Shopify · Shopify Acceptable Use Policy

Malware, Hacking, and Security Threat Prohibition

Medium severity
Share 𝕏 Share in Share 🔒 PDF

What it is

Merchants and users cannot use Shopify to spread viruses, malware, or any malicious software, or to attack or disrupt Shopify's systems or other websites.

Consumer impact (what this means for users)

This clause protects consumers whose payment information and personal data are processed through Shopify stores from cybersecurity threats introduced through the merchant's account, though consumers have no direct mechanism to verify a specific store's security posture.

How other platforms handle this

Netflix Medium

The Netflix service is provided "as is" and without warranty or condition. In particular, our service may not be uninterrupted or error-free. You waive all special, indirect and consequential damages against us. These terms will not limit any non-waivable warranties or consumer protection rights tha...

Amazon Medium

TO THE FULL EXTENT PERMISSIBLE BY LAW, AMAZON DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.

Google Maps Medium

You will not reverse engineer, decompile, disassemble, translate, or attempt to extract the source code of the Maps APIs or any component thereof.

See all platforms with this clause type →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

This provision protects both Shopify's infrastructure and the consumers who transact through Shopify-powered stores, but merchants who inadvertently host compromised third-party apps or themes that introduce malware may face account termination even without direct fault.

View original clause language
You may not use Shopify's Services to transmit any malware, viruses, or other malicious code, or to engage in any activity that interferes with or disrupts the integrity or performance of the Services or related systems.

Institutional analysis (Compliance & legal intelligence)

(1) REGULATORY FRAMEWORK: This provision engages the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030) prohibiting unauthorized computer access and damage; the Electronic Communications Privacy Act (ECPA, 18 U.S.C. §§ 2510–2523); PCI DSS (Payment Card Industry Data Security Standard) v4.0 which governs all merchants processing card payments through Shopify; FTC Act Section 5 (reasonable security obligation as established in FTC v. Wyndham); and the NIST Cybersecurity Framework. For EU merchants, GDPR Article 32 requires appropriate technical security measures. Enforcement: DOJ (CFAA), FTC (Section 5 security), card brands and acquiring banks (PCI DSS). (2)

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    FTC enforces reasonable data security standards under Section 5 of the FTC Act and has brought numerous enforcement actions against online commerce platforms for inadequate security practices
    File a complaint →

Provision details

Document information
Document
Shopify Acceptable Use Policy
Entity
Shopify
Document last updated
April 29, 2026
Tracking information
First tracked
March 15, 2026
Last verified
April 10, 2026
Record ID
CA-P-002660
Document ID
CA-D-00124
Evidence Provenance
Source URL
Wayback Machine
SHA-256
c3d037196ffbb1471c40eb696d0527749e9581d33970cdd9620dc96a8e8dfbdb
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Shopify | Document: Shopify Acceptable Use Policy | Record: CA-P-002660
Captured: 2026-03-15 12:02:55 UTC | SHA-256: c3d037196ffbb147…
URL: https://conductatlas.com/platform/shopify/shopify-acceptable-use-policy/malware-hacking-and-security-threat-prohibition/
Accessed: April 29, 2026
Classification
Severity
Medium
Categories

Other provisions in this document