Poliogo

What Shopify means for your privacy policy

A storefront collects shipping addresses, which is the one category of personal data that is unavoidable, un-minimisable and has to be retained for tax far longer than anything else in the product. Poliogo finds Shopify in your code, writes the clauses it forces into your documents, and shows you the diff before anything is published.

Detected automaticallyMoves your Terms of ServiceCanada, United States
Shopify detected
What changed in your product
Your Privacy Policy does not mention Shopify.
↓
What we updated for you
Terms of Service, Privacy Policy, Cookie Policy, Cookie banner updated, with Shopify named and its purpose stated.
Proved from your own code, with the file and line beside it.
21
stacks with a page of their own
50+
services the scan classifies
<5 min
signup to finished documents

Compliance on a Shopify project, end to end

The clauses are the visible part. What makes them worth having is that they keep matching the code after you stop paying attention.

It finds it without being told

Automatic

Shopify resolves from its package, its endpoint or its credential name — so an integration with no SDK installed is found like any other.

Clauses, not a template

The disclosures Shopify forces are assembled from a library built from published regulatory text, and filled in from the catalog row rather than from a guess about what the vendor does.

Every clause explained

Beside each one, in plain English: what it means, why your product needs it, and which detected component put it there — with the file and line it was proved from.

It notices when this changes

Drift

Later scans are diffed against the snapshot your documents were generated from, so removing Shopify or adding something beside it becomes an update you approve.

Delivered where you work

As a pull request on a connected Git host, as an approval in the dashboard, or from your editor over MCP — the same six tools your agent can call without opening a browser.

Read in memory, not retained

The files a scan reads are processed in memory and dropped when the request ends; what is kept is the list of services it found. The MCP server goes further and scans on your own machine.

How Poliogo proves Shopify is there

Detection is pattern matching over what is literally in your repository — dependency manifests, source files, configuration, edge functions and `.env.example` — not a model's opinion about your code. Shopify resolves from any of the signatures below, so an integration written as a bare `fetch` with no package installed is found exactly like one with an SDK.

  • ✓The cart cookie lasts two weeks and is strictly necessary; _shopify_y and _shopify_s are Analytics and wait behind the gate. Same vendor, two classifications, which is why classification is per cookie rather than per service.
  • ✓Shopify Inc. processes in Canada and the United States, so the transfer clause names an adequacy-decision country and a non-adequacy one in the same row.
  • ✓Order details and payment status reach your Terms of Service, not only your Privacy Policy — refunds and shipping are contract terms, and a storefront with no refund clause has a gap no privacy drafting closes.

What Shopify changes in your documents

Shopify runs your store — this adds order, shipping and refund terms. It processes financial data on your behalf, so billing, refund and financial-data handling terms must be disclosed. That is why Shopify moves your Terms of Service, Privacy Policy, Cookie Policy and Cookie banner — and it is the same sentence the Updates page shows when a scan finds it for the first time, because both are read from one place.

Shopify — generated clauses
Data
Shopify receives: order details, shipping and billing address, payment status, browsing history in store
Why
Purpose: running the storefront and processing orders
Transfer
Processed in: Canada, United States
Entity
Sub-processor of record: Shopify Inc.
  • ✓Terms of Service — regenerated and shown as a diff before anything is published.
  • ✓Privacy Policy — regenerated and shown as a diff before anything is published.
  • ✓Cookie Policy — regenerated and shown as a diff before anything is published.
  • ✓Cookie banner — regenerated and shown as a diff before anything is published.

The cookies Shopify sets

Every row here is the one the generated Cookie Policy prints and the one the banner classifies from — same source, so the table on your site and the behaviour of the gate cannot disagree. "Strictly Necessary" means it is disclosed and never held: gating it would break the thing it is there to do.

CookieWhat it doesLifespanClassification
_shopify_y, _shopify_sStore session and visitor analyticsSession – 1 yearAnalytics
cartKeeps the shopping cart between visits2 weeksStrictly Necessary

Read from the same catalog row the Cookie Policy is generated from.

