Shopify Store Privacy Law Requirements

A Shopify store sells across state lines by default — which makes privacy-law applicability messier for you than for a local business. Here's what actually applies and the practical first steps.

Updated October 2026 · 10-minute read

Why Shopify stores are special: a local bakery's customers live in one state. Your customers live in fifty. Every state's applicability test runs against your customer list simultaneously — which is exactly why e-commerce sellers need the patchwork view, not a single-state answer.

If you run a Shopify store, you already know your customers aren't local. Someone in Oregon buys your candle; someone in Texas buys two. That geographic spread is the whole business model — and it's also what makes state privacy laws complicated for you in a way they aren't for the bakery down the street.

The good news: the same three-question applicability test from our flagship guide works here. The bad news: you have to run it with multi-state math. Let's do that.

Step 1: Count your customers per state, not in total

State thresholds are per state. Having 80,000 total customers doesn't make you covered anywhere if they're spread thin — but 80,000 total with 30,000 in California and 25,000 in Texas-adjacent states starts to matter in specific places.

Shopify actually makes this easy: your customer and order data includes shipping addresses. Export it, pivot by state, and you have the core input for every state's consumer-count test. Most stores are surprised in both directions — some discover they're bigger in one state than they thought; most discover they're below every threshold.

The standard test, per state: 100,000 consumers (or 25,000 + over half your revenue from selling personal data). Lower in some states — Rhode Island at 35,000, Montana at 25,000/15,000, Delaware dropping to 10,000/5,000 in January 2027, Alabama at 25,000. Run the big states first: California, Texas, Florida, New York, Illinois.

Step 2: Audit what you're actually collecting and sharing

A typical Shopify store collects more data than the owner realizes:

Two things in that list deserve a hard look. First, ad pixels: sharing browsing/purchase data with Meta or Google for targeted advertising can count as "selling" or "sharing" personal information under several states' definitions — which affects both the thresholds and your opt-out duties. Second, your app stack: each app is a vendor relationship that may need a data-processing agreement.

The pixel problem is real. California lawyers spent years suing businesses over website tracking tools under the old CIPA wiretapping law, with settlement demands up to $200,000 — though that particular wave was defunded in October 2026. The lesson survives the wave: know exactly what your pixels collect and where it goes. It's the highest-risk, least-understood part of most stores' data footprint.

Step 3: The practical first steps (in order)

1 Privacy policy that reflects reality

Shopify auto-generates a privacy policy template, but it's generic — it doesn't describe your pixels, your apps, or your data flows. Rewrite it to match what you actually collect and share, with state-specific rights sections if you're covered anywhere. This is the single most common gap we see.

2 The "Do Not Sell or Share" link

If you're covered in any state, you need a clear opt-out mechanism — the "Do Not Sell or Share My Personal Information" link in your footer, plus honoring Global Privacy Control signals. Several Shopify consent apps handle this; the point isn't which tool, it's that the mechanism exists and works.

3 A rights-request process

Covered businesses must answer consumer access/deletion requests, typically within 45 days. For a small store, this can be a dedicated email inbox and a documented process — it doesn't require software. What matters is that requests don't sit unanswered.

4 Vendor hygiene

List every app and service touching customer data. Shopify itself is your processor (covered by Shopify's DPA). For the rest — Klaviyo, your analytics, your review app — confirm you have data-processing terms in place, and remove apps you don't use. Dead apps with data access are pure risk.

5 The 2027 calendar

Oklahoma and Louisiana take effect January 1, 2027; Alabama on May 1. If your per-state counts put you near any threshold, the time to get the basics right is now, not December. Our Starter Pack includes dated action checklists for all three.

What about cookie banners?

Short version: US state privacy laws don't require EU-style consent banners. The US model is opt-out, not opt-in — the "Do Not Sell or Share" link plus GPC recognition, not a popup blocking the screen until visitors click accept. If a vendor is selling you an EU-style banner as a US compliance requirement, they're selling you the wrong product. (We'll cover this properly in a follow-up article.)

Watch: setting up your Shopify store policies

Video: "How to Create Refund, Shipping & Privacy Policies on Shopify" — a step-by-step walkthrough of generating and customizing your store policies in Shopify's settings. Practical companion to step 1 above. We haven't watched it end-to-end; verify anything you act on.

The 20-minute app audit

Here's the highest-value twenty minutes a Shopify store owner can spend on privacy. Open your Shopify admin and work through this:

  1. Settings → Apps and sales channels. List every installed app. For each one, ask: does it touch customer data? (Reviews, upsells, loyalty, email, analytics, chat — yes. A currency converter — probably not.)
  2. Kill the dead ones. Uninstall every app you don't actively use. Each one is a vendor relationship, a data flow you can't fully see, and a potential breach surface — for zero benefit.
  3. Check the survivors' data access. Shopify shows what customer data each app can access. If a review app can read your full customer list including purchase history, that's worth knowing — and worth confirming you have data-processing terms covering it.
  4. Inventory your pixels. Open your theme code (or ask whoever manages it): which pixels fire on which pages? Meta, Google, TikTok, Pinterest — list them. Each one is a data-sharing relationship that may count as a "sale" under state definitions.
  5. Write it down. One page: apps, pixels, what data each touches, and whether you have terms covering them. That's your data inventory — the foundation everything else builds on. Our Starter Pack includes a fill-in worksheet for exactly this.

Most stores find at least one surprise in step 2 or 4 — usually a pixel installed by a long-gone freelancer, or an app still syncing customer data months after it was "replaced."

What about international customers?

Different regimes entirely — GDPR for EU customers, UK GDPR, PIPEDA for Canada, and others. This guide covers US state laws only. If more than a trivial share of your revenue comes from abroad, that's a separate (bigger) compliance conversation worth having with counsel.

The cookie-banner question, settled

Since it comes up constantly: no US state privacy law requires an EU-style opt-in cookie banner. What the laws require is an opt-out mechanism — the "Do Not Sell or Share My Personal Information" link plus honoring Global Privacy Control. A banner that blocks the screen demanding consent before browsing is solving the wrong continent's problem.

That said, many stores run a lightweight banner anyway — not for legal reasons, but because it makes the opt-out visible and builds trust. If you do, make sure "reject/don't sell" is as easy as "accept." A banner with no real opt-out is worse than none: it's evidence you knew about the obligation and faked it.

Frequently asked questions

Does Shopify handle compliance for me?

Partially. Shopify acts as your data processor and maintains its own compliance program — but you're the controller for your customers' data. Shopify can't write your privacy notice, honor your opt-outs, or answer your rights requests. The platform handles the pipes; the legal duties are yours.

We're tiny — 200 orders a month. Do we need to worry?

Almost certainly not yet — you're below every state's thresholds by an order of magnitude. Do the basics (privacy policy, kill dead apps, know your pixels) and re-check yearly. The stores that get in trouble are the ones that grow to 50,000 customers without ever re-running the math.

Sell in multiple states?

The $49 Starter Pack includes the 24-state threshold matrix as a sortable spreadsheet — built for exactly this math.

See the Starter Pack

Start free

The 20-question compliance checklist tells you where you stand in about ten minutes.

Get the free checklist

Important: this is not legal advice

This article is general educational information about privacy-law applicability for e-commerce businesses, not legal advice. Thresholds and requirements vary by state and change over time — verify against the statutes and consult a licensed privacy attorney in your state before making compliance decisions.