Privacy Policy

1. Introduction

Welcome to Shopify!

This Privacy Policy was written to help you better understand how we collect, use and store your information. Since technology and privacy laws are always changing, we may occasionally update this policy. If a significant change is made, we will be sure to post a notice on our home page and in the merchant admin. If you continue to use Shopify after these changes are posted, you agree to the revised policy.

By signing up for any of the products or services offered by Shopify (together, the “Services”), or dealing with a merchant using Shopify Services, you are agreeing to the terms of this Privacy Policy and, as applicable, the Shopify Terms of Service. This policy is a legally binding agreement between you (and your client, employer or another entity if you are acting on their behalf) as the user of the Services (referred to as “you” or “your”) and Shopify Inc. (referred to as “we”, “our”, “us” or “Shopify”). If we add any new features or tools to our Services, they will also be subject to this policy.

We will keep your Personal Information accurate, complete and up-to-date with the information that you provide to us. If you request access to your Personal Information, we will inform you of the existence, use and disclosure of your Personal Information as allowed by law, and provide you access to that information.

When we use the term “Personal Information” in this policy, it means any information related to an identifiable individual, but does not include the name, title, business address, or telephone number of an employee of an organization.

2. Information from merchants

Privacy matters! If you are a merchant, you agree to post a privacy policy on your storefront that complies with the laws applicable to your business. You also agree to obtain consent from your customers for the use and access of their Personal Information by Shopify and other third parties. To help you get started on creating your own privacy policy, check out our policy generator.

What information do we collect from merchants and why?

  • We collect your name, company name, address, email address, phone number(s) and credit card details.
    • We need this information to provide you with our Services, for example, to confirm your identity, contact you, and invoice you.
  • We collect data about the Shopify-hosted webpages that you visit and how and when you access your account, including information about the device and browser you use, your network connection and your IP address.
    • We need this information to give you access to and improve our Services.
  • Upon completing the sign-up process for the Services and depending on your location, we may create a Shopify Payments account on your behalf. If you activate a Shopify Payments account (applicable only to Canada, US & UK merchants), we collect your business address, business type, business ID number, date of birth (if you are an individual business owner), bank account information and government identification information, such as your Social Security Number or your Social Insurance Number.
    • We need this information to create a Shopify Payments account for you, to provide you with Shopify Payments services, including fraud and risk monitoring, and to comply with applicable legal and regulatory requirements.
  • We collect Personal Information about your customers that you share with us or that customers provide while shopping or during checkout.
    • We use this information to provide you with our Services and so that you can process orders and better serve your customers.
  • We will also use Personal Information in other cases where you have given us your express permission.

When do we collect this information?

  • We collect Personal Information when you sign up for our Services, when you access our Services or otherwise provide us with the information.

3. Information from our merchants’ customers

What information do we collect and why?

  • We collect our merchants’ customers’ name, email, shipping and billing address, payment details, company name, phone number, IP address and device data.
    • We need this information to provide merchants with our Services, including supporting and processing orders, authentication, and processing payments. This information is also used to improve our Services.

When do we collect this information?

  • Information is collected when a merchant’s customer uses or accesses our Services, such as when a customer visits a merchant’s site, places an order or signs up for an account on a merchant’s site.

4. Information from Partners

Partners are individuals or businesses that have agreed to the terms of the Partner Program to work with Shopify to promote the Services by (a) referring clients to Shopify; (b) developing Shopify store themes for merchant use; or (c) developing apps using the Shopify Application Interface (API) for merchant use.

What information do we collect from Partners and why?

  • We collect your name, company name, website, twitter or other social media handles, phone number(s), address, business type, email address, PayPal Account, and GST/HST number.
    • We use this information to work with you, confirm your identity, contact you, and pay you.
  • We collect data about the Shopify-hosted webpages that you visit and how and when you access your account, including information about the device and browser you use, your network connection and your IP address.
    • We use this information to give you access to and improve our Services.
  • We collect Personal Information about your customers that you share with us or that they provide to us directly.
    • We use this information to work with you and to provide our Services to your customers.
  • We will also use Personal Information in other cases where you have given us express permission.

When do we collect this information?

  • We collect this information when you sign up for a Partner Account, when you sign up one of your customers for our Services, or when your customers sign up themselves. We also collect any additional information that you might provide to us.

