A beauty brand we work with on Shopify Plus had a "Do Not Sell or Share My Personal Information" form in its footer for years. Nobody thought about it until the requests went from one or two a year to eight in a single month, and the brand's IT and legal teams asked a simple question: when someone submits this form, are they actually opted out everywhere?
The honest answer was no. The form sent an email to the customer service inbox. The reply told the shopper to decline cookies in the banner. Nothing was recorded on the customer's profile, nothing reached Klaviyo, and the shopper's email stayed in every advertising audience it had already been synced to. The store was not unusual. In our experience, most Shopify stores that have the link in the footer have exactly this gap behind it.
This article is what we learned fixing it: what the law requires of the process, what Shopify's built-in tools actually do when a request comes in, where the request stops, and the process we now recommend. It is written for the person who owns the store, not the lawyer, though your lawyer should read the second section.
A note before we get into it: this is general information, not legal advice. Privacy regulation is changing quickly and the details of your setup matter. For decisions your business puts weight on, talk to a privacy attorney.
TL;DR: A Do Not Sell request has to be honored within 15 business days, without asking the shopper to verify their identity or create an account. Shopify's own opt-out page handles the browser it was submitted from and Shopify Audiences, and nothing else. To honor the request for the person rather than the browser, set Shopify's profile-level flag and a tag, exclude that tag from every Klaviyo segment that feeds an ad audience, make sure scripts outside Shopify's pixel manager respect consent, and keep a hashed record for shoppers who have no account yet. Send a notice with an undo link after processing, never a confirmation link before it.
What the Law Requires, and What It Forbids
California's rules are the most detailed and the most enforced, so they are the ones a process should be built around. As of 2026, 20 states have comprehensive privacy laws in effect (19 if you set aside Florida's narrow one), and twelve of them require businesses to honor browser opt-out signals. Indiana, Kentucky and Rhode Island came online in January 2026; Oklahoma, Alabama and Louisiana follow in 2027.
Mid-sized brands often assume these laws are for companies far larger than themselves. Check the thresholds before relying on that. California applies if you have $26.6 million or more in annual revenue, or if you buy, sell or share the personal information of 100,000 or more California residents. "Share" includes sending browsing data to Meta or Google for retargeting, so a store with a few hundred thousand California visitors a year and a Meta pixel is usually in regardless of revenue. Texas and Nebraska have no revenue or headcount threshold at all; anything above a small business as the SBA defines it is covered.
For the opt-out process itself, the California regulations are specific. The same ideas run through the other states' laws.
- The link. A link titled "Do Not Sell or Share My Personal Information" in the header or footer of every homepage, which either applies the opt-out immediately or leads to a page where the shopper can make that choice. (11 CCR 7013)
- Minimal steps. The method "shall be easy for consumers to execute, shall require minimal steps." The path to the more private choice cannot be longer or harder than the path to the less private one. "Accept all" with no equivalent "Decline all" is the textbook violation. (7026(b), 7004)
- No account. You cannot require the shopper to create an account, or provide more information than you need to carry out the opt-out. (7026(c))
- No verification. "A business shall not require a verifiable consumer request for a request to opt-out of sale/sharing." You may deny a request only with a good-faith, reasonable and documented belief that it is fraudulent, and you have to tell the requester why. (7026(d), (e))
- 15 business days. Comply as soon as feasible and no later than 15 business days after receipt. In that window you must also notify every third party you sold or shared the person's data with and direct them to stop. (7026(f))
- 12 months of silence. You must wait at least 12 months before asking an opted-out shopper to opt back in, and opting back in must be a two-step process: a clear request, then a separate confirmation. (7026(k), 7028)
- Browser signals. A Global Privacy Control (GPC) signal from the shopper's browser is a valid opt-out request and must be processed without any extra steps. Since January 1, 2026, you must also display whether you have honored it, for example with a status line or a toggle that shows the opt-out is in effect. (7025)
Penalties are currently $2,663 per violation and $7,988 per intentional violation, with no right to a cure period since 2023. Regulators have been treating each affected consumer as a violation when they negotiate.
