The Shopify DPDP problem
A typical Shopify store runs many third-party apps, often 15 to 40, each receiving customer personal data, and tracking pixels that frequently fire before the customer has consented. Under the DPDP Act, every app is a processor the merchant is responsible for, and pixels firing pre-consent are a compliance gap. Consent has to be wired in through the Shopify Customer Privacy API.
Easy to add functionality, easy to lose track
Reviews, upsells, email, SMS, analytics, loyalty, support, and shipping apps each plug into your store and each may receive customer data. Under the Act, every one of those apps is a processor you are accountable for, whether or not you remember installing it.
The pixel problem
Many tracking and advertising pixels load and start collecting on page view, before the customer has agreed to anything. Under the Act, that is processing without consent. Fixing it means gating pixels and tags behind consent state, so nothing fires until the customer has chosen.
The Shopify Customer Privacy API
Shopify provides the tool to do this through its Customer Privacy API, which exposes consent state your store can read and act on. The work is wiring your apps, tags, and pixels to respect that state, and rewriting your policies to match what the store actually does.
"The fastest path is an app-stack audit that finds every data flow, then consent wiring and rights workflows on top."
Next step
Find out how compliant your product is.
Ten questions covering consent, data rights, security, and breach readiness. Takes two minutes.
Start the readiness check →Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.