5. Information from Shopify website visitors and support users

What information do we collect and why?

  • From Shopify website visitors, we collect information about the device and browser you use, your network connection and your IP address.
  • From telephone support users, we collect your phone number and call audio.
  • From chat support users, we collect your name, email address, information about the device and browser you use, your network connection and your IP address.
  • From forum users, we collect your name, email address and website URL.

We use this information to service your account, enhance our Services, and answer any questions you may have.

When do we collect this information?

  • We collect this information when you visit Shopify-hosted webpages or engage with us either by email, web form, instant message, phone, or post content on our website (including forums & blogs). We also collect any additional information that you might provide to us.

6. Information from cookies

What is a cookie? A cookie is a small amount of data, which may include a unique identifier. Cookies are sent to your browser from a website and stored on your device. Every device that accesses our website is assigned a different cookie by us.

Why does Shopify use cookies?

  • We use cookies to recognize your device and provide you with a personalized experience
  • We also use cookies to serve customized ads from Google and other third-party vendors.
  • Our third-party advertisers use cookies to track your prior visits to our website and elsewhere on the Internet in order to serve you customized ads.
  • Opting out: You may be able to opt out of customized ads by visiting the Ads Preferences Manager, and the Google Analytics Opt-out Browser Add-on. If you use our website without opting out, this means that you understand and agree to data collection for the purpose of providing you with remarketing ads.

7. When and why do we share Personal Information with third parties?

  • Shopify works with third parties to help provide you with our Services and we may share Personal Information with them to support these efforts. In certain limited circumstances, we may also be required by law to share information with third parties.
    • Personal information may be shared with third parties to prevent, investigate, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service or any other agreement related to the Services, or as otherwise required by law.
    • Personal information may also be shared with a company that acquires our business, whether through merger, acquisition, bankruptcy, dissolution, reorganization, or other similar transaction or proceeding. If this happens, we will post a notice on our home page.
  • Except when required by law, Shopify will never disclose your Personal Information without obtaining your consent.

8. What do we do with your Personal Information when you terminate your relationship with us?

  • We will continue to store archived copies of your Personal Information for legitimate business purposes and to comply with the law.
  • We will continue to store anonymous or anonymized information, such as website visits, without identifiers, in order to improve our Services.

9. What we don’t do with your Personal Information

  • We do not and will never share, disclose, sell, rent, or otherwise provide Personal Information to other companies for the marketing of their own products or services.
  • We do not use the Personal Information we collect from you or your customers to contact or market to your customers or directly compete with you. However, Shopify may contact or market to your customers if we obtain their information from another source, such as from the customers themselves.

10. How do we keep your Personal Information secure?

  • We follow industry standards on information security management to safeguard sensitive information, such as financial information, intellectual property, employee details and any other Personal Information entrusted to us. Our information security systems apply to people, processes and information technology systems on a risk management basis.
  • We perform annual audits to ensure our handling of your credit card information aligns with industry guidelines. We are certified as a PCI DSS Level 1 compliant service provider, which is the highest level of compliance available, and our platform is audited annually by a third-party qualified security assessor.
  • No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee the absolute security of your Personal Information.

11. How do we protect your information across borders?

  • Shopify remains responsible for Personal Information that is transferred to a third party abroad for processing or to support our efforts. Any Personal Information transferred to a third party for data processing is subject, by law, to a comparable level of protection as that provided by Shopify. A “comparable level of protection” means a level of protection generally equivalent to that provided by Shopify.

  • In relation to European markets, we also comply with the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework as set forth by the U.S. Department of Commerce regarding the collection, use, disclosure and retention of Personal Information by Shopify Data Processing (USA) Inc. from European Union member countries and Switzerland. We have certified that we adhere to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. For more information regarding our Safe Harbour Privacy Policy for Shopify Data Processing (USA) Inc.,

12. Access to your personal information

You retain all rights to your Personal Information and can access it anytime. In addition, Shopify takes reasonable steps to allow you to correct, amend or delete personal information that is shown to be inaccurate or incomplete.

If you have any questions about your Personal Information or this policy, please contact:

Chief Privacy Officer
privacy@shopify.com
(613) 241-2828

Last updated: June 10th, 2015
© 2015 Shopify Inc.