10 Total
1 High severity
8 Medium severity
1 Low severity
Summary

This is Shopify's privacy policy, which explains what personal information Shopify collects about merchants, shoppers, and visitors, how it uses that information, and who it shares it with. If you use Shopify to run a store or shop on a Shopify-powered site, Shopify collects data such as your name, email, purchase history, browsing behavior, and payment details. You have rights to access, correct, or delete your data, and you can contact Shopify's privacy team to exercise those rights.

Technical Summary

Shopify's Privacy Policy governs the collection, use, disclosure, and retention of personal information across Shopify's merchant-facing platform, consumer-facing services (including the Shop App), and related products. The policy distinguishes between Shopify acting as a data controller (for merchant and visitor data) and as a data processor (for data merchants collect about their own customers). Key rights afforded to users include access, correction, deletion, portability, and objection to processing, with jurisdiction-specific provisions for GDPR (EEA/UK), CCPA/CPRA (California), and other regional frameworks. Notable provisions include cross-border data transfers with Standard Contractual Clauses as a safeguard, use of data for marketing and product improvement, sharing with third-party service providers and advertising partners, and retention of data for legal and fraud-prevention purposes even after account closure.

Institutional Analysis

The policy engages GDPR (with SCCs for cross-border transfers and dual controller/processor roles), CCPA/CPRA (with explicit California consumer rights disclosures), and Canada's PIPEDA. Compliance t…

The policy engages GDPR (with SCCs for cross-border transfers and dual controller/processor roles), CCPA/CPRA (with explicit California consumer rights disclosures), and Canada's PIPEDA. Compliance teams should note Shopify's distinction between its controller role (merchant and visitor data) and p…

🔒

Compliance intelligence locked

Regulatory exposure, material risk, and due diligence action items.

Evidence Provenance
Captured March 15, 2026 06:04 UTC
Document ID CA-D-000122
Version ID CA-V-000100
Wayback Machine View archived versions →
SHA-256 df98f1fad1002dcce5ed6efc633df7380aa25064eee5aeb0b0ff6b6e89494bc7
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Change Timeline
High Severity — 1 provision
Medium Severity — 8 provisions
Low Severity — 1 provision