# Shopify Privacy Policy Switzerland, Setup Guide

> Shopify and data protection: Shopify's role, the data it processes, what your privacy policy must state, apps, cookies and pixels.

- Source: https://www.sidd.swiss/en/insights/shopify-privacy-policy-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Shopify is the most used cloud platform for online shops in Switzerland. It covers storefront, checkout, payment processing (Shop Pay, Shopify Payments), shipping, marketing and analytics in a single stack. That convenience has a data-protection flipside: Shopify Inc. (Canada) processes the personal data of your Swiss and EU customers across a global data-centre network in which the US plays a major role. On top of that come thousands of third-party apps in the Shopify App Store, each of which represents its own disclosure.

This article shows:

- which role Shopify plays as processor, sub-processor and partly as independent controller;
- which contractual foundations (Shopify DPA, EU SCCs, Swiss-US DPF) you need;
- which mandatory information your privacy policy must contain (Art. 19 DSG / Art. 13 GDPR);
- how to vet Shopify apps from a data-protection standpoint before installing them;
- which cookie and pixel apps require particular attention under DSG and GDPR;
- and how to cleanly integrate Swiss online-shop specifics (UID, VAT number, packaging and recycling notices).

Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 16, 19, 22), GDPR (Art. 6, 13, 28, 44 et seq.), Swiss Telecommunications Act (TKG/FMG), Unfair Competition Act (UWG), ePrivacy Directive.

## Shopify as processor, and more

Shopify Inc. (headquartered in Ottawa, Canada) acts as **data processor** for your shop operation under Art. 9 DSG and Art. 28 GDPR. The contractual basis is the Shopify *Data Processing Addendum*, which is automatically incorporated into the Shopify Merchant Terms of Service when you open a shop as a European merchant. It includes the EU SCCs (Module 2) and, since 2023, a Swiss Addendum.

Importantly, Shopify wears two additional hats that are often missed:

1. **Independent controller for Shop Pay:** if you enable Shop Pay as the accelerated checkout, Shopify links buyer data into a cross-merchant network profile. Here Shopify acts as controller vis-à-vis the buyer, and your customers must be informed of this.
2. **Independent controller for platform telemetry:** performance data, fraud scoring, security logs.

Canada has held an EU Commission adequacy decision since 2018, so transfers from Switzerland/EU to Canada are adequately protected (Art. 16(1) DSG read with Annex 1 of the Data Protection Ordinance). The picture is different for sub-processors in the US: here the Swiss-US DPF / EU-US DPF apply, supplemented by SCCs plus a TIA.

## Data that Shopify processes

A standard order generates the following categories of personal data:

- **Customer master data:** name, delivery and billing address, email, phone.
- **Order data:** products, quantities, prices, shipping option, order date.
- **Payment data:** with Shopify Payments, the payment runs via Shopify as payment service provider and via Stripe as sub-processor. Full card data does not land on your server but with the PCI-DSS-certified provider.
- **Behavioural data:** IP address, browser, device fingerprint, session and cart data, heatmaps (when activated).
- **Marketing data:** newsletter subscriptions, click tracking, push permissions.

Things get sensitive with apps that harvest additional data points, for example loyalty apps with birth date, subscription apps with IBAN, B2B apps with UID or verification apps with ID scans. Each enrichment is a separate disclosure to a further processor and requires its own justification in the record of processing activities.

## Mandatory information in the privacy policy

A complete Shopify privacy policy for Switzerland must cover at least the following points (Art. 19 DSG / Art. 13 GDPR):

1. **Identity of the controller:** company, registered office, UID, contact person for data-protection matters (email, phone where available).
2. **Platform notice:** reference to Shopify Inc. (Canada) and Shopify International Ltd. (Ireland) as technical platform operators.
3. **Processing purposes:** order processing, payment, shipping, customer service, marketing (newsletter, retargeting), fraud prevention.
4. **Categories of personal data:** as listed above.
5. **Legal bases:** contract performance, legitimate interest (fraud prevention), consent (marketing, non-essential cookies).
6. **Recipients:** Shopify, Stripe, PayPal, TWINT, shipping providers, ERP/CRM integrations, marketing apps in use.
7. **Cross-border transfers:** Canada (adequacy decision), US (Swiss-US DPF, EU-US DPF, SCCs), other countries depending on app.
8. **Retention period:** order data 10 years (Art. 957 et seq. CO, Swiss VAT Act), marketing data until withdrawal, cookies as per cookie table.
9. **Data-subject rights:** access, rectification, deletion, data portability, objection; right to lodge a complaint with the FDPIC.
10. **Cookies and tracking:** separate cookie notice or cookie table with provider, purpose and retention period.

