Cookie policy for a Shopify store
A cookie policy and consent configuration for a Shopify store, drafted for the merchant with the privacy notice, for a fixed fee of £595 in five working days.
Cookie policy for a Shopify store
Buy now, £595A Shopify store sets the platform's own cookies, which the merchant cannot change, and the cookies and pixels the merchant adds through apps, the Facebook and Google integrations and the scripts pasted into the theme, which the merchant is responsible for. Shopify provides a consent banner and customer privacy settings, but they are off by default and they do not control every app. The cookie policy has to list what the store sets, the banner has to be switched on and configured so that the apps and pixels wait for consent, and the merchant has to understand what Shopify does with customer data as the merchant's processor. I draft the cookie notice and the privacy notice for the business, with guidance on configuring consent, for a fixed fee of £595, delivered in five working days.
Who this is for
Merchants in England and Wales selling through a Shopify store, from a first store to one with dozens of apps installed, whose consent banner is either off or set to the platform's defaults.
What matters in a Shopify cookie policy
What Shopify sets and what the merchant controls
Shopify sets cookies the platform needs (the cart, the session, the checkout, fraud prevention, its own analytics and the pixels that feed the merchant's dashboard), which the merchant cannot remove and which Shopify's documentation classifies into strictly necessary and the rest, and the merchant adds everything else: the apps it installs, the marketing pixels it connects, the scripts it pastes into the theme; the cookie notice has to list both, using Shopify's published list for the platform's cookies and an audit for the merchant's additions, by category (strictly necessary, performance, functional, marketing) with name, purpose, provider and duration, and the policy should say which the merchant controls and which it does not.
The apps, the pixels and the scripts merchants install
Review apps, popups, recommendation engines, chat widgets, email capture tools, analytics apps and the advertising pixels for social media and search all set cookies and send data to their providers, often before consent and sometimes for the provider's own purposes, and the merchant is the controller for the data they collect on its store; the policy should identify each app and pixel, the guidance should explain which can be made to wait for consent through Shopify's customer privacy settings and the apps' own consent integration and which cannot (and should be removed or replaced), and the merchant should review the apps it no longer uses, because an uninstalled app's cookies disappear and a forgotten one's do not.
The consent banner Shopify provides and the settings that make it lawful
Consent must be obtained before non-essential cookies and similar technologies are set, under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, and Shopify's own cookie banner, once enabled in the customer privacy settings, can block the platform's non-essential cookies and the compliant apps' cookies until the visitor consents, with a region setting that decides where it appears; the guidance covers enabling it for the United Kingdom, choosing the settings that block rather than merely inform, giving reject the same prominence as accept, and testing that nothing non-essential fires before consent, because the banner is off by default and merchants assume it is on.
The cookie notice and the audit of a store with apps
The cookie notice is produced from an audit of the live store (a scan in a logged-out browser with consent refused and then accepted, repeated when apps are added or removed), listing the platform's cookies from Shopify's documentation and the merchant's additions from the audit, and the policy should say when it was last updated and commit the merchant to repeating the audit when the store changes; the pack includes the notice built from the audit and the instructions for repeating it, and the privacy notice refers to the cookie notice rather than duplicating it.
The customer privacy settings, regions and refusals
Shopify's customer privacy settings let the merchant require consent before tracking, honour browser signals and apply the banner by region, and the guidance covers the choices (requiring consent in the United Kingdom and Europe, the treatment of visitors elsewhere, the sale of data settings that some United States laws require) and what happens when a visitor refuses (the store works, the cart works, the checkout works, the marketing pixels do not fire, the email capture does not pre-populate), so that the merchant can see that refusal costs it tracking rather than sales; the notice tells the visitor what refusing does.
Shopify as processor, the transfers and the privacy notice alongside
Shopify processes the merchant's customer data as its processor under the data processing addendum in Shopify's terms (which the merchant accepted without reading), hosts it outside the United Kingdom under the safeguards Article 46 of the UK GDPR requires, and uses some data for its own purposes as a controller (fraud prevention, its own analytics, the Shop app), which the merchant's privacy notice should explain alongside the payment processor, the shipping apps and the marketing platforms; the pack includes the privacy notice for the store, the marketing basis under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 for the email capture and the abandoned cart messages (which are marketing, needing consent or the soft opt-in), and the registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Is Shopify's cookie banner enough?
Once enabled, configured to block rather than inform, with reject as prominent as accept and the apps integrated with it, yes for the cookies it controls. It is off by default and does not control every app. The guidance covers the settings and the test.
Are abandoned cart emails marketing?
They are. They need consent or the soft opt-in (a customer who gave their email in the course of a purchase and could refuse marketing). The privacy notice states the basis and the capture form implements it.
We have thirty apps installed. Do they all need to be in the cookie notice?
Every app that sets cookies or sends data, yes, which the audit identifies. Apps that cannot wait for consent should be replaced, and apps nobody uses should be removed.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Cookie policy for a WordPress website
- Privacy notice for an e-commerce website
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.