Protecting the Store and the Orders
Last updated:
The platform is not your exposure
Shopify handles hosting security, patching and payment card compliance. That removes the largest category of risk that self-hosted stores carry.
What remains is yours: who can access the admin, what apps can do, and which orders you choose to fulfil.
Account security
- Two-factor authentication on every staff account, without exception
- Staff permissions limited to what each person needs
- Accounts removed the day someone leaves
- The account list reviewed quarterly
- App permissions reviewed — several request far more than they need
The most common compromise of a Shopify store is not technical. It is a staff account with a reused password and no second factor.
Fraudulent orders
Shopify flags high-risk orders. The flag is a prompt to look, not an instruction — and ignoring flags is how stores accumulate chargebacks.
- Review every high-risk flag before fulfilling
- Watch for mismatched billing and delivery addresses on high-value orders
- Be cautious with express delivery on first-time high-value orders
- Phone the customer where the value justifies it — genuine customers do not mind
Chargebacks
You will get some. What determines the outcome is evidence: proof of delivery, the order record, any correspondence, and your published policies.
Keeping delivery confirmation for every order is the single most useful habit for winning them.
Customer data
| Obligation | What to do |
|---|---|
| Privacy notice | Say what you collect and why |
| Data requests | Know how to export a customer's data |
| Deletion requests | Know how to honour them |
| App data sharing | Know which apps receive customer data |
| Retention | Decide how long, and apply it |
Frequently asked questions
Do we need PCI compliance?
Should we cancel every high-risk order?
What about app permissions?
How do we win chargebacks?
Staff accounts without two-factor?
That is the most common way a store gets compromised. Ten minutes to fix for everyone.