ConsentPixel – Privacy · Verified

Shopify · How-To

How to add a privacy policy to Shopify (step by step)

Adding the policy to Shopify takes about two minutes — the setting lives under Settings → Policies, and Shopify links it in your footer automatically when you save. The part that actually matters takes a little longer: making sure the policy describes your real store, not a generic template. Here's the full process, both halves.

Quick answer

From your Shopify admin, go to Settings → Policies, add your privacy policy in the Written policies section, and click Save — Shopify automatically links it in your footer and at checkout. You can write it yourself, use Shopify's automated template (Settings → Customer privacy), or paste one from a generator. Whichever you choose, edit it to match your store's real apps and trackers before publishing.

First: do you actually need one?

Yes — on Shopify, this one isn't ambiguous. Shopify strongly recommends a privacy policy in its merchant terms, and separately, most privacy laws require one the moment your store collects personal data. A Shopify store always collects personal data: names and addresses at checkout, emails for marketing, and analytics or ad pixels from day one. So between Shopify's own expectations and laws like the GDPR and CCPA/CPRA, every real Shopify store needs a privacy policy. The only real question is how to do it well.

One thing worth clearing up first, because it confuses a lot of merchants: Shopify's own privacy policy doesn't cover your store. Shopify's policy describes how Shopify Inc. handles data as your platform provider. Under the GDPR and CCPA, each merchant is a separate data controller — so your store needs its own policy regardless of Shopify's.

How to add the privacy policy: step by step

Here's the exact process in current Shopify. The mechanical part is genuinely quick.

Open your policy settings

From your Shopify admin, go to Settings → Policies. The privacy policy sits in the Written policies section, alongside your refund, shipping, and terms-of-service policies.

Create your policy (three ways)

You have three options here, and they're not equal — more on that below. You can write your own and paste it in, use Shopify's automated template (found under Settings → Customer privacy → Privacy policy → Use automated policy, which auto-updates as certain settings change), or paste in a policy from a third-party generator. Shopify lets you use HTML in the content, so a formatted policy pastes in cleanly.

Review and edit for your store

This is the step people skip, and it's the important one. Whatever you started from, edit it so it reflects the apps, trackers, and data flows your store actually uses. A template describes a generic store; yours has specific analytics, marketing, reviews, and upsell apps, each with its own data handling. Template language alone is rarely accurate for your business.

Save — Shopify publishes and links it

Click Save. Shopify automatically links the policy in your store footer and on relevant checkout pages — so for most themes, you don't need to add a link manually. Shopify also archives past versions of your policy (kept for two years) and logs changes in your Store activity log.

Add an explicit footer link (if you want one)

If your theme doesn't surface the auto-link where you want it, add it manually: go to Content → Menus, click your Footer menu, choose Add menu item, name it "Privacy Policy," and link it to the policy page. This guarantees a visible, findable link — which matters, because a policy nobody can find isn't doing its job.

◆ Two-minute version

Settings → Policies → add your privacy policy → Save. That's the whole mechanical process, and Shopify handles the footer link. Everything else in this guide is about making the policy good — which is where the real work is.

The three ways to create the policy — compared honestly

Step 2 gave you three options. They lead to very different outcomes, so here's the honest trade-off:

Write it yourself

Most accurate if you truly know every app and data flow — but genuinely hard to get right, and easy to leave gaps in rights language or third-party disclosures.

High effort
Shopify's template

Fast and free, auto-updates with some settings. But it's generic: it doesn't list your specific third-party apps and trackers, which is the part most likely to be inaccurate.

Generic
Scan-based generator

Builds the policy from your store's actual detected trackers, so the disclosure matches your real apps from the start — then you still review it.

Accurate start

The common thread across every honest guide on this topic is the same: a generator gives you a structure, not a finished document. Treat any generated policy — Shopify's or a third party's — as a first draft you customize, never a policy you publish blind. Which raises the question of what actually makes a Shopify policy accurate.

