Is Shopify safe?
Review Shopify security risks.

Nudge Security provides security profiles for thousands of SaaS apps, including Shopify. This public profile has the basics you’ll need for a vendor risk assessment. For more details on Shopify, including breach history, start a free trial of Nudge Security.
Shopify Security Profile

CATEGORY

IT & Infrastructure

Organization Details

What is

Shopify

?

Shopify is a platform that helps businesses manage their ecommerce needs. It includes tools to manage every part of a business, from shipping to marketing.

HEADQUARTERS

HOSTING

HOSTING LOCATION

Who's Using Shopify in your org?

Nudge Security discovers every user for every SaaS app within minutes of starting a free trial. No credit card required.

Learn how

Security Program

SECURITY CERTIFICATIONS

SOC2 Compliance
PCI Compliant
HIPAA Compliant
SOC2 Compliance
SOC 2 Compliant
GDPR Compliant
ISO 27001 Compliant
FedRamp Compliant
CSA Star Level 1
Compliant

SECURITY PAGE

SECURITY PORTAL

BUG BOUNTY

VULNERABILITY DISCLOSURE

STATUS PAGE

Shopify breach history
Has Shopify experienced a recent breach? Start a free trial of Nudge Security for a full breach history and more security program details.
Learn more

Authentication

AUTHENTICATION / SSO

Supported Okta Features
  • SAML
  • Create
  • Deactivate