FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Shop Pay

Shop Pay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Shop Pay do?

Shop Pay is Shopify's one click accelerated checkout that lets returning shoppers complete a purchase with stored email, address and payment information.

What is Shop Pay

Shop Pay is the accelerated checkout option that Shopify offers to merchants on its platform. Shoppers can enable Shop Pay on any participating store, which stores their email, shipping address, billing address and tokenised payment information at Shopify level. On the next visit to any Shop Pay enabled store, they can complete the purchase with a single click after a one time SMS code.

What cookies and data Shop Pay collects

The Shop Pay button writes _shopify_y, _shopify_s, _shopify_country, _orig_referrer and a tracked_start_checkout cookie on the merchant domain, plus _shop_pay session and authentication cookies on shopify.com. Shopify receives the shopper email, phone, full address, payment token, IP, browser fingerprint, cart contents and the cross store purchase history.

GDPR and ePrivacy implications

Loading the Shop Pay button reads existing Shop Pay cookies to detect a returning shopper and may pre fill information. EU regulators (CNIL in particular) consider the remember me capability to go beyond strictly necessary checkout, so Article 5(3) ePrivacy consent is required for the proactive prompt. The actual transaction relies on contract performance. PSD2 strong customer authentication still applies.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

Contract performance covers the actual purchase. The Shop Pay enrolment (one off across stores) and the cross store behavioural enrichment are based on the shopper consent given to Shopify directly. As the merchant you act as joint controller for the collection on your store, so disclose Shop Pay in your privacy policy with a link to Shopify''s policy.

Data transfers and hosting

Shopify Inc. is based in Ottawa, Canada (GDPR adequacy under PIPEDA). Production runs on Google Cloud in multiple regions and Shopify also operates Shopify International Limited in Ireland for EU merchants. Transfers to the US (where Shopify has subsidiaries) rely on the EU US Data Privacy Framework and Standard Contractual Clauses.

Practical compliance steps

Mention Shop Pay and Shopify Inc. in your privacy policy. Show the Shop Pay link explicitly so the shopper opts in. Confirm Shopify International Limited (Ireland) as your data controller when you set up your Shopify store. Sign the Shopify data processing addendum. Disable Shop Cash and Shop App promotions when not desired, since they rely on cross store profiling.

GDPR consent category

Preferences

Websites using Shop Pay must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for the payment transaction itself, plus consent (Art. 6(1)(a) GDPR) for the Shop Pay accelerated remember me feature and for any marketing tied to it
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, EU US Data Privacy Framework, PSD2, PCI DSS, Shopify Merchant Agreement

DPIA considerations

A DPIA is recommended when Shop Pay is combined with Shop Cash rewards, when shoppers are profiled across stores, when buy now pay later features (Shop Pay Installments) are offered, or when minors are part of the audience.

Sample consent text

Shop Pay enables one click checkout by remembering your email, address and payment information on Shopify infrastructure. By choosing Shop Pay you consent to Shopify Inc. (Canada and the United States) processing your data for payment, fraud prevention and remember me features.

Technical details

Tracking methodHosted Shopify accelerated checkout button with JavaScript SDK, Shop Pay Installments and one click payment flows
Server locationCanada (Shopify Inc., Ottawa) and Google Cloud regions worldwide
Data transferred outside the EUShop Pay is operated by Shopify Inc. (Ottawa, Canada) and processes payments globally on Google Cloud. Canada benefits from a GDPR adequacy decision under PIPEDA. Shopify also operates entities in Ireland and the US; transfers to the US rely on the EU US Data Privacy Framework and Standard Contractual Clauses.

Third-party domains contacted

shop.appshopify.comcdn.shopify.compay.shopify.com

Cookies placed

NameTypeDurationPurpose
_shopify_yfirst_party1 yearPersistent shopper identifier used by Shopify and Shop Pay
_shopify_sfirst_partysessionSession cookie used by Shopify storefront and Shop Pay
tracked_start_checkoutfirst_partysessionFlags that the shopper initiated the Shop Pay accelerated checkout
_shop_paythird_party1 yearAuthentication token for Shop Pay across stores
_orig_referrerfirst_partysessionStores the original referer at the start of the checkout

Shop Pay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Shop Pay set?

On the merchant domain Shop Pay writes _shopify_y, _shopify_s, _shopify_country, _orig_referrer and tracked_start_checkout. On shopify.com it adds _shop_pay session and authentication cookies, plus device fingerprinting data used to recognise returning shoppers.

Is consent required for Shop Pay?

The actual checkout runs on contract performance, so consent is not needed to complete the purchase. The remember me feature, the proactive Shop Pay prompt and cross store profiling require Article 5(3) ePrivacy consent and Art. 6(1)(a) GDPR consent for the related processing.

Which GDPR legal basis applies?

Contract performance for the payment and order delivery. Consent for the Shop Pay remember me feature and any marketing through Shop Cash. Legal obligation for tax and accounting retention. Legitimate interest for fraud prevention.

Are there transfers to the United States?

Yes, indirectly. Shopify Inc. is Canadian (GDPR adequate) but operates US subsidiaries and routes payment data through US infrastructure. Cover transfers with the EU US Data Privacy Framework and Standard Contractual Clauses; rely on Shopify International Limited (Ireland) as the EU controller of the merchant relationship.

Do I need a DPIA?

Recommended for high volume merchants, for buy now pay later integration (Shop Pay Installments), when minors are part of the audience, when fraud scores are reused for marketing, or when Shop Cash rewards are activated.

How do I implement Shop Pay compliantly?

Disclose Shop Pay in your privacy policy with a link to Shopify, configure Shopify with EU as the data residency where supported, sign the Shopify DPA, disable Shop App promotions and Shop Cash if not needed, and honour deletion requests by routing them through Shopify.

Are there alternatives to Shop Pay?

Other accelerated checkouts: Apple Pay, Google Pay, Klarna, PayPal Express, Amazon Pay. For EU specifically: Bancontact, iDEAL, Giropay, SEPA Instant via Mollie or Adyen. Shopify also supports them natively.

How do I update my cookie policy for Shop Pay?

List _shopify_y, _shopify_s, _shopify_country, _orig_referrer, tracked_start_checkout and the _shop_pay cookies set on shopify.com with purpose and duration. Disclose Shopify Inc. as joint controller with you for the collection step and mention the EU US Data Privacy Framework basis.