JavaScript to write. A documented, versioned JavaScript API covers anything the attributes cannot. It publishes what the app decided and never the rules behind it, so a theme cannot end up with its own drifting copy of your access rules. Every plan, including Free. Read the theme contract.

And the things that are not features

Worth saying on a features page, where everything is written to sound good.

  • The gate fails open. If we cannot be reached within four seconds your page reveals itself unlocked. That is deliberate, because our outage must not blank your storefront. It does mean hidden prices can become visible during one.
  • Checkout enforcement does not come from every lock. Locks that name their products, and locks covering the whole store, are enforced at the cart. Locks pointed at a collection, or at conditions like a tag, a vendor or a product type, are not yet — they gate the storefront and stop there. Nor is a lock you set to hide the price while leaving buying open, which is that setting doing its job. A price may still be readable from a cached copy, a search result or a product feed.
  • The checkout check fails open too. If our check cannot run or takes too long, Shopify completes the sale rather than holding up your customer. The same reasoning as above: our fault should cost us a locked sale, not cost you a paying one.
  • Revoking access is not instant at the checkout. The storefront closes to someone the moment you revoke them. A shopper carrying an access code can hold a valid checkout pass for up to about a day and a half after that, until it expires. Take the product off sale if somebody has to be stopped immediately.
  • Locks on specific products don’t gate collection grids. The decision is per page, and hiding every price in a collection because three products are locked would be worse than the problem.
  • Theme compatibility is best effort. Broad selectors, plus a field for your own. Check yours.

All of it, in full, in the Terms of Service.

The questions this raises

Can someone get around it with devtools?

They can make the button reappear, and you should plan for that rather than be surprised by it — but what it gets them is a button. Every gate decision, code check and request is handled on our servers behind Shopify’s cryptographic verification, so nobody edits themselves into a tier or forges a redemption. And where the lock is one Shopify enforces at checkout, the sale is refused at the cart, so a hand-built cart link ends in a rejection rather than an order. That covers locks naming their products and locks covering your whole store; a lock pointed at a collection or at conditions like a tag is still a storefront control and stops there, as is a lock you have set to hide the price while leaving buying open. If our check cannot run at all, Shopify completes the sale rather than hold up your customer. Where a product must be unbuyable under every one of those conditions, unpublish it.

Can I have different levels of access, not just in or out?

Yes. That’s what access tiers are. You name and order the levels, a code grants one, and a lock can require a given tier and above. Each tier also writes a customer tag, so Shopify segments and discounts can act on it without knowing this app exists. Tiers are on the Growth plan.

Do the emails actually send? Shopify doesn’t let apps send email.

They do, and you’re right about Shopify: it offers apps no general way to email a customer. So Inner Circle sends the customer-facing mail itself: access codes, unlock links, request confirmations and drop announcements. The sender name is your shop and replies go to your address, so only the technical address behind the name is ours. Anything that can’t be delivered is shown to you in the admin to send by hand, never silently dropped, and on Growth you can send through your own SMTP server or Resend account instead.

Where is my data stored, and for how long?

In the European Union, in Frankfurt, encrypted in transit and at rest. When you uninstall, everything belonging to your store is permanently deleted 48 hours later, so export anything you want to keep first. The detail is in the Privacy Policy.

All 15 questions

Ready to put a door on it?

Inner Circle installs from the Shopify App Store in a couple of minutes, and nothing on your storefront changes until you turn the app embed on.