Secure Transmission Policy

Shopify securely transmits your sensitive information via secure encrypted methods.

Introduction

Welcome to Shopify!

As part of our mission of helping make commerce better for everyone, Shopify Inc. and its affiliates, including Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., Shopify (USA) Inc., and Shopify International Limited (collectively, “Shopify”) collect and process a lot of information. This Privacy Policy is intended to help you better understand how we collect, use and store your personal information—whether you are a merchant or end user that uses Shopify’s products, applications or services (together, the “Services”), a customer that shops at a store using our technology, a participant in Shopify’s “Partners” program, or whether you’re simply visiting this website. By using any of Shopify’s Services, or by dealing with a merchant using Shopify’s Services, you are agreeing to the terms of this Privacy Policy and, as applicable, the Shopify Terms of Service.

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our privacy practices or for other operational, legal, or regulatory reasons. If we make material changes to this Privacy Policy, we will give you notice of such changes by posting the revised policy on this Website, and where appropriate, by other means. By continuing to use this Website or the Support Service after these changes are posted, you agree to the revised policy.

2. Information from merchants

Privacy matters! If you are a merchant, you agree to post a privacy policy on your storefront that complies with the laws applicable to your business. You also agree to obtain consent from your customers for the use and access of their Personal Information by Shopify and other third parties. In addition, if you are collecting any sensitive Personal Information from your customers (including information relating to medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or sexuality), you agree to obtain affirmative, express consent from your customers for the use and access of sensitive Personal Information by Shopify and other third parties. To help you get started on creating your own privacy policy, check out our policy generator.

What information do we collect from merchants and why?

  • We collect your name, company name, address, email address, phone number(s) and credit card details.
    • We need this information to provide you with our Services; for example, to confirm your identity, contact you, and invoice you.
  • We collect data about the Shopify-hosted webpages that you visit. We also collect data about how and when you access your account, including information about the device and browser you use, your network connection and your IP address.
    • We need this information to give you access to and improve our Services.
  • Upon completing the sign-up process for the Services, and depending on your location, we may create a Shopify Payments account on your behalf. If you activate a Shopify Payments account (applicable only to Canada, US, UK, and Australia merchants), we collect your business address, business type, business ID number, date of birth (if you are an individual business owner), bank account information and government-issued identification information, such as your Social Security Number or your Social Insurance Number or, alternatively, if you are Canadian merchant and elect not to provide your Social Insurance Number, a copy of your government-issued identification.
    • We need this information to create a Shopify Payments account for you, to provide you with Shopify Payments services, including fraud and risk monitoring, and to comply with applicable legal and regulatory requirements.
  • We collect Personal Information about your customers that you share with us or that customers provide while shopping or during checkout.
    • We use this information to provide you with our Services and so that you can process orders and better serve your customers.
  • We will also use Personal Information in other cases where you have given us your express permission.

When do we collect this information?

  • We collect Personal Information when you sign up for our Services, when you access our Services or otherwise provide us with the information.

3. Information from our merchants’ customers

What information do we collect and why?

  • We collect our merchants’ customers’ name, email, shipping and billing address, payment details, company name, phone number, IP address and device data.
    • We need this information to provide merchants with our Services, including supporting and processing orders, authentication, and processing payments. We also use this information to improve our Services.

When do we collect this information?

  • Information is collected when a merchant’s customer uses or accesses our Services, such as when a customer visits a merchant’s site, places an order or signs up for an account on a merchant’s site.

4. Information from Partners

Partners are individuals or businesses that have agreed to the terms of the Shopify Partner Program to work with Shopify to promote the Services by (a) referring clients to Shopify; (b) developing Shopify store themes for merchant use; or (c) developing apps using the Shopify Application Interface (API) for merchant use.

What information do we collect from Partners and why?

