Clicks & Carts

Shopify privacy policy: what it needs to say

Shopify can generate one. It will not know about your twelve apps, your pixels, or where your data actually goes.

6 min read · Store setup ·

Shopify can generate a privacy policy from the admin. It's a reasonable skeleton and a poor finished document, for one specific reason: it doesn't know what you've installed. Your apps, pixels and integrations are what actually determine where customer data goes, and the generated text has no idea they exist.

This is a practical guide to what the policy needs to cover, not legal advice — the specifics depend on where you and your customers are, and it's worth a lawyer's eyes if the stakes justify it.

What it has to cover

What you collect. Order and delivery details, contact information, payment information (which Shopify and your gateway handle, not you), browsing behaviour, and anything you ask for in forms.

Why. Fulfilling orders, support, marketing, fraud prevention, legal obligations. Be specific — "to improve our services" is filler.

The legal basis, where your jurisdiction requires one — contract, consent, legitimate interest.

Who receives it. This is the section that's always wrong, and it's the one that matters most. Every app with access to customer or order data, your payment provider, your shipping carriers, your email platform, your analytics and advertising pixels, and any system you've integrated.

Where it goes. International transfers, if data leaves your region.

How long you keep it.

What customers can do — access, correction, deletion, objecting to marketing, and how they exercise those rights.

Cookies and tracking, and how consent is handled.

Contact details for privacy questions, monitored by a person.

The recipients list is the real work

Open your apps list and go through it. For each one, ask: does it receive customer or order data? Most do.

Then add: your payment provider, your carriers, your email tool, your analytics, every advertising pixel, your accounting integration, your review platform, your chat widget.

That list is longer than merchants expect and it's the concrete, checkable part of the policy. It's also a useful audit in its own right — most stores discover an app nobody remembers installing that has full order access. If it's not earning its place, remove it; you'll be removing several anyway.

If you serve regions requiring consent before non-essential cookies, you need a consent mechanism that actually gates the pixels rather than a banner that informs people while everything fires anyway.

Shopify has native consent tooling and there are apps. Whichever you use, test it: load the store in a private window, decline, and check in the browser's network tab that the advertising pixels genuinely don't fire.

Where stores get it wrong

  • Copying a competitor's. It describes their apps and their jurisdiction, not yours — and if theirs is wrong, you've inherited the error. Same reasoning as any policy page.
  • Never updating it. Every new app changes who receives data. Review it whenever you install one, and formally once a year.
  • A consent banner that consents to nothing.
  • A privacy email address nobody reads.
  • Placeholders left in from the generator. Search the published page for square brackets and the phrase "your company".

If you build custom

Any custom app you commission is a data processor. It needs to appear in the policy, and it must implement the mandatory privacy webhooks — data request, customer redact, shop redact — so deletion requests actually reach it.

That's a requirement for App Store apps and a good idea for private ones, because a deletion request you can't fulfil is a problem regardless of who built the software.

The generated policy is a template with your shop's name in it. The part that makes it true is the list of everyone who receives your customers' data — and only you can write that.

Is this the problem you’re looking at?

Send me the link to your store and a line about what is going wrong. You get a straight answer within one business day — no pitch, no obligation.

mario@clicksandcarts.co

Or see what I do around Shopify: services, work beyond the theme, selected work.

Keep reading

← All articles