What enforcement has actually targeted
The pattern in the public settlements is worth a close read, because almost every one is about process friction rather than a data breach.
| Date | Company | Penalty | What went wrong |
|---|---|---|---|
| Aug 2022 | Sephora | $1.2M | Did not process Global Privacy Control signals; did not disclose that it was selling data |
| Mar 2025 | Honda | $632,500 | Required verification and excessive information to opt out; cookie tool had no symmetrical decline |
| May 2025 | Todd Snyder | $345,178 | Misconfigured consent banner failed to process opt-outs for 40 days; required identity verification to opt out |
| Jul 2025 | Healthline | $1.55M | Kept sharing with ad vendors after opt-out; consent banner did not actually disable tracking |
| Sep 2025 | Tractor Supply | $1.35M | No effective opt-out mechanism, including for Global Privacy Control |
| Feb 2026 | Disney | $2.75M | Opt-out applied only to the device and service it was made on, even for logged-in users |
| Mar 2026 | Ford | $375,703 | Required email verification before processing opt-outs |
Two of those are retailers, and one of them is a beauty retailer whose entire case was a browser signal that nobody had wired up. The Todd Snyder decision came with a line from the regulator that applies to every Shopify store running a consent app: using a consent management platform does not get you off the hook for compliance. And the Disney case established the point that matters most for the rest of this article: an opt-out that only covers the device it was made on, when you know who the person is, is not an opt-out.
What Shopify Actually Does With a Request
Shopify gives you a data sharing opt-out page under Settings > Customer privacy. You pick the regions it shows in, or let Shopify's automated settings pick them, and the "Your Privacy Choices" icon and link are added to your footer menu. Here is what happens when a shopper uses it, pieced together from Shopify's documentation, its developer docs and answers from Shopify staff on the community forum.
- The browser is opted out. Consent is stored in a first-party cookie that lasts a year. Pixels that run through Shopify's pixel manager, including the Meta, Google, Pinterest and TikTok channel pixels and any custom pixel configured as "data sale," stop firing in that browser. Shopify Audiences and Shopify's own advertising use of the data are told to exclude the visitor.
- Nothing visible happens. There is no confirmation email and no on-screen message by default. Nothing appears on the customer record in the admin. A merchant on the Shopify forum tested their own form and reported that "nothing was added to the customer's record." Shopify staff confirmed the request is processed in the background and synced to Audiences, and that the only way to see it is under the Audiences app's customer opt-out list.
- The opt-out follows the browser, not the person. The consent cookie lives in one browser on one device. Shopify does have a profile-level flag,
dataSaleOptOuton the customer record, but it is only settable through the Admin API with a dedicated mutation keyed by email. It is not in the customer CSV import, there is no query filter to find opted-out customers, and Shopify does not document any link between the profile flag and the browser cookie. Treat them as two separate records that you have to set separately. - Global Privacy Control works only where the page is enabled. Shopify's docs say the signal "is automatically collected and honored in regions configured for data sale opt-out." If your region list was set by hand two years ago and California is not on it, the signal is silently ignored for Californians. The store in our story had exactly this problem.
- No app is told. Shopify's mandatory privacy webhooks for apps cover data access requests, deletion requests and shop deletion. There is no webhook or event for a data sale opt-out. Shopify staff said it plainly on the developer forum: there is no public API to add or verify that opt-out for third-party apps.
Shopify's opt-out is a browser-level setting applied to Shopify-managed surfaces. The law describes a person-level right that reaches every third party you shared with. Everything between those two definitions is your job.
Where the Request Leaks
Once you know what Shopify handles, the gaps are easy to list. These are the six we had to close.
| Gap | What happens today |
|---|---|
| New device, not logged in | The shopper opens the site on a new phone and is tracked again. Their consent cookie is on the old laptop. |
| Klaviyo audience syncs | Klaviyo keeps pushing the profile to Meta Custom Audiences hourly and Google Customer Match in real time. Klaviyo's Shopify integration syncs name, email, phone, subscription status, events and tags, and no data sale field. |
| Email suppression | Suppressing or unsubscribing the profile in Klaviyo does not remove it from ad audiences. Klaviyo's own help docs say you "may still target contacts who are suppressed" on Facebook. |
| Scripts outside the pixel manager | Review widgets, loyalty programs, chat, A/B testing and anything pasted into theme.liquid are only consent-aware if the vendor coded against Shopify's Customer Privacy API. Shopify does not gate them. Yotpo, for example, documents a support-ticket switch to disable its widget cookies, not a consent-aware one. |
| Guest shoppers | Many requests come from people with no customer record. A later order with the same email creates one, with no flag and no tag, and it syncs straight to Klaviyo. |
| Existing audiences | Excluding someone from future syncs does not remove them from audiences already built. Shopify says the same of Audiences: a manual exclusion "isn't removed from previously generated audiences." |
If you run a consent app such as Pandectes, Consentmo or Enzuzo, it most likely covers the fourth row: blocking theme scripts until consent, which is the same mechanism we covered in our article on wiretapping lawsuits against Shopify stores. It does not cover the rest. Consent apps manage what runs in the browser. They do not reach into Klaviyo's audience syncs or Meta's existing audiences, and the regulator has already said that installing one is not a defense.