  • We collect your name, company name, website, twitter or other social media handles, phone number(s), address, business type, email address, PayPal Account, and GST/HST number.
    • We use this information to work with you, confirm your identity, contact you, and pay you.
  • We collect data about the Shopify-hosted webpages that you visit and how and when you access your account, including information about the device and browser you use, your network connection and your IP address.
    • We use this information to give you access to and improve our Services.
  • We collect Personal Information about your customers that you share with us or that they provide to us directly.
    • We use this information to work with you and to provide our Services to your customers.
  • We will also use Personal Information in other cases where you have given us express permission.

When do we collect this information?

  • We collect this information when you sign up for a Partner Account, when you sign up one of your customers for our Services, or when your customers sign up themselves. We also collect any additional information that you might provide to us.

5. Information from Shopify website visitors and support users

What information do we collect and why?

  • From Shopify website visitors, we collect information about the device and browser you use, your network connection and your IP address. We also collect Personal Information submitted by you via any messaging feature available from any of our websites (“Messaging Feature”).
  • We may also receive Personal Information when you purchase tickets or make other requests to Shopify via any of our websites.
  • From telephone support users, we collect your phone number and call audio.
  • From chat support users, we collect your name, email address, information about the device and browser you use, your network connection, your IP address and chat transcript.
  • From forum users, we collect your name, email address and website URL.

We use this information to provide and enhance our Services (including servicing your account, if applicable), and answer any questions you may have.

When do we collect this information?

  • We collect this information when you visit Shopify-hosted webpages, use Services offered on our websites or engage with us either by email, web form, instant message, phone, or post content on or through our websites (including forums, blogs and via any Messaging Feature). We also collect any additional information that you might provide to us.

6. Information from cookies and similar tracking technology

What is a cookie? A cookie is a small amount of data, which may include a unique identifier. Cookies are sent to your browser from a website and stored on your device. We assign a different cookie to each device that accesses our website.

Why does Shopify use cookies and similar tracking technology?

  • We use cookies to recognize your device and provide you with a personalized experience.
  • We also use cookies to serve targeted ads from Google, Facebook, Bing, and other third-party vendors.
  • Our third-party advertisers use cookies to track your prior visits to our websites and elsewhere on the Internet in order to serve you targeted ads. For more information about targeted or behavioral advertising, please visit https://www.networkadvertising.org/understanding-online-advertising.
  • Opting out: You can opt out of targeted ads served via specific third party vendors by visiting the Digital Advertising Alliance’s Opt-Out page.
  • We may also use web beacons, tracking technology and other automated tracking methods on our websites, in communications with you, and in our products and services, to measure performance and engagement.
  • Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

7. When and why do we share Personal Information with third parties?

  • Shopify works with third parties to help provide you with our Services and we may share Personal Information with them to support these efforts. In certain limited circumstances, we may also be required to share information with third parties to conform to legal requirements or to respond to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also receive Personal Information from our partners and third parties.
    • Personal Information may be shared with third parties to prevent, investigate, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service or any other agreement related to the Services, or as otherwise required by law.
    • Personal Information may be shared with third party vendors to help us conduct marketing and/or advertising campaigns.
    • Personal Information may also be shared with a company that acquires our business, whether through merger, acquisition, bankruptcy, dissolution, reorganization, or other similar transaction or proceeding. If this happens, we will post a notice on our home page.
  • Shopify is responsible for all onward transfers of Personal Information to third parties in accordance with the EU-U.S. Privacy Shield Principles, the U.S.-Swiss Safe Harbor Framework, and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
  • Shopify will always ask for your consent before sharing your Personal Information with third parties for purposes other than those described in this Section 7.

8. What do we do with your Personal Information when you terminate your relationship with us?

  • We will continue to store archived copies of your Personal Information for legitimate business purposes and to comply with the law.
  • We will continue to store anonymous or anonymized information, such as website visits, without identifiers, in order to improve our Services.

9. What we don’t do with your Personal Information

  • We do not and will never share, disclose, sell, rent, or otherwise provide Personal Information to other companies (other than to specific Shopify merchants you may be interacting with) for the marketing of their own products or services.
  • If you are a merchant using Shopify’s Services, we do not use the Personal Information we collect from you or your customers to independently contact or market to your customers. However, Shopify may contact or market to your customers if we obtain their information from another source, such as from the customers themselves.

