8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This is Shopify's Privacy Policy explaining how Shopify collects and uses personal information from merchants who build stores on Shopify, shoppers who buy from those stores, and anyone who visits Shopify's website. The most important thing to know is that Shopify shares your personal data — including name, contact details, purchase history, device identifiers, and browsing behavior — with third-party app developers, payment processors, advertising partners, and other merchants in its network for purposes including fraud prevention, analytics, and marketing. If you are a shopper on a Shopify-powered store, you should contact the individual merchant directly to exercise data rights, as the merchant — not Shopify — is the controller of your purchase data.

Technical Summary

This document is Shopify's global Privacy Policy governing the collection, use, storage, and disclosure of personal information from merchants, shoppers, partners, and visitors across Shopify's platforms, with legal basis rooted in contractual necessity, legitimate interests, consent, and legal obligation depending on jurisdiction. The policy creates obligations for Shopify to respond to data subject access requests, honor opt-out requests for marketing and certain data sharing, and maintain data transfer mechanisms for cross-border transfers including Standard Contractual Clauses for EU/EEA data. Notable provisions include Shopify's broad information sharing with third-party partners, app developers, and payment processors without granular consent requirements for operational sharing, as well as retention of aggregated or de-identified data indefinitely — a practice that carries re-identification risk not fully addressed in the document. The policy explicitly engages GDPR (including Chapter V transfer mechanisms), CCPA/CPRA, Canada's PIPEDA, and implicitly LGPD and other national frameworks given the 70+ jurisdiction-specific alternate URLs; Shopify acts as both a data controller (for merchant and visitor data) and a data processor (for end-customer data processed on behalf of merchants), creating a layered compliance obligation that requires careful role delineation. Material compliance considerations include ensuring merchant-customers have adequate processor agreements in place with Shopify, that consent mechanisms on merchant storefronts satisfy jurisdiction-specific standards, and that Shopify's use of shopper data across its merchant network for network-wide fraud prevention and analytics is disclosed and lawful under applicable frameworks.

Evidence Provenance
Captured April 19, 2026 06:08 UTC
Document ID CA-D-000122
Version ID CA-V-000693
Wayback Machine View archived versions →
SHA-256 7c0bf9501b86d83070ac3cc9fece30882778eaa6a5728dc77b7719cbe2fa974d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Institutional Analysis

🔒 Institutional analysis locked

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Upgrade to Professional — $149/mo
Change Timeline
View full version history (0 captures) →
High Severity — 1 provision
Medium Severity — 6 provisions
Low Severity — 1 provision

Cross-platform context

See how other platforms handle Cross-Context Behavioral Advertising via Shop App and similar clauses.

Compare across platforms →

Applicable Regulations

CCPA/CPRA
California, USA
CFAA
United States Federal
CAN-SPAM
United States Federal
DMCA
United States Federal
DSA
European Union
GDPR
European Union
UK GDPR
United Kingdom