StackLégal

Banking and commerce

GDPR Shopify

In an indie stack, Shopify is used for Online store. Entity cited: Shopify International Ltd. (Ireland) receives data of people located in the EEA, the United Kingdom or Switzerland; Shopify Inc. (Canada) depending on location. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Shopify

Yes. Public DPA: the merchant is controller and Shopify is processor.

Read the DPA

Stated role

For personal data of the merchant's customers, the merchant is controller and Shopify is processor, except the Enhanced Services where Shopify acts as controller. Shopify is also controller for persons with whom it has a direct relationship.

Personal data

Customer's name, email, and contact details, billing and shipping, purchases and transactions, status updates, store activity (products viewed, cart contents), privacy-preference signals, IP address, browser, network activity, and other interactions provided by the merchant or the customer.

Sub-processors of Shopify

Help page listing the sub-processors.

List published by the vendor

Transfers outside the EU

Hosting / location

EEA, United Kingdom, and Swiss personal data is received by Shopify International Ltd. in Ireland, then sent to other Shopify sites and to providers, including Canada and the United States. Processing is possible in any country where Shopify or its providers are established, including Singapore and Canada.

EU–United States Data Privacy Framework

Shopify is on the list. Exact EU-U.S. Data Privacy Framework status: Inactive - Withdrawal. This is not an active certification.

Data Privacy Framework sheet

Cookies

The Cookie Policy (stated update: 1 October 2026) publishes the cookies set on a merchant's store. Necessary: __Host-Http-shop_binding, _shopify_essential, _shopify_test, _tracking_consent, cart, cart_currency, discount_code, localization, login_with_shop_finalize, shopify_pay, storefront_digest. Measurement: _shopify_analytics, _shopify_s, _shopify_y, shop_analytics. Marketing: _shopify_marketing. Preference: shopify_override_user_locale. Shopify states that it does not itself set advertising cookies on those stores. The same page lists separate cookies for Shop (shop.app) and for shopify.com / the admin. Names of cookies set by the third parties cited: not disclosed.

Typical use, written by StackLégal and not by the vendor: Online store.

History

Last update: October 4, 2026.

  1. Cookies: names from the Cookie Policy of 1 October 2026, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Shopify a processor within the meaning of the GDPR?

For personal data of the merchant's customers, the merchant is controller and Shopify is processor, except the Enhanced Services where Shopify acts as controller. Shopify is also controller for persons with whom it has a direct relationship.

What DPA does Shopify publish?

Yes. Public DPA: the merchant is controller and Shopify is processor. https://www.shopify.com/legal/dpa

Which further sub-processors does Shopify publish?

Help page listing the sub-processors. https://help.shopify.com/en/manual/privacy-and-security/privacy/subprocessors

Where does Shopify state that it processes data, including outside the EU?

EEA, United Kingdom, and Swiss personal data is received by Shopify International Ltd. in Ireland, then sent to other Shopify sites and to providers, including Canada and the United States. Processing is possible in any country where Shopify or its providers are established, including Singapore and Canada.

Is Shopify registered under the EU–United States Data Privacy Framework?

Shopify is on the list. Exact EU-U.S. Data Privacy Framework status: Inactive - Withdrawal. This is not an active certification. https://www.dataprivacyframework.gov/participant/603

Which personal data does Shopify mention?

Customer's name, email, and contact details, billing and shipping, purchases and transactions, status updates, store activity (products viewed, cart contents), privacy-preference signals, IP address, browser, network activity, and other interactions provided by the merchant or the customer.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets banking and commerce

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.