Applications Guide

Learn how to manage B2B customer applications — review, approve, reject, and request more information.

Application Lifecycle

When a customer submits a registration form on your storefront, an application is created with a pending status. (If your plan's monthly application limit has been reached, it is saved as held instead and becomes pending automatically when capacity opens up — see Held Applications and Plan Limits.) From there, you review the submission and take one of three actions:

  • Approve — creates a Shopify customer account and sends a welcome email
  • Reject — declines the application and notifies the customer
  • Request more information — asks the customer for additional details before deciding

The status flow is: pendingapproved / rejected / info-requested. You can manually update the status at any time from the application detail page.

Buyer Status Page

You can give applicants a personal link to a read-only status page in their confirmation email. The buyer can open it at any time to see where their application stands — no account or login required. The page is per-application: the link arrives only in that applicant's "we received your application" email and is not a shared URL.

To include the link, add the {{statusUrl}} variable to your Application Received — Customer template under Settings → Email Templates (it appears in that template's Available variables list). New installs include it by default; if you customised this template earlier, add the variable yourself to switch the status page on.

The page shows a single, plain-language status and nothing else. It never exposes internal notes, reviewer names, raw form data, or other private fields. Statuses map as follows:

  • Under review — the application has been received and is being reviewed (pending or in review).
  • More information requested — you have asked the buyer for additional details; they should check their email.
  • Approved — the wholesale account has been approved.
  • Not approved — the application was declined.

The page is read-only — buyers cannot edit their submission, re-upload documents, or resend the link from it. Status links expire for security; once expired, the page shows a neutral "this link has expired" message directing the buyer to their latest email or to contact the store.

Viewing Applications

The applications list shows all submissions across your forms, except submissions held in Quarantine. Each row displays the customer name, email address, associated form name, submission date, and a colour-coded status badge.

Applications list with status badges and filtering options

Before your first application arrives, this page shows a 'No applications yet' panel. Its primary action, Create sample application, generates a one-click demo submission so you can try the full review-and-approve flow immediately — no need to wait for a real buyer (see Sample applications below). The panel also lets you copy your registration link, preview the form as a customer, and open Shopify's navigation editor to add the link to your store menu.

Sample applications

A sample application is a one-click demo submission that lets you experience reviewing and approving a wholesale application before any real customer applies. Create one from the empty Applications panel, from the Submit and approve your first application item in your setup guide, or from the final screen of the onboarding wizard.

The sample is tailored to your store's country: an EU/UK store reviews a buyer with a verified VAT number, an Australian store sees a verified ABN, a New Zealand store a verified NZBN, and a US store opens a buyer with an attached, verified resale certificate you can preview and download — all shown through the same verification badges as real applications.

Sample applications are clearly labelled with a Sample badge on the list and detail pages, and the detail page carries a banner reminding you it is demo data. They are safe to remove: the detail page has a Delete sample action (the only application delete path — real applications are never deleted). Samples never send an email to the sample buyer, never trigger Shopify Flow, and never count toward your monthly plan usage. The one email that does send is your own merchant notification, so you can confirm your alerts are working.

Filtering and Searching

Use the status filter tabs at the top of the list to narrow down applications:

  • All — every application regardless of status, except submissions held in Quarantine (those have their own page)
  • Pending — applications awaiting your review
  • Held — applications that arrived after your monthly plan limit was reached (see Held Applications and Plan Limits)
  • Info Requested — applications where you have asked for more details
  • Approved — applications you have approved
  • Rejected — applications you have declined
  • Imported — applications created by a company CSV import rather than submitted by a buyer (see the migration guide)

Imported applications are marked with an Imported badge on the list — and their companies carry the same badge on the Companies page — so a migrated back-catalogue is always distinguishable from organic sign-ups. They are excluded from your dashboard performance metrics and weekly digest, so an import never inflates your approval rate, response time, or time-saved numbers.

If you delete a company in your Shopify admin, opening its record here tells you so: a banner explains the company was deleted in Shopify, so contacts, locations and roles can no longer be shown, while the record itself is kept for its application and credit history. From then on it carries a Missing badge on the Companies page instead of Active. We check when you open the record rather than polling Shopify, so a company you deleted still shows its old badge until someone opens it.

