Shopify · Shopify Privacy Policy

Dual Controller Structure — Merchants as Independent Data Controllers

High severity
Share 𝕏 Share in Share

What it is

Shopify merchants are independent data controllers when they use our services. This means that merchants, not Shopify, are responsible for their customers' data collected through their stores. Merchants are responsible for obtaining any necessary consents from their customers and for complying with applicable data protection laws.

Why it matters

This provision allocates primary data controller responsibility to individual merchants, which means the compliance quality of your data protection varies significantly depending on the merchant you buy from, and Shopify's protections may not fully extend to your data in a merchant-specific context.

Consumer impact

Shopify collects a wide range of personal data including contact details, payment information, browsing behavior, device identifiers, and purchase history from both merchants and end consumers shopping at Shopify-powered stores. This data is shared with an extensive network of third parties including advertising platforms, fraud detection vendors, payment processors, and third-party app developers, meaning your shopping behavior across multiple stores may be aggregated and used for targeted advertising without your explicit awareness. You can opt out of cross-context behavioral advertising and exercise data access or deletion rights by visiting Shopify's privacy request portal at https://privacy.shopify.com/en/consumer.

Applicable agencies

  • FTC
    The FTC has authority to pursue merchants for deceptive or unfair data practices under Section 5, including failure to honor stated privacy commitments to consumers.
    File a complaint →
  • State AG
    State Attorneys General (particularly California) can enforce CPRA compliance obligations against merchants acting as independent controllers.
    File a complaint →

Provision details

Document information
Document
Shopify Privacy Policy
Entity
Shopify
Document last updated
March 24, 2026
Tracking information
First tracked
March 15, 2026
Last verified
April 4, 2026
Record ID
CA-P-002222
Document ID
CA-D-00122
Evidence Provenance
Source URL
Wayback Machine
SHA-256
929225abb20671960ed1f40a6325a4c72cf5ea341e79aa8378056b3b66ef5708
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Shopify | Document: Shopify Privacy Policy | Record: CA-P-002222
Captured: 2026-03-15 11:22:02 UTC | SHA-256: 929225abb2067196…
URL: https://conductatlas.com/platform/shopify/shopify-privacy-policy/dual-controller-structure-merchants-as-independent-data-controllers/
Accessed: April 6, 2026
Classification
Severity
High
Categories

Other provisions in this document