Skip to content

SHOPIFY · POLICIES & PRIVACY

Your store’s privacy, taken care of.

I prepare the policies, build the privacy choices and set up the cookie banner. You get clear pages for your customers and settings that match what those pages say.

ONE CONNECTED SETUP

Clear policies. Real choices.

Privacy Policy
Cookie Policy
Your Privacy ChoicesDo Not Sell or Share

The documents and the storefront, working together.

From policy pages to the buttons that make them work.

I handle the writing, Shopify setup and checks as one project, tailored to your store and the markets you serve.

01

Privacy Policy

A clear explanation of what customer information your store collects, how it is used and which services receive it.

02

Cookie Policy

An explanation of the cookies and tracking tools actually used by your store, with choices visitors can understand.

03

Your Privacy Choices

A place for customers to manage their preferences, including Do Not Sell or Share where relevant to your store.

04

Cookie banner & settings

A banner connected to your store’s privacy settings. I check how analytics and connected apps respond to the visitor’s choice.

BUILT ON REAL STORE PROJECTS

A legal foundation. Adapted to your business.

Working with lawyers on other stores, I developed my own set of templates and a repeatable process based on the documents they supplied. I use that foundation to prepare your policies, with your business details and the services your site actually uses.

I handle preparation and implementation. Questions that need a legal decision go to your lawyer.

You send the store. I connect the pieces.

  1. 01

    Understand your store

    I review the site and ask you for the business details that only you can provide.

  2. 02

    Prepare & implement

    I adapt the documents, publish the pages and connect the banner and privacy controls.

  3. 03

    Check & hand over

    I test the visitor choices and show you where to update the texts in Shopify.

A REAL PROJECT

The policy needs to match the store.

For a US wellness brand, I worked from the lawyers’ questionnaires, checked what the site collected and built the privacy controls. Some connected tools kept sending data after a visitor opted out. I addressed that behavior before the policies went live.

The result: published policy pages backed by a tested opt-out mechanism.

Inside the project

Optional reading: the original audit, implementation details and measurements.

Read the technical case

Shopify · The same store as the flagship case

Privacy, Cookie and Terms, built from what the site actually does

A US wellness brand was adding a corporate page to its Shopify store, and its lawyers sent three questionnaires: 78 questions in all. More than half were technical, not legal. I measured what the page did with visitor data, built the opt-out mechanism in the theme and assembled the three documents from facts instead of a template. About two working days from audit to published pages, and a module I now run on any store.

One corporate page, measured in a clean browser from a US and a European address
27
cookies, HttpOnly included
14
Shopify Web Pixels
26
third-party hosts
9
trackers

Tracker requests per page

Before the opt-out60–120
After the opt-out2–4

Four integrations ignored Shopify's consent API. The guard snippet in the theme stops them.

Role
The technical side of all three documents: the audit, 78 questionnaire answers, the opt-out mechanism in the theme and the checks before publication. The legal wording stayed with the lawyers.
Period
2026
Client
A US wellness brand under NDA: the corporate page of the store from the flagship case, on the same domain and the same theme.
Documents
Privacy Policy, Cookie Policy, Terms of Use. Written for the US only, from the European GDPR templates the lawyers had on hand.
Regimes
The US opt-out model: Do Not Sell or Share, Global Privacy Control, Shopify's regional privacy settings. Europe and the UK measured in advance for the client's decision.
Status
Published. Two weeks later the same measurements found why half of the purchases had vanished from the store's analytics.
What stays private
The brand and the documents themselves. The method, the numbers from the audit and the mechanism are shown.

Where the lawyers stopped

Three questionnaires: 18 questions for the Terms of Use, 29 for the Privacy Policy, 31 for the Cookie Policy.

The templates were European, written for GDPR, while the documents were only for the US. The first pass took me about ten hours, and by the end one thing was clear: more than half of the questions were not legal at all. A lawyer cannot answer which cookies the site sets, who keeps collecting data after an opt-out, or where the contact form goes. Those are measured.

So I split the work three ways: what the audit answers, what only the client can answer, and what is legal framework that stays the same from project to project. Of 78 questions, about two thirds came out of the audit and 16 went to the client as a short list.

Where the answers come from

Technical audit
About two thirds of the questions
The client
16 questions: legal entity, addresses, retention decisions, mailing lists
Legal framework
The rest: rights, legal bases, disclaimers, liability

The audit: every pixel, not only the visible ones

I measure in layers, in a clean browser, from a US and a European address, in three states: no action, after the opt-out, after the undo.