You can also search by customer name or email address using the search field to quickly find a specific application.

Held Applications and Plan Limits

Each plan includes a monthly application allowance (Free 10, Starter 50, Growth 250, Pro unlimited). Reaching your limit never turns an applicant away: your registration form keeps working exactly as before, the applicant submits normally and receives the usual confirmation, and nothing in their experience mentions your plan.

Applications that arrive past the limit are saved in full with a Held status. You can open a held application and read everything — contact details, addresses, tax IDs, uploaded documents — the data is yours. What waits until you have capacity is processing: Approve, Reject, and Request More Info are disabled, auto-approval rules don't run, and no customer or B2B company is created yet.

Held applications are released automatically, oldest first, in two situations:

  • A new month starts — released into the fresh allowance until the limit is reached again. Nothing is ever deleted or lost.
  • You upgrade — released immediately, up to the new plan's allowance (a Pro upgrade releases everything).

So you always know where you stand, B2B Onboard shows a usage banner on every page from 80% of your allowance, a used/limit meter on the Applications page, and sends you at most two emails per month: one as you approach the limit and one when the first application is held.

Quarantine (spam holds)

Public registration forms attract junk. When the spam checks judge a submission suspicious, it is held back on the Quarantine page instead of landing in your Applications list. Whoever submitted it sees the same confirmation page as everyone else, so a spammer gets no feedback about what was filtered.

A quarantined submission is inert. It is not counted in your Applications list or your monthly plan usage, it sends no notification email to you and no confirmation email to the submitter, and it cannot be approved, rejected, or actioned by an automation while it sits there. Nothing is deleted behind your back — the full submission is stored, and restored intact if you mark it as not spam.

The Quarantine page lists who submitted it: the company name, the contact name and email address, when it arrived, and badges naming the checks that flagged it, so you can judge at a glance. Two actions are available:

  • Not spam — restores the submission to your Applications list as pending, and runs everything a normal submission would have run: your notification email, the applicant's confirmation, auto-approval rules, and any connected Shopify Flow. It then counts toward your monthly allowance like any other application.
  • Delete — select the rows you are sure about (up to 10 at a time) and delete them permanently, after a confirmation step. Deleting removes the submission and its history for good.

Click any held submission to review it in place. A panel opens showing everything that was submitted, answer by answer, alongside a plain-language explanation of each check that fired — and where a link was the reason, the answer that contained it is marked. Not spam and Delete are both available from the panel, so you can decide without leaving the page.

The badges name the checks that flagged the submission, and the set of checks grows over time. One you will see is link_spam: a web address was pasted in among other words in a free-text answer, such as a notes or "tell us about your business" field. That is a common shape for junk, but a genuine applicant occasionally includes their own website, so these submissions are held for your review rather than turned away. An answer that is only a web address, with nothing else in the box, is not flagged at all — that is someone answering a "your website" question, whichever free-text box your form gave them for it. And when a held answer links to the same domain as the applicant's own email address, the review panel marks it with an Applicant's own domain badge, so you can see at a glance that they linked their own site rather than someone else's.

Other badges describe where the submission came from rather than what it said. Your form hands out a single-use pass each time its page is loaded on your storefront, and a submission spends that pass when it arrives. A submission that carries no pass — typically a script posting straight at the address your form uses, without ever loading the page — is held with a form_token_missing badge. One that reuses a pass already spent, which usually means a page was sent twice after pressing the browser's Back button, is held with form_token_replayed. A pass also goes stale if a form is left open for more than a day before being sent. In every one of those cases the submission is held for your review, never discarded, and Not spam restores it exactly as it does any other hold.

Volume is watched too. When submissions arrive unusually fast from the same network, or unusually many turn up in a single day for one store or from one email domain, the ones over the line are held for review the same way, with a badge starting rate_limit naming which limit was crossed. The limits sit far above what a normal week of genuine registrations looks like, so this generally only shows up during a burst — and as with every other hold, nothing is turned away or deleted: Not spam restores the submission intact.

You don't have to remember to check the page. While anything sits in Quarantine, your Dashboard shows a "Quarantined submissions" row on the Action Required card, the Action required page lists a "Spam quarantine" row showing how long until the oldest hold is removed, and your weekly digest email includes the count — a week where quarantine holds are the only news still sends the digest. Each of them takes you straight to this page.

