Orders and support

A private support comment appeared on the parcel instructions

Work from the physical output back to the field that fed it. Identify the exact printed document, the exact text on it, and the system field whose content matches, before concluding that a support comment was exposed. Shopify documents that a printed order page can include internal Timeline comments, while packing documents are separate outputs, so the document type decides whether the text had a legitimate place. Preserve the original comment in its system of record and trace only its reference and field path here. Then name one owner to correct the mapping or the printing practice that routed it.

For: A research-only store owner or fulfillment lead who found internal support text on a printed packing or shipping document.

Updated 2026-10-01

Identify the document before judging the text

Preserve the physical or reprinted document exactly as it came out: which document it is, when it was produced, who printed it, and the order reference. A printed order page, a packing slip, a picking list and a carrier label are different outputs with different legitimate content. Shopify's documentation for printing an order page shows that the order page can carry Timeline comments; it does not establish that a packing slip carries them. So the first record to make is which document actually held the text, not which document someone assumed they were printing.

Record the exact position of the text on that document: a customer-facing address block, an instructions area, or an internal summary area. The same words are a different incident when they sit where a carrier or recipient reads instructions than when they sit in an order summary kept inside the business. In this worksheet, reference the order and quote only enough to locate the text; keep the full comment in the authorized support system.

Match the printed text to one source field

Compare the printed wording with the candidate fields on the matching order: the customer note the buyer typed at checkout, a delivery-instructions field, an internal support or Timeline comment, and any custom field created by an app. Shopify documents Timeline as a place for internal comments on an order's activity. A staff member's belief about which field they used is not the record; match the exact text, character for character, to the field that actually contains it.

Where two fields contain similar wording, record both and mark the match unresolved until the print template or mapping shows which one it pulls. Do not test by retyping the comment into a live order to see where it prints; that creates a new copy of the sensitive text. If the platform's template editor shows the source field for each printed block, capture that configuration reference rather than a screenshot full of order data.

A comment can also be copied by hand into an instructions field at packing time. If the printed text matches no stored field but matches a staff message, the routing is human, not technical, and the correction is a practice change rather than a template fix. Keep those two causes separate in the record.

Trace the mapping from field to output

Once the source field is known, follow its route to the printed document. For a template-driven document, the template decides which fields print; for an app-generated document, the app's field mapping decides. Record the template or app name, the mapped field identifier, and whether the same field feeds any other outward document, such as a warehouse export or a third-party fulfillment feed. A correction to one template does not fix a second document fed by the same field.

Distinguish three findings: the field was designed to hold buyer instructions and printed correctly, the field was internal and was mapped onto an outward document by configuration, or the document was the internal order page printed where only a packing document should have been used. Each finding has a different owner: the template or app maintainer, the staff member choosing what to print, or both. An uninspectable app mapping is a gap to record, not a reason to assume the buyer caused it.

Decide what belongs on the parcel and close the route

Write the rule that follows from the records: which field is the authorized source of parcel instructions, which documents may show it, and which fields must never reach an outward document. Where the exposed comment contained sensitive support content, treat the existing parcels as a handling question for the business owner — how many went out, to whom, and whether any recall or notification judgment is needed. That judgment belongs to the authorized owner with the actual facts; this worksheet supplies the chronology, not the decision.

The correction is complete when the template or practice change is recorded, a non-sensitive test order prints without the internal field, and the authorized owner has accounted for parcels already dispatched. Keep the original comment, the printed document reference, the mapping evidence and the correction together so the team can explain the sequence later without re-exposing the text.

If the template investigation shows the storefront or order workflow needs a wider review, a Prism consultation can start from the platform, the document type and the point where the field trace stops. Describe the routing problem without pasting the comment or customer details into the public form. Scope, responsibilities, fees and terms are confirmed before work, and a request does not purchase an implementation.

Comment-to-parcel trace

Trace one real incident using order references and field identifiers, never the full comment text. The trace is finished when the source field, the printing route and the responsible correction owner are each either established or explicitly marked unknown.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Comment-to-parcel trace. The last column is for temporary notes.
CheckpointRecord to inspect and the decision it settlesYour finding
Printed document identityThe actual output as printed, with order reference and print time. Settles which document type held the text, since Shopify treats the printed order page and packing documents as distinct outputs.
Text position on the documentWhether the wording sat in a carrier- or recipient-facing instructions area or an internal summary area. Settles the exposure scope of this incident.
Matching source fieldExact character-for-character match against the buyer note, instructions field, internal Timeline comment or app field. Settles which field fed the document; a staff recollection does not.
Field's intended audienceThe field's definition in the platform or app configuration. Settles whether the text was internal content routed outward or buyer content printed as designed.
Template or app mappingThe template block or app field mapping that pulls the source field. Settles whether the correction is a template change, an app configuration change or a printing-practice change.
Other outputs fed by the fieldEvery document, export or fulfillment feed using the same field. Settles whether one fix closes the route or several outputs need the same correction.
Parcels already dispatchedCount and destination class of parcels printed before the correction. Gives the authorized owner the facts for any handling decision about existing exposure.
Correction owner and verificationNamed owner, the change made, and a non-sensitive test print showing the internal field absent. Settles that the route is closed rather than assumed closed.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Shopify's documented print and Timeline behavior applies to Shopify; another platform's printed documents and comment fields need their own template inspection.
  • Do not claim that all packing slips include private comments; only the actual template and mapping establish what prints.
  • This worksheet does not decide notification duties or legal exposure from text already shipped; that judgment belongs to the authorized owner with the full facts.
  • Keep the full comment text, customer records and credentials out of this worksheet and the public consultation form.

Sources

  • Shopify: Printing an order page — checked 2026-10-01. A printed order page can contain internal Timeline comments, and packing documents are distinct outputs; it does not establish that all packing slips include private notes.
  • Shopify: Timeline — checked 2026-10-01. Timeline records order activity and supports internal comments, which is the field class to compare against printed text.

Get help with store operations

Need help with the order, email or fulfillment step itself?