10. How do we keep your Personal Information secure?

  • We follow industry standards on information security management to safeguard sensitive information, such as financial information, intellectual property, employee details and any other Personal Information entrusted to us. Our information security systems apply to people, processes and information technology systems on a risk management basis.
  • We perform annual audits to ensure our handling of your credit card information aligns with industry guidelines. We are certified as a PCI DSS Level 1 compliant service provider, which is the highest level of compliance available, and our platform is audited annually by a third-party qualified security assessor.
  • No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee the absolute security of your Personal Information.

11. Residents of the European Economic Area (“EEA”)

Shopify works with merchants and users around the world, including in the EEA. If you are located in the EEA, your personal information is processed by Shopify’s Irish affiliate, Shopify International Ltd. Please note that as part of our service, we may transfer your personal information to other regions, including to Canada and the United States. In order to ensure that your information is protected when transferred out of the EEA, Shopify relies on the EU-U.S. Privacy Shield (described in more detail below), as well as inter-company agreements between our various affiliates that may process your information on behalf of Shopify International Ltd.

Additionally, if you are located in the EEA, you have certain rights under European law with respect to your personal data, including the right to request access to, correct, amend, delete, or limit the use of your personal data. In order to exercise these rights, please reach out to us using the contact information below.

12. How do we protect your information across borders?

While Shopify Inc. is a Canadian company, we provide services to customers and our technology processes data from users around the world. Accordingly, Shopify may transmit your personal information outside of the country, state, or province in which you are located.

Shopify (specifically Shopify’s affiliates Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., and Shopify (USA) Inc.) complies with the EU-U.S. Privacy Shield Framework, regarding the collection, use, and retention of Personal Information from data subjects in the European Economic Area (“EEA”), and with the Swiss-U.S. Privacy Shield Framework regarding the collection, use and retention of Personal Information from data subjects in Switzerland. In this regard, we have certified that we adhere to the Privacy Shield Principles of notice, choice, accountability for onward transfers, security, data integrity and purpose limitation, access, recourse, enforcement and liability.

If you are located in the EEA or in Switzerland, and believe that your Personal Information has been used in a manner that is not consistent with the relevant privacy policies listed above, please contact us using the information below. If your complaint or dispute remains unresolved, you may also contact the International Centre for Dispute Resolution®, the international division of the American Arbitration Association® (ICDR/AAA). This organization provides independent dispute resolution services, at no charge to you. ICDR/AAA can be contacted at http://go.adr.org/privacyshield.html.

If, after attempting to resolve a dispute through ICDR/AAA, you feel that your concerns about the use of your Personal Information have not been resolved, you may seek resolution of the issue through binding arbitration. For more information about the binding arbitration process, please visit http://www.privacyshield.gov.

By participating in the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework, Shopify’s participating U.S. entities are subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. For more information about the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield, please visit https://www.privacyshield.gov. You can view Shopify’s certification statement at https://www.privacyshield.gov/participant?id=a2zt0000000TNSNAA4&status=Active.

13. Control and access to your Personal Information

You retain all rights to your Personal Information and can access it anytime. In addition, Shopify takes reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Information. You can update many types of Personal Information, such as payment or contact information, directly within your account settings. If you are unable to change your Personal Information within your account settings, please contact us to make the required changes. It’s important to remember that if you delete or limit the use of your Personal Information, the Services may not function properly.

If you have any questions about your Personal Information or this policy, or if you would like to make a complaint about how Shopify processes your personal data, please contact Shopify by email at privacy@shopify.com, or by using the contact details below:

Residents outside of the European Economic Area:

Shopify Inc.
Attn: Chief Privacy Officer
150 Elgin St., 8th Fl
Ottawa, ON K2P 1L4
Canada

Residents of the European Economic Area:

Shopify International Limited
Attn: Data Protection Officer
c/o Intertrust Ireland
2nd Floor 1-2 Victoria Buildings
Haddington Road
Dublin 4, D04 XN32
Ireland

Last updated: October 25, 2017
© 2017 Shopify Inc.