Do Shopify Stores Need a Privacy Policy? The State by State Answer for 2026.
Short answer: yes, your Shopify store almost certainly needs a privacy policy. Not because Shopify says so — because state law says so. And depending on where your customers are, that law may have real teeth behind it.
Here is what's actually required in 2026, broken down by state in plain English.
Why This Question Has Gotten More Complicated
A few years ago, the honest answer was "best practice, but not legally required for most small sellers." That's changed. Since California's CCPA came into force and a wave of states followed with their own versions, the legal landscape for online seller privacy Obligations have shifted significantly.
The hard part is that none of these laws tell you "you need a privacy policy." They tell you what rights consumers have and what disclosures you must make — which in practice means you need a privacy policy to make those disclosures anywhere accessible.
California — The One That Started Everything
California's CCPA (now updated to CPRA) is the strictest consumer privacy law in the United States and the one most Shopify sellers worry about first. The California Privacy Protection Agency enforces it with a dedicated budget and has issued fines.
You're covered by California law if your business meets ANY ONE of these three criteria:
- You process personal data of 100,000 or more California consumers per year
- You process data of 50,000 or more California consumers, households, or devices
- You earn 50% or more of your annual revenue from selling California consumer personal data
If you meet any one of those, California requires you to disclose what data you collect, why you collect it, who you share it with, and what rights consumers have to access or delete it. A properly written privacy policy is how you make all those disclosures.
For most independent Shopify sellers, the 100,000 consumer threshold is the relevant one. That sounds like a lot — but it's 100,000 individuals whose data you touch, not 100,000 purchases. Website visitors, email subscribers, and customers all count.
Texas, Virginia, Colorado — The States That Followed
Texas's TDPSA came into effect July 1, 2024. Virginia's VCDPA has been active since January 2023. Colorado's CPA since July 2023. All three require similar privacy disclosures to California, with slightly different thresholds.
Texas is notable because it has no revenue threshold — it's broadly applicable to any business that processes Texas consumer data above certain volumes. The Texas Attorney General has been active in enforcement, particularly against businesses with weak or missing privacy disclosures.
Colorado requires something California doesn't — merchants must honour Global Privacy Control (GPC) browser signals. If a consumer's browser sends an automatic opt-out signal, Colorado says you must respect it. Most Shopify stores aren't set up for this yet.
Virginia was the second comprehensive state privacy law after California and became the model that most other states copied. Civil penalties run up to $7,500 per intentional violation.
The States Active in 2025-2026
Several more states joined the active enforcement landscape over the past year:
- Minnesota — MCDPA effective July 31, 2025. Has a unique requirement most states don't: merchants must disclose the specific third parties they've sold or shared data with, if a consumer asks.
- Tennessee — TIPA effective July 1, 2025. Has a higher $25 million revenue threshold, which means most independent Shopify sellers are technically exempt. Still worth knowing if your store is growing.
- Indiana and Kentucky — both became active on January 1, 2026. Both follow the Virginia model closely.
- Arkansas (ACTOPPA) — Became active July 1, 2026. This law goes further than almost any other state regarding minors. For children under 13 and teens aged 13 through 16, it places an unconditional flat ban on targeted advertising tracking. There is no consent exception, no opt-in loophole, and no parental workaround. If your Shopify store uses Meta or Google tracking pixels and your products attract teen shoppers from Arkansas, you cannot use behavioural tracking for ad campaigns — regardless of consent.
Florida — Why Most Shopify Sellers Don't Need to Worry
Florida passed its Digital Bill of Rights in 2023, but set the threshold at $1 billion in annual revenue. For most independent Shopify sellers, this means Florida's law doesn't apply to your store directly. A general best-practice privacy policy is still a good idea, but Florida isn't the compliance risk it might appear.
States With No Comprehensive Privacy Law Yet
Quite a few states still don't have a comprehensive consumer privacy law on the books. That includes Georgia, Michigan, Missouri, Mississippi, North Carolina, and several others. If your customers are concentrated in these states, state-level privacy law isn't your immediate concern — but that's changing. Alabama signed its privacy law in April 2026, effective May 2027. The trend is clearly in one direction.
What Your Privacy Policy Actually Needs to Include
Across all the active state laws, the core disclosures are similar. A solid Shopify store privacy policy needs to cover:
- What personal data you collect (email, purchase history, device data, browsing behaviour on your store)
- Why you collect it (fulfilling orders, marketing, improving the site)
- Who you share it with (Shopify, payment processors, email marketing tools, analytics)
- How long you keep it
- What rights consumers have — access, deletion, correction, opting out of data sale
- How to contact you with privacy requests
The specific language matters. A generic one-paragraph "we respect your privacy" statement doesn't satisfy these requirements. You need actual disclosures that address each of these points specifically.
The FTC Factor
Even if your store operates entirely in states without comprehensive privacy laws, the Federal Trade Commission has long required that if you post a privacy policy, it must be accurate. Posting a policy that says "we never share your data" and then sharing data with third-party marketing platforms are a deceptive trade practice under FTC rules. This applies to any US online seller, regardless of state.
Everything in this article is informational only and sourced from official state attorney general and government publications. Regulens does not provide legal advice. Consult a licensed attorney for guidance specific to your situation.
The Practical Bottom Line
If you're selling to customers across the US and you don't have a privacy policy, add one. If you have one that was written in 2021 and hasn't been updated, it almost certainly doesn't cover the laws that have come into force since then.
The good news is that Shopify's own policy generator gives you a reasonable starting point. The less good news is that it may not cover state-specific requirements like Colorado's GPC signal obligation or Minnesota's third-party disclosure rule. Worth having a lawyer review it if you're in a high-volume state.
Check Your Store's Privacy Readiness
Regulens scores your Shopify store's privacy law readiness across all covered US jurisdictions as part of its four-pillar readiness score. It looks at which active state laws apply to your profile and flags gaps in your policy documents — all based on verified government sources, not summaries.
Free to try, takes about three minutes, no credit card needed. Informational only — not legal advice.
Further Reading
Kentucky's New Privacy Law Already Has Its First Lawsuit — Here's What Sellers Should Know
Kentucky's consumer privacy law took effect January 1, 2026. Eight days later, the state's Attorney General filed its first enforcement action, and skipped the standard cure period to do it. Here's what the KCDPA actually requires.
Indiana's Privacy Law Looks Like Virginia's — But Don't Assume It's Identical
Indiana's consumer privacy law took effect January 1, 2026, modeled closely on Virginia's framework. But the details that differ, especially around sensitive data and cure periods, are worth knowing if you sell into the state.