Separately, the form runs a couple of invisible checks that only automated scripts trip — an unused field a person never sees, and a submission that arrives faster than anyone could type. Submissions that trip those are discarded on the spot: they are not stored, do not appear in Quarantine or the Applications list, do not count toward your plan usage, and send no email. Whoever submitted still sees the ordinary confirmation page, so a bot gets no clue that it was filtered. No check like this is perfect, and none of them replaces reading the applications you receive.

Anything you leave in Quarantine is removed automatically after 30 days, so filtered junk does not pile up. Review the page occasionally — the checks are deliberately cautious, but a real customer can still be flagged, and "Not spam" puts them straight back into your normal workflow.

Application Detail

Click any application to open its detail view. Here you will find the full submission data including all form fields, any uploaded files, and the complete action timeline showing every status change and note.

Application detail page with VAT verification and approve/reject buttons

Approve

Approving an application triggers three actions:

  1. Creates a Shopify customer account using the submitted contact information (name, email, phone, and address fields). Phone numbers are automatically normalized to international format (E.164) before they reach Shopify. If the phone number is already assigned to another Shopify customer, or Shopify will not accept the format it was submitted in, you can still approve — a confirmation appears, and the phone number is omitted from the new customer account. Applications waiting on a phone number Shopify will not accept also show up under Action required, so a lead never goes quiet while you track down the right number.
  2. Applies customer tags from your Approved tags list (Settings → Customer Tags) plus any per-option tags attached to the applicant's selected form field options, so you can identify B2B customers in Shopify admin and set up automatic discount rules
  3. Sends an approval email notifying the customer that their application has been accepted

Reject

Rejecting an application sends a rejection email notification to the customer. The application remains in the system for your records — it is not deleted. You can still view the full submission and timeline at any time. (The only exception is a sample application, which you create yourself for testing and can remove with its Delete sample action.)

Request More Information

If you need additional details before making a decision, you can request more information from the customer:

  1. Click Request Info on the application detail page
  2. Write a custom message explaining what additional information or documents you need
  3. The application status changes to info-requested and the customer receives an email with your message
  4. After receiving the customer's response through other channels (email, phone, etc.), you can manually update the application status to continue the review

Note: Customer responses are received through your regular communication channels (email, phone). The application timeline can be updated manually to reflect the response.

Customer Tags

When you approve an application, B2B Onboard applies tags from two sources: the Approved tags list configured in Settings → Customer Tags, and any per-option tags attached to options the applicant selected on select or multi-select form fields. Both are merged additively — existing tags on a returning customer are preserved and never removed.

Tags are useful for:

  • Identifying B2B customers in Shopify admin — filter your customer list by tag to see all wholesale accounts
  • Automatic discount rules — create Shopify discounts that apply only to customers with specific tags
  • Segmentation — use tags to build customer segments for targeted marketing or reporting

Bulk Actions

Select multiple applications using checkboxes on the Applications page to approve or reject them all in one action.

Bulk actions respect Shopify API rate limits and process sequentially. Each application in a bulk action gets its own timeline entry, email notification, and customer account (if approved).

VAT/Tax ID Verification

When a form includes a Tax ID field, several kinds of number are verified automatically against their official register:

  • EU VAT numbers are checked against the VIES database
  • UK VAT numbers are checked against HMRC's VAT lookup
  • Australian ABNs are checked against the Australian Business Register (ABR)
  • New Zealand NZBNs are checked against the NZBN register
  • Norwegian organisation numbers are checked against Brønnøysundregistrene, which also reports MVA (VAT) registration status
  • Numbers from other countries are accepted and stored, but not auto-verified — Canadian GST/HST numbers, for example, are format-checked only (see below)

For a Norwegian application, the detail page shows an Org.nr Verification (Norway) card with the registry's official name and registered address, the organisation form (AS, ASA, ENK, NUF and so on), and whether the company appears in the MVA register. Not being in the MVA register is normal for new or small Norwegian businesses, so it is shown as plain context rather than a warning.

Verification status appears as a badge on the application detail page: Verified, Invalid, or Pending.

