S
E-commerce

TruePrivacy + Shopify

Manage customer data, consent, and deletion requests across your Shopify store.

Auth: OAuth 2.0
Setup time: 5 minutes

Overview

Shopify is the world's leading e-commerce platform, storing customer profiles, order history, addresses, and payment method references for millions of merchants. TruePrivacy integrates with Shopify to discover personal data across customers, orders, and metafields, to manage cookie consent through Shopify's storefront, and to automate customer deletion requests for GDPR and CCPA compliance.

For Shopify merchants, TruePrivacy is the compliance layer that handles the full customer privacy lifecycle — from cookie consent at first visit, to marketing consent at checkout, to deletion requests from former customers — without requiring any custom development.

What TruePrivacy can do

Data Discovery
DSR Automation
Consent Management
Cookie Banner

Data types accessed

  • Customer profiles
  • Order history
  • Shipping addresses
  • Email addresses
  • Phone numbers
  • Payment method references
  • Customer tags and metafields

DSR capabilities

  • Anonymise customer records via Shopify's erasure webhook
  • Export customer data and order history for access requests
  • Update marketing consent and email subscription status
  • Remove customers from marketing lists across connected platforms
  • Respond to Shopify's mandatory erasure webhooks within 30 days

How it works

  1. 1

    Install TruePrivacy from the Shopify App Store or connect via OAuth 2.0 — setup takes under 5 minutes.

  2. 2

    TruePrivacy scans Shopify customers, orders, draft orders, and metafields for personal data, building a complete customer data inventory.

  3. 3

    TruePrivacy's cookie banner is embedded in your Shopify storefront and consent is captured at checkout using Shopify's native consent API.

  4. 4

    Customer deletion requests are processed via Shopify's Customer Privacy API, anonymising the customer record while preserving order history for accounting purposes.

Frequently asked questions

Shopify sends customers/redact and shop/redact webhooks when data erasure is requested. TruePrivacy receives these webhooks automatically and processes them through the TruePrivacy DSR workflow — ensuring the erasure is completed within Shopify's 30-day deadline and documented in the compliance audit trail.

No. Shopify's erasure API anonymises the customer record (replacing personal data with generic values) while preserving order records for accounting purposes. Order records lose their personal data linkage but remain in Shopify for financial reporting. This approach satisfies GDPR's right to erasure while respecting financial records retention requirements.

TruePrivacy's cookie banner is deployed via Shopify's theme script injection. It integrates with Shopify's Customer Privacy API for consent signal handling and supports Shopify Markets for multi-region consent experiences (GDPR for EU, CCPA for California, etc.).

Yes. With both Shopify and Klaviyo connected to TruePrivacy, a single deletion DSR triggers deletion workflows in both platforms simultaneously. TruePrivacy waits for confirmation from both before issuing the deletion certificate.

Connect TruePrivacy to Shopify today

Start your free trial and connect Shopify in 5 minutes.