Shopify in your sub-processor schedule

A sub-processor schedule names the legal entity, not the brand — Shopify Inc. rather than "Shopify" — because that is the name a customer's data protection agreement is checked against. The row below is what Poliogo generates and what your Trust Center publishes.

FieldValue
Legal entityShopify Inc.
What it receivesOrder details, shipping and billing address, payment status, browsing history in store
PurposeRunning the storefront and processing orders
Processing locationCanada, United States
Their privacy policywww.shopify.com/legal/privacy

Generated from the catalog entry, and published on your Trust Center alongside every other sub-processor a scan found.

Getting this onto a Shopify project

Nothing is written or published until you have seen it. The scan proposes, you approve, and only then does anything reach your repository or your live pages.

1
Connect

Connect the repository, the host or the live address. The scan reads manifests, source, configuration and `.env.example` in memory and keeps the list of services it found, not the files it read.

2
Check what it found

A plain-English list of every service the scan proved, Shopify among them, each with the file and the line it was found on. Correct anything wrong before a word is generated.

3
Generate and review

Privacy Policy, Cookie Policy and Terms, with the clauses Shopify forces already in them, and a plain-language explanation beside each one saying which detected component put it there.

4
Keep them current

Later scans are diffed against the snapshot your documents were generated from, so a service added next month becomes an update you approve rather than a quiet inaccuracy nobody notices.

Questions people ask

Does Poliogo detect Shopify on its own?

Yes. Shopify resolves from the signatures in the detection library — the package name, the endpoint it is called at, and the credential name it uses in `.env.example`. Matching on the endpoint is the part that matters: an integration written as a bare `fetch` with nothing added to package.json is still found, and that is the case a dependency-only scanner misses entirely.

What does Shopify actually receive from my users?

Order details, shipping and billing address, payment status, browsing history in store — for running the storefront and processing orders. That list is not written for this page: it is the catalog row the generated Privacy Policy prints, so what you read here is what your document will say, down to the categories.

Do I have to list Shopify as a sub-processor?

If it processes personal data on your behalf, yes — and the row names Shopify Inc., the legal entity, rather than the brand, because that is the name a customer's data protection agreement is checked against. Poliogo generates the row and publishes it on your Trust Center alongside every other sub-processor a scan found.

Where does Shopify process the data?

Canada, United States. That matters for the transfer clause rather than for the vendor list: an EU product sending personal data to a US processor owes a transfer disclosure whether or not anything else in the stack is American. The generated clause names the location from this same row rather than assuming one.

Which cookies does Shopify set, and are they blocked before consent?

_shopify_y, _shopify_s, cart. Whether each one waits depends on its classification, not on its vendor: the ones marked strictly necessary are disclosed in the Cookie Policy and always allowed to run, because gating them breaks the thing they exist for, and anything classified Analytics or Marketing is held until a visitor agrees.

What happens when I add another service later?

A scan has to run first — manually on any plan including Free, or on your plan's schedule from Starter. When one finds a service your documents do not mention, the change arrives as a proposal with a plain-language diff: what changed, why, and which detected component triggered it. On a connected Git host it can also arrive as a pull request on a side branch, so changes reach your default branch only through a pull request you approve.

Is any of this legal advice?

No. Poliogo reads code and assembles clauses from a library built from published regulatory text; it does not weigh your circumstances, and no generated document settles whether a business is compliant — that turns on how the business actually handles data. What the product is for is making sure the documents describe what the software genuinely does, which is the part that goes stale on its own and the part a person cannot check by hand every week.

See what a scan finds in your Shopify project

Connect it and read the list before anything is generated. Free plan, no credit card, nothing published until you approve it. Poliogo automates the reading and the drafting, not the judgement — it is not a law firm and this page is not legal advice.

Start free — no credit card

Poliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.