You can re-verify a tax ID at any time from the application detail page — this applies to VAT numbers, ABNs, NZBNs and Norwegian organisation numbers alike. When an application with a verified VAT is approved, the customer can be automatically marked as tax-exempt in Shopify.

The full verification evidence — status, the verified company name and address, the verification source, and the VIES consultation number (a timestamped proof token issued by VIES) — is recorded on each application and included in the applications CSV export. This gives you the documentation needed to defend a reverse-charge claim under EU VAT rules.

Canadian GST/HST numbers

B2B Onboard does not verify Canadian GST/HST numbers — the Canada Revenue Agency (CRA) publishes no public lookup service an app can call. Instead, a Canadian application's detail page shows a GST/HST Registry check: a one-click link to the official CRA registry with the nine-digit Business Number ready to copy, so the lookup takes seconds.

The CRA tool asks for three things: the nine-digit Business Number, the business name in the exact form it was registered (slight variations will not match), and a transaction date. Once you have looked it up, record what the registry showed — Registered, Not registered, or Not found. Your answer is stored on the application with a timestamp and appears in the timeline, so the evidence behind your decision stays on file.

This is identity decision-support only: it records what you saw, and it does not change tax treatment or grant any exemption. For buyers whose address is in Quebec, the card also notes that QST registration is a separate provincial registration with its own number format (ten digits followed by TQ and four digits — it is not the GST/HST number, and the application form does not collect it); if the buyer provides their QST number, it is looked up at Revenu Québec, not at the CRA.

Certificate Review

When an applicant uploads a resale or tax-exemption certificate, B2B Onboard reads the document and flags anything that doesn't match the application — the legal business name, issuing state, tax ID, or expiry date — so you can review faster and approve with more confidence. It is decision-support: the app flags mismatches and you make the final decision. A flag means "take a closer look," not "deny," and it does not block approval.

Each certificate carries one of five statuses — collected, verifying, verified, flagged, or needs review. Certificate review is available on the Growth and Pro plans.

On Pro, existing customers can also renew certificates themselves through a secure self-service link, with automatic expiry reminders — each renewal reviewed the same way. See the Certificates Guide.

For the full walkthrough — what each status means, reading confidence, approving a flagged application, your responsibilities, and how documents are processed — see the Certificates Guide.

Business Verification (KYB)

From a company's detail page you can run a business-registry check (KYB — know your business) against the official company register for the company's jurisdiction. Enter the registration number, pick the jurisdiction, and B2B Onboard looks the company up, compares the registry's official name, registered address, and lifecycle status against the details you hold, and surfaces anything that doesn't line up.

It is decision-support, exactly like certificate review: the check flags discrepancies for you to review — it never approves or rejects a company for you, and it never blocks anything. A human (you) always makes the call.

Covered registries:

  • Denmark — CVR (Det Centrale Virksomhedsregister, the open Danish business register)
  • Norway — Brønnøysundregistrene (Enhetsregisteret, the open Norwegian entity register)
  • France — the open company register
  • Finland — the open business information system
  • Czechia — the open business register
  • Brazil — the open CNPJ register
  • United Kingdom — Companies House (the free public company register)
  • New Zealand — the NZBN register

The first six registries are open and always available. The United Kingdom and New Zealand registries need API access, which is already configured. Additional registries (for example Australia and Ireland) appear in the jurisdiction list once their API access is configured.

The result carries one of these advisory statuses: Verified (the registry confirmed the company and nothing was flagged), Flagged (a name/address mismatch, an inactive registry status, or a duplicate VAT/email/address elsewhere in your shop needs a look), Pending (the check hasn't completed yet), Not found (the registry has no company for that number — check the number and jurisdiction), or Unavailable (the registry couldn't be reached or isn't configured — verify manually and re-check). A plain-language match confidence band (High / Medium / Low) summarises how closely the registry record matched — never a raw percentage.

A free/consumer contact-email domain is surfaced as an informational signal on the KYB card for context; on its own it does not change a Verified result to Flagged or add a worklist row.

Flagged and Unavailable companies appear on the Action required worklist as a "KYB review" row, so nothing slips through. You can re-run the check at any time from the company's KYB card.