The Process We Recommend
This is what we built, in the order the request flows. The whole thing is a small custom app plus configuration; nothing here needs a platform change.
1. Apply the browser opt-out the moment the form is submitted
When the form is submitted, call Shopify's Customer Privacy API in the shopper's browser with data sale set to false, the same thing the "Decline" button on the cookie banner does. This takes effect immediately on every Shopify-managed surface for that browser. Shopify's developer docs specifically say data sale opt-outs should run in a flow started by the customer, which a form submission is.
2. If a customer record exists, set the flag and a tag
Look the email up through the Admin API. If there is a customer, run the dataSaleOptOut mutation to set Shopify's profile-level flag, and add a do-not-sell tag. The flag is the correct record for Shopify. The tag is what reaches everything else, because almost every app that syncs customers from Shopify syncs tags, and almost none of them read the privacy flag. Write the request date and source to a metafield or the customer note so there is a record on the profile.
3. Exclude the tag from every segment that feeds an ad audience
In Klaviyo, the tag arrives as a "Shopify Tags" profile property. Add a condition of Shopify Tags doesn't contain do-not-sell to every segment connected to a Meta Custom Audience or a Google Customer Match audience. Klaviyo adds and removes audience members based on segment membership, so leaving the segment removes the profile from the audience on the next sync. Two details catch people here:
- A Klaviyo list cannot carry conditions. If any of your audience syncs run off a list rather than a segment, rebuild them on segments first.
- Do not unsubscribe or suppress the profile. The shopper asked you to stop sharing their data, not to stop emailing them. Those are different rights, and taking away the newsletter they signed up for is both a worse experience and a different problem.
Repeat the exercise for any other app that pushes customers to ad platforms, and for Shopify Audiences if you use it. The same tag works everywhere tags sync.
4. Make the scripts outside the pixel manager respect consent
Audit every script in the theme and every app embed against the consent state. Shopify's pixel manager already gates app pixels and custom pixels; check that each custom pixel is set to "qualifies as data sale," which is the default for new ones but not necessarily for old ones. For anything else, either confirm the vendor honors Shopify's Customer Privacy API or put it behind your consent app's blocking. Our script-blocking guide walks through this audit.
5. Turn on automated region settings for the opt-out page
This is a five-minute fix with the largest payoff. Switch the data sharing opt-out page from a manual region list to Shopify's automated settings, so the page, and with it Global Privacy Control, follows Shopify's current recommendations as states add signal requirements. Then add the status display that California has required since January 2026: when a signal has been honored, say so on the opt-out page. Shopify's Customer Privacy API exposes whether data sale is currently allowed, which is enough to render "Opt-out preference signal honored" when it is.
6. Keep a hashed record for shoppers who have no account
For a request with no matching customer, store a one-way hash of the email with the request date and source. Not the email itself; the regulations say the email given in an opt-out request may only be used to comply with it, and a hashed list cannot be repurposed. Then listen for new orders and new customer accounts. When one arrives, hash the incoming email, check it against the list, and if it matches, apply step 2 automatically before the record syncs anywhere.
Two alternatives come up every time, and both should be declined. Creating a Shopify customer record for the person, so you have somewhere to put the flag, pushes their email into Klaviyo and every other connected app the moment it is created. The person asked you to limit sharing and you have just widened it. On stores still on legacy customer accounts they will also meet an "account already exists" error when they try to sign up later. Asking them to create an account and resubmit is simpler and is flatly prohibited.
7. Send a notice after processing, with an undo link
The instinct is to send a confirmation email and only process the request once the link is clicked, to stop someone opting out a stranger. That is the thing Honda, Todd Snyder and Ford were fined for. Requiring a click before honoring the request is verification, and verification is not allowed for opt-outs.
Flip it. Process the request immediately, then email the address: we received a request to stop selling or sharing your information and have applied it; if this was not you, click here to undo. The real owner finds out either way. A bad actor gains nothing, because the worst a fake opt-out can do is keep someone out of ad audiences. And the undo link is where confirmation belongs: opting back in is supposed to be a two-step process, so a link that requires a click to restore sharing is exactly what the rules describe.
8. Block bulk abuse quietly, and log everything
A honeypot field, rate limiting per IP address and Shopify's built-in form protection stop someone from submitting a list of five thousand addresses. Avoid a visible CAPTCHA step; it is an extra step on the privacy-protective path, which the symmetry rule frowns on. Log the IP address and timestamp with every request. Two hundred requests from one address in an hour is the "documented belief" the fraud exception asks for. One stranger's email is not. California also requires you to keep records of consumer requests for at least 24 months, so keep the log in a place that survives staff changes.