The honest truth about the template

Shopify says it plainly: "Although Shopify can generate templates, you're responsible for following your published policies." The template is a convenience, not a shield. If it says your store does one thing and your apps do another, the responsibility — and the mismatch — is yours. A privacy policy is a disclosure of what your store actually does, and only you can make sure it's true.

A note on Shopify's "automated policy"

Shopify's automated template has one genuinely nice property worth understanding: it auto-updates as certain settings change. That sounds like it solves the staleness problem — but read it carefully. It updates when your Shopify settings change (like your data-sharing configuration), not when you install a third-party app that starts loading a new tracker. And app trackers are exactly the part most likely to drift. So the automated template keeps the Shopify-native parts of your policy current while leaving the highest-risk gap — your apps' tracking — exactly as unaddressed as a static template would. It's a real convenience for what it covers; just don't mistake "auto-updating" for "always accurate about everything your store does."

What makes a Shopify privacy policy actually accurate

The single biggest accuracy gap on Shopify is the third-party app trackers. A Shopify store is an app magnet — reviews, email, analytics, upsells, chat — and many of those apps quietly add their own tracking pixel. Your privacy policy is supposed to disclose them. But no template can list apps it doesn't know you installed, and most merchants can't name every tracker their apps load. That's the gap where a generic policy becomes an inaccurate one.

To close it, you have to answer a question first: what is my store actually running? Before you finalize any policy, it's worth documenting your real data collection — in Shopify, you can review your installed apps under Settings → Apps and sales channels and note what each collects. But apps don't always advertise their trackers clearly, which is why the more reliable approach is to scan your live store and see the trackers that actually fire. Then your policy can list them — and match reality.

What a Shopify privacy policy should include

Beyond listing your trackers accurately, a Shopify privacy policy needs to cover the sections privacy laws expect. If you're editing a template or reviewing a generated draft, make sure each of these is present and actually matches your store:

  • What you collect — the categories of personal data: contact and shipping details, payment information (handled by your payment processor), account data, and usage/analytics data.
  • Why you collect it — fulfilling orders, customer support, marketing, fraud prevention, and analytics.
  • Who you share it with — Shopify as your platform, payment processors, shipping carriers, and every third-party app that touches customer data. This is the section templates most often leave thin.
  • Cookies and tracking — the analytics and advertising technologies your store runs, ideally linked to a fuller cookie policy.
  • Customer rights and how to exercise them — access, deletion, and opt-out of sale/sharing, with a working request path (a real DSAR route, not a dead "email us").
  • International transfers — if you use US-based tools and serve EU customers, data crosses borders, which your policy should acknowledge.
  • Contact details and a last-updated date — both are expected, and the date signals the policy is maintained.

The recurring theme is the "who you share it with" section, because on Shopify that list is defined by your apps — and it's the part a generic template can't fill in for you. Getting it right is exactly why knowing your real trackers matters.

See your store's real trackers

Find out what your Shopify apps actually load

Run a free scan of your store to see the trackers your apps and pixels fire — the exact things your privacy policy needs to disclose. No account needed.

Scan my store free →

Free · about 10 seconds · no signup. Information, not legal advice.

Don't forget the cookie side

A privacy policy is one piece. If your Shopify store runs analytics or ad pixels — and it does — you also have cookie obligations that the privacy policy alone doesn't satisfy. Depending on your audience, that means a cookie policy and a cookie consent banner, plus an accurate list of the cookies your store sets. Shopify provides a built-in cookie banner (under Settings → Customer privacy), which handles the consent prompt — but the banner is only as good as whether your trackers actually wait for consent, and whether your disclosed cookie list matches what's really running. It's worth treating the privacy policy and the cookie setup as one job, not two unrelated ones.

Keeping it accurate as your store grows

Here's the part that turns a good policy into a stale one: a Shopify store is never finished. You add apps, run campaigns, swap tools — and every one of those can change what data your store collects and what trackers it loads. The policy that was accurate at launch drifts out of date with each addition, quietly, because nothing forces you to revisit it.

