Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
Shopify & eCommerce

Protecting the Store and the Orders

Last updated:

The platform is not your exposure

Shopify handles hosting security, patching and payment card compliance. That removes the largest category of risk that self-hosted stores carry.

What remains is yours: who can access the admin, what apps can do, and which orders you choose to fulfil.

Account security

  1. Two-factor authentication on every staff account, without exception
  2. Staff permissions limited to what each person needs
  3. Accounts removed the day someone leaves
  4. The account list reviewed quarterly
  5. App permissions reviewed — several request far more than they need
The most common compromise of a Shopify store is not technical. It is a staff account with a reused password and no second factor.

Fraudulent orders

Shopify flags high-risk orders. The flag is a prompt to look, not an instruction — and ignoring flags is how stores accumulate chargebacks.

  • Review every high-risk flag before fulfilling
  • Watch for mismatched billing and delivery addresses on high-value orders
  • Be cautious with express delivery on first-time high-value orders
  • Phone the customer where the value justifies it — genuine customers do not mind

Chargebacks

You will get some. What determines the outcome is evidence: proof of delivery, the order record, any correspondence, and your published policies.

Keeping delivery confirmation for every order is the single most useful habit for winning them.

Customer data

ObligationWhat to do
Privacy noticeSay what you collect and why
Data requestsKnow how to export a customer's data
Deletion requestsKnow how to honour them
App data sharingKnow which apps receive customer data
RetentionDecide how long, and apply it

Frequently asked questions

Do we need PCI compliance?

Shopify handles card data, which removes most of the burden. You still have obligations around how you handle other customer data.

Should we cancel every high-risk order?

No — review them. Some are legitimate customers travelling or using a work address. Review, then decide.

What about app permissions?

Review what each app can access. Several request broad permissions they do not need, and each is an additional exposure.

How do we win chargebacks?

Evidence. Delivery confirmation, the order record, correspondence and your published policies, submitted promptly.

Keep reading

Staff accounts without two-factor?

That is the most common way a store gets compromised. Ten minutes to fix for everyone.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

Shopify DevelopmenteCommerce Development