## Vetting apps from the Shopify App Store

Every installed app is another disclosure under data-protection law. Swiss merchants face the issue that many apps come from small providers in the US, India, Singapore or China and don't offer clean DPAs. We recommend a two-stage review:

**Stage 1, before installation:**

- Identify data categories the app requests access to (visible in the install dialog).
- Read the app vendor's DPA / privacy policy and check for SCC / DPF certification.
- Verify the business address and country of registration.
- Cross-check App Store reviews, particularly for data-protection complaints.

**Stage 2, periodically (at least annually):**

- Reconcile the app inventory against your record of processing activities.
- Uninstall obsolete or unused apps, every unused app is a compliance risk and an attack vector.
- For apps with access to sensitive personal data: run a DPIA.

A pragmatic rule of thumb: if an app does not deliver a DSG/GDPR-capable DPA within 30 days, uninstall. There is almost always an alternative.

## Cookies, pixels and consent mode

Since 2023, Shopify has had a built-in **Customer Privacy** API with which you can activate a cookie banner. The *cookie banner* option is available under Settings → Customer Privacy and supports an opt-in mode for the EU. For Switzerland alone, in most cases a simple cookie notice with opt-out option suffices, but as soon as you target EU customers or use marketing cookies, the opt-in regime of the ePrivacy Directive applies.

Critical cookie and pixel apps:

- **Meta Pixel (Facebook/Instagram):** requires a Conversion API interface that transmits personal data to Meta. Lawful only after consent.
- **Google Analytics 4 + Google Ads:** even with server-side tagging and Google Consent Mode v2, mandatorily only after consent. Watch the default Consent Mode status.
- **TikTok Pixel:** currently particularly critical from a data-protection standpoint, cross-border transfer to the PRC, limited DPA, Schrems II issues without DPF equivalent.
- **Hotjar / Microsoft Clarity:** session recording = profiling. DPIA recommended, masking of sensitive fields mandatory.

Use a Consent Management Platform (Cookiebot, Usercentrics, CCM19) and couple the apps to the consent category, otherwise your cookie banner becomes a fig leaf.

## Swiss online-shop specifics

Beyond data protection in the strict sense, Swiss Shopify shops must reflect additional regulatory duties that land in the privacy policy and the imprint:

- **Imprint:** mandatory under Art. 322 of the Swiss Criminal Code / Art. 3 UWG: company, address, email, UID, commercial register entry where applicable.
- **VAT notice:** Swiss VAT number (CHE-XXX.XXX.XXX MWST) for VAT-liable merchants.
- **T&Cs:** delivery conditions, return rights (for CH sales: no statutory withdrawal right, voluntary regulation common; for EU consumers: 14-day right of withdrawal mandatory).
- **VeVa and VREG notices:** Packaging Ordinance and Ordinance on the Return of Electronic Equipment for electronics shops.
- **DSA platform duties:** if you use an open marketplace setup, EU Digital Services Act obligations may apply to the extent you serve EU consumers.
- **Newsletter marketing:** double opt-in, clear unsubscribe option, separation of advertising and information (UWG Art. 3(o)).

The privacy policy is not a T&C copy, but it should cross-reference these documents so customers can quickly understand the full legal framework.

## How SIDD supports you

SIDD accompanies Swiss online shops from first setup to multi-country rollout. For Shopify shops we offer:

- Shop audit covering privacy policy, T&Cs, imprint, cookie banner;
- App inventory review and DPA collection for all installed apps;
- DPIA for high-risk apps (loyalty, subscription, fraud scoring);
- mandates as external [data-protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland);
- GDPR DPO for shops with EU nexus ([GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu)) and EU representation ([EU representative](https://www.sidd.swiss/en/services/eu-representative));
- UK representation for shops shipping to the UK ([UK representative](https://www.sidd.swiss/en/services/uk-representative));
- penetration tests and vulnerability scans against Shopify themes and custom apps ([penetration testing](https://www.sidd.swiss/en/services/penetration-test), [vulnerability scanning](https://www.sidd.swiss/en/services/vulnerability-scan));
- privacy workshops for marketing and CRM teams ([privacy workshop](https://www.sidd.swiss/en/services/data-protection-workshop-sme)).

Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a quote via the [quote form](https://www.sidd.swiss/en/quote). We deliver a Shopify quick-check within three working days.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