  • Re-check when you add or remove an app — that's the most common moment a new tracker appears and your policy falls behind.
  • Review at least annually — the CCPA expects a review at least every 12 months, and GDPR expects the policy to be accurate at all times.
  • Keep the cookie list in sync — the cookie declaration goes stale fastest, since it names specific trackers that change constantly.

The sane way to handle this on a busy store is to tie your documents to what your store actually does, rather than maintaining them by memory — so that when your trackers change, your disclosure can change with them instead of silently falling behind.

Common Shopify privacy policy mistakes

A few errors show up over and over on Shopify stores specifically — worth checking your policy against:

  • Assuming Shopify's policy covers you. It doesn't — Shopify's policy is about Shopify Inc., not your store. You're a separate controller and need your own.
  • Publishing the template unedited. The generic template names none of your apps' tracking, which is precisely the disclosure that makes it accurate. An unedited template is a generic document, not your policy.
  • Forgetting the apps you installed months ago. That reviews widget or abandoned-cart app you set up and forgot is still collecting data — and still needs disclosing.
  • Treating the policy as one-and-done. Every app you add after publishing can change what you collect, quietly making the policy inaccurate.
  • Skipping the cookie side entirely. A privacy policy doesn't satisfy your cookie-consent obligations; a store with ad pixels needs both.

The bottom line

Adding a privacy policy to Shopify is easy: Settings → Policies → add your policy → Save, and Shopify links it in your footer and checkout automatically. If you want a guaranteed footer link, add one under Content → Menus. That's the two-minute part.

The part that actually protects your store is making the policy true — reflecting the specific apps and trackers your store runs, not a generic template. Shopify itself says you're responsible for following your published policies, so a policy that misstates what your store does is your problem, not Shopify's. Start from your store's real data, review the draft properly, keep it in sync as you add apps, and pair it with the cookie side. Do that, and the footer link means something. Skip it, and it's just a generic document with your store's name on top.

Frequently asked questions

Where do I add a privacy policy in Shopify?

From your Shopify admin, go to Settings → Policies and add your privacy policy in the Written policies section. When you save, Shopify automatically links it in your store footer and on relevant checkout pages. You can also manage privacy-policy content under Settings → Customer privacy.

Does Shopify provide a privacy policy?

Shopify offers a template you can apply — under Settings → Customer privacy, you can click "Use automated policy" to use Shopify's template text, which updates as certain settings change. But Shopify is clear that although it can generate templates, you're responsible for following your published policies, and the template doesn't list the specific third-party apps and trackers your store runs.

Is Shopify's template privacy policy enough?

It's a starting structure, not a finished document. The template describes a generic store and typically doesn't list the third-party apps and trackers your specific store loads — the part that makes the disclosure accurate. Review and edit it so it reflects your real store, or generate one from an actual scan of your site.

How do I add the privacy policy to my Shopify footer?

When you save a policy under Settings → Policies, Shopify automatically links it in your footer and checkout. If you want an explicit footer menu link, go to Content → Menus, select your footer menu, click Add menu item, and link it to the policy page.

Do I need a separate cookie policy on Shopify too?

If your store runs analytics or ad pixels — which nearly all do — then yes, you have cookie obligations beyond the privacy policy. Depending on your audience that means a cookie policy and a cookie consent banner (Shopify provides a built-in banner under Settings → Customer privacy), plus a cookie list that matches what your store actually sets. Treat the privacy policy and cookie setup as one job.

Disclaimer: This article is general information, not legal advice, and does not create an attorney–client relationship. Shopify's interface and features may change; verify current steps in Shopify's Help Center. ConsentPixel — Privacy · Verified is not a law firm and is independent of and not affiliated with Shopify ("Shopify" is a trademark of its respective owner). Generating or publishing a privacy policy does not by itself make your store compliant with any law. Consult qualified counsel for your specific situation.

Scroll to Top