Cookies, taken twice

The browser does not show all of them. On this project three Shopify cookies were HttpOnly, and the first pass missed them: mine and another contractor's. They only appear in the server's response headers, so I collect them separately through a cookie jar and the Set-Cookie headers, with their lifetimes.

Storage

localStorage, sessionStorage and IndexedDB: the identifiers that survive when cookies are cleared, and the ones a cookie table never lists.

Third-party hosts

Every host the page actually calls, counted per request, with Shopify's own infrastructure kept apart from the vendors.

Web Pixels, app embeds, theme snippets

Shopify Web Pixels first. Then the apps embedded outside Shopify's consent layer: they show in the theme settings file, disabled ones included. Then the snippets rendered from the layout directly, A/B testing among them.

Checkout

Checkout runs its own pixels, which the storefront never shows, including the store's custom code. A separate layer, measured separately.

The opt-out test

I set the opt-out through the Customer Privacy API, reload the page and repeat every measurement. This shows who actually listens to Shopify and who keeps sending data. On this store four kept going after the opt-out: Amplitude, the Meta pixel app, and partly Klaviyo and Clarity. That is the answer to why one setting in the admin is not enough.

What one page turned out to carry

27 cookies, 14 Shopify Web Pixels, 26 third-party hosts and nine trackers: two GA4 properties, Google Ads, Microsoft Clarity, Amplitude with session replay, Klaviyo, an A/B testing app, Meta and TikTok through a server-side pixel app, and an ad optimization app.

Retention periods come from the vendors' current documentation, with the date of the check written down: Clarity keeps recordings for 30 days and heatmaps for 9 months; Google's IDE cookie lives 13 months in Europe and 24 elsewhere; GA4 keeps data for 2 or 14 months depending on the setting; Amplitude Session Replay 30 days by default.

The details that usually land in a policy by guesswork

  • Which captcha the form uses. Shopify currently serves hCaptcha, not reCAPTCHA, and it sets no cookies on the store's domain.
  • Where form submissions go, and what the domain's SPF and DMARC records say.
  • Whether the addresses printed on the site exist at all. On this project the contact address from the mockup pointed to a domain nobody had registered.

Which laws and mechanisms I account for

United States: the opt-out model

A Do Not Sell or Share link, the Global Privacy Control signal the browser sends on its own, and Shopify's built-in opt-out page. Separately, the store's privacy settings: Shopify keeps a list of regions where consent is required, and 20 US states with their own privacy laws are on it now. If that list is on and there is no banner, the store quietly loses part of its analytics. More on that below.

Europe and the UK: consent first

A different regime: consent before tracking, a banner, legal bases, international transfers. I measure the state in advance so the client chooses knowingly instead of finding out afterwards.

Health niches: a separate flag

In some states health data needs consent rather than an opt-out, and the order of work changes. That is where I go to the lawyer instead of deciding myself.

And the technical side of consent: what Shopify gates on its own (its pixels and channels), what it does not (app embeds and theme scripts), the state of Google Consent Mode, and which vendors ignore both layers.

The opt-out mechanism comes before the texts

Code first, then documents.

A guard snippet becomes the first script in the head. It mirrors the opt-out into a cookie of its own, because Shopify's consent cookie is HttpOnly and invisible to JavaScript. It reads the Global Privacy Control signal, deletes vendor cookies, refuses to load vendor scripts or send their requests, calls the vendors' own kill switches, and passes the opt-out into Shopify's API so the pixels and channels follow.

In the footer there is one link. A click opts out at once, a confirmation appears next to it, and the confirmation carries an Undo link. The order matters because those confirmation texts go into the policy word for word.

Checked on the live site two weeks later

Tracker requests per page after the opt-out
60–120 → 2–4
Web Pixels after a reload
Do not start
Vendor cookies
Deleted
Undo
Everything comes back

Tracker requests per page

Before the opt-out60–120
After the opt-out2–4

The texts are assembled from facts

When the lawyers' final documents arrived, I checked every paragraph against my answers. Three kinds of text came out: a fact from the audit, a decision by the client, and legal framework. The shares differ by document.

Share of the text that comes straight from the audit

Cookie Policy

80%

Almost entirely generated from the audit: the tables, the vendors, the mechanics

Privacy Policy

45%

Half facts, half rights and legal bases

Terms of Use

15%

Framework, with about ten facts about the site slotted in

Four rules the lawyers applied every time

  1. 01

    An unverified fact gets a caveat.