9. Notify the third parties, and clean up existing audiences
The 15-day clock covers notifying the parties you shared with, not just stopping future shares. For the ad platforms, that means removing the person from audiences that already exist, which the Klaviyo exclusion does for synced audiences but not for ones built directly in Meta or Google from past uploads. Decide with counsel how far back the cleanup goes. For other recipients, the notice is usually an email to the vendor, which the custom app can send from a template.
Three Things Not to Do
- Do not hide the link. Two of the most-viewed Shopify forum threads on this page are merchants asking how to remove the "Do Not Sell or Share" link from their footer, with accepted answers explaining how to hide it with CSS. For a store with California traffic that is removing a legal requirement because it looked unexpected.
- Do not point people elsewhere. Sending shoppers to the industry opt-out pages run by the Network Advertising Initiative or the Digital Advertising Alliance in place of your own mechanism was one of the findings in the PlayOn Sports settlement in March 2026. You have to provide your own.
- Do not treat the inbox as the system. A form that emails your support team is a notification, not a process. The request has to land somewhere that changes what your systems do.
Test It Yourself This Week
Before changing anything, fill out your own Do Not Sell form and follow the request. Then answer these questions honestly:
- Did anything change on your customer record in Shopify?
- Is your email still in the Klaviyo segments that feed Meta and Google?
- Open the site in a private window on your phone. Are the pixels firing again?
- Turn on Global Privacy Control in a browser and visit from a California address or VPN. Does the opt-out page say the signal was honored?
- Submit the form with an email that has never ordered. Where did that request go?
For a lot of stores, the answer to the last one is "someone's inbox," and that is the whole problem in one sentence.
Need This Built?
The work described above is a small custom Shopify app plus Klaviyo and privacy configuration, and it is the same shape on every store we have looked at. If your legal team has asked the question this article opens with, we can scope it quickly. See our Shopify app and API integration services or talk to us directly.
Frequently Asked Questions
What does "Do Not Sell or Share My Personal Information" mean for a Shopify store?
Under California law, "sharing" includes sending a shopper's data to advertising platforms for cross-context behavioral advertising, which is what retargeting pixels and audience syncs do. A Do Not Sell or Share request asks you to stop that for one person. It does not ask you to delete their data or stop emailing them, and it does not require you to stop processing their orders.
Does Shopify's built-in data sharing opt-out page make my store compliant?
It covers the surfaces Shopify controls: Shopify Audiences, Shopify's own data use, and pixels that run through Shopify's pixel manager, for the browser the request was made in. It does not reach Klaviyo, review or loyalty apps, scripts added to your theme, or audiences already built on Meta and Google. Those are your responsibility, and Shopify does not notify them.
Can I ask the shopper to confirm by email before I process the opt-out?
No. The California regulations say a business may not require a verifiable consumer request for an opt-out of sale or sharing, and regulators have fined Honda, Todd Snyder and Ford for exactly this. Process the request first, then send a notice with an undo link. Opting back in is allowed to require confirmation, so the confirmation step belongs on the undo path.
Does a Do Not Sell request unsubscribe the shopper from my emails?
No. Opting out of data sale or sharing and unsubscribing from marketing are separate choices under the law. Keep sending the newsletter to anyone who is still subscribed. The reverse is also true: unsubscribing or suppressing a profile in Klaviyo does not remove it from Meta or Google audience syncs, so an unsubscribe is not an opt-out of sharing.
Does Klaviyo honor Shopify's data sale opt-out flag?
Not as far as Klaviyo documents. Its Shopify integration syncs names, emails, phone numbers, subscription status, events and Shopify tags, but no data sale field. The reliable approach is to add a tag such as do-not-sell in Shopify, let it sync as a Shopify Tag, and add a "Shopify Tags doesn't contain do-not-sell" condition to every segment that feeds a Meta or Google audience.
Does Shopify honor Global Privacy Control?
Only for visitors in regions where your data sharing opt-out page is enabled. If that region list was set by hand and California or another signal state is missing, the signal is ignored there. Switching the page to Shopify's automated region settings is the simplest fix. Twelve states require businesses to honor these signals as of 2026, and from January 2027 California will require browsers to offer one.
How long do I have to process a Do Not Sell request?
In California, as soon as feasibly possible and no later than 15 business days after you receive it. In the same window you must notify the third parties you sold or shared the person's data with and tell them to stop. Keep a record of the request; California requires records of consumer requests to be kept for at least 24 months.
What if the shopper has no Shopify customer account?
You still have to honor the request, and you cannot ask them to create an account first. Apply the browser-level opt-out immediately, then keep a one-way hash of the email with the request date so a later order or account creation with that email is flagged automatically. Do not create a customer record for them, because that record would sync to Klaviyo and other apps and spread the email to more systems.