B2B Company Creation

On stores with native B2B enabled, approving an application creates or matches a B2B Company in Shopify depending on your matching configuration. The Company includes:

  • A contact from the applicant's details
  • A location from address fields
  • The tax ID from the form submission

If you have configured a B2B catalog in Settings, it is automatically assigned to the new Company. If catalog assignment fails (for example, the catalog no longer exists, or your plan's catalog limit has been reached), the approval still completes and a "Catalog not assigned" warning appears in the success message — the Company is created and you can assign the catalog manually in Shopify.

On the Basic, Grow, and Advanced plans a catalog can't be assigned to a company directly, so wholesale pricing arrives through a market instead: the Company's location is added to your Default B2B market (set in Settings, and overridable per application in the Approve dialog), and the application timeline records "Added to B2B market". If that step fails, the approval still completes and a "Market not assigned" warning appears in the success message — you can add the location to the market manually in Shopify admin. A company location inherits its market's currency, catalogues and tax settings, so choose a market whose region and currency match these buyers: a Danish buyer added to a market under the Canada region would check out in CAD. If you sell into several regions, create one B2B market per region and pick the right one on each application.

If company creation fails: Company creation works best with a valid phone number in international format (e.g. +1 555 123 4567) and a recognised country on the address field. If the phone or address data can't be used — or company creation otherwise fails — the customer is still approved and can transact immediately. The company-creation failure is recorded with its reason, a "B2B company not created" warning appears in the success message, and you can fix the data and retry company creation from the application detail page. A "companies need attention" nudge on the Dashboard also surfaces approved applications whose company creation failed so none are missed.

This feature is detected automatically — no setup needed. If your store has native B2B access, Companies are created on approval.

B2B Company Matching

When company matching is enabled in Settings, the application detail page shows a B2B Company Matching card in the right sidebar for pending applications. The card evaluates three independent signals to determine whether the applicant may belong to an existing B2B Company:

  • VAT / Tax ID — high-confidence signal. Matches the applicant's VAT number against existing company contacts' notes.
  • Email domain — medium-confidence signal. Compares the applicant's email domain against contacts in existing companies. Freemail providers (Gmail, Yahoo, etc.) are excluded automatically.
  • Company name — low-confidence signal. Exact case-insensitive match against existing company names.

The matching card displays one of three states:

  • Existing company found (amber) — a high-confidence match was detected. Shows the company name, contact count, and which signals matched. You can choose Add to company to assign the applicant as a contact on the existing company, or Create new to create a separate company as usual.
  • Possible match — verify manually (red) — a low or medium-confidence match was found. The same options are available, but Create new is visually emphasised as the safer default.
  • No matching company found (blue) — no signals matched. A new B2B Company will be created on approval.

If you click Approve Application without selecting an option on the matching card, a prompt appears asking you to choose before proceeding.

When VAT auto-match is enabled in Settings and a high-confidence VAT match exists, the applicant is automatically assigned to the existing company on approval without prompting. The matching card still appears on the review page for transparency.

Sync from Shopify (existing companies)

If your store already had B2B Companies in Shopify before you installed the app, open Companies and click Sync from Shopify. The sync is read-only against Shopify — it never creates or changes Shopify companies, locations, or customers. For each company the app doesn’t know yet, it creates an app-side company record plus a pre-approved application (labelled Shopify sync in the Applications list), so certificate collection and review work exactly as they do for companies onboarded through an application.

The sync records every contact and every location of each company (as references — the data itself stays in Shopify). The results card shows how each company was handled: Created, Skipped (already in the app), No contact, or Failed. Certificate links go to the company’s main contact (or its only contact, when just one exists). A company with no usable contact is still tracked — add a main contact in Shopify and run the sync again, and it becomes link-capable with no duplicates. Re-running is always safe: already-synced companies pick up newly added contacts and locations, or are simply skipped.

Timeline and Audit Trail

Every action taken on an application is logged with a timestamp and the actor who performed it. The timeline on the application detail page shows the full history, including:

  • Submission — when the customer originally submitted the form
  • Status changes — approvals, rejections, and information requests with who made the decision
  • Notes — any messages sent to the customer when requesting more information
  • Customer responses — when the customer replied to an information request and what they provided

This audit trail gives you a complete record of every interaction, which is helpful for compliance and team handoffs.