    I wrote that field masking in the session recorder was on by default and needed confirming. The lawyers wrote that the masking settings live in the vendor's console. Mark every answer as verified or not, and the caveat writes itself.

  2. 02

    Every figure is tied to a date.

    The tables keep the inventory as of a stated day. So every answer carries the date of the measurement.

  3. 03

    Consent mechanics are described in the words of the interface.

    The confirmation texts from the footer entered the policy verbatim. Build the mechanism first, write the policy second, never the other way around.

  4. 04

    Whatever depends on real use says so.

    Whether data is sold, whether a provider acts as a processor, whether server-side transfer happens: the answers carry facts, not legal qualifications.

What remained after the project

A module of 819 lines that turns the next project into two working days.

All 78 questions verbatim, each marked with where the answer comes from: about two thirds from the audit, roughly 16 for the client, the rest framework. Next to them the audit commands, the skeletons of the three policies with placeholders, a library of ready paragraphs, the order of rollout on Shopify, and a checklist of 15 points.

Each point of the checklist is a mistake I caught

  • Word splits long links in half on export. Every href is checked after conversion.
  • The site's own opt-out cookie belongs in the strictly necessary table.
  • Google's cookie lifetimes differ between Europe and the rest of the world.
  • The confirmation text on the site and in the policy must match character for character.
  • The policy must not promise more than the site does. If the email platform's loader stays after the opt-out, that is written plainly.

Rollout on Shopify

A page template with a section that renders the title and the content from the admin, so the texts are edited without a deploy. Template and section go in the first pull request, otherwise the admin has no template to pick. Then the pages in the admin, then the footer links in the second.

The proof that the audit pays for itself

Two weeks after the policies went live, half of the purchases began to disappear from the same client's analytics. With the same set of measurements I walked the chain from the storefront to the checkout and found the cause. The store's privacy settings required cookie consent for 20 US states, and there was no banner on the site where a visitor could give it. For those buyers the checkout pixel never started. The storefront events still went out, so the funnel broke exactly after the click to pay.

I checked it against the orders, then proved it with a direct test: with the setting on, the checkout pixel does not load; with it off, it loads at once and sends the event. Every test ran with the analytics endpoints blocked, so nothing landed in the client's data.

22 of 23

orders from the consent-required states missing from analytics

3 of 32

orders from the other states missing

Missing from analytics, not lost: the orders themselves went through. What broke was the measurement the ad spend is steered by.

What the client gets

  • A full inventory of what the site collects: cookies from both sides, storage, pixels, hosts, embedded apps and server-side integrations.
  • A check of which vendors respect the opt-out and which do not.
  • A working opt-out mechanism in the theme, not a line in a document.
  • Three policies assembled from the site's facts, with measurement dates.
  • A checklist that shows the document and the site say the same thing.

It works with any set of services. So far the projects have included subscriptions, A/B tests, two session recorders at once, server-side delivery to Meta and TikTok, an email platform, custom analytics code on the checkout and a separate sales channel. The method does not depend on the list; only the hosts and cookies in the configuration change.

Where I stop

I am not a lawyer. The choice of jurisdictions, arbitration, regulated niches, children under 13 and selling data as a business model go to a lawyer. The rest this module closes on its own.

Facts and figures

3
documents: Privacy Policy, Cookie Policy, Terms of Use
78
questionnaire questions: 18, 29 and 31
2/3
of the answers come from the technical audit; 16 questions go to the client
27 · 14 · 26 · 9
cookies, Web Pixels, third-party hosts and trackers on one page
4
integrations kept collecting after the opt-out through Shopify's API
60–120 → 2–4
tracker requests per page after the opt-out
80 · 45 · 15%
share of audit facts in the Cookie Policy, the Privacy Policy and the Terms
819
lines in the module, with a 15-point checklist
~2
working days from audit to published pages on a new project

Ownership

The audit, the answers, the opt-out mechanism, the page template and the checks are mine. The legal wording is the lawyers'; my part was making sure it matches what the site does.

Code: the guard snippet and the audit commands are shown on request.

The same storefront

Wellness DTC brand

The subscription buy box on native Selling Plans, the analytics through checkout and the real-user performance work on the store this page belongs to.

View case

Need the privacy side of your store sorted?

Send me your store and the markets you sell in. We’ll agree on the documents and setup your project needs.

Tell me about your store