What Shopify merchants actually have to disclose
Shopify's Terms of Service require merchants to publish a privacy policy that explains how customer data is handled. In practice the data flows are wider than most store owners expect: the checkout collects name, address, email and phone; the payment processor (Shop Pay, Stripe or PayPal) sees card data; and installed apps often receive a copy of the order.
The practical test is simple — list every app in your admin, then make sure each category of data those apps touch appears somewhere in your policy. A review app that emails buyers, a Klaviyo flow that segments by purchase history, and a pixel that tracks add-to-cart events are three separate disclosures, not one.
- Order and account data, and how long you keep it after a purchase
- Payment processing (you never see full card numbers — say so)
- Abandoned-cart and marketing email, plus how buyers unsubscribe
- Analytics and advertising pixels, named individually
- Third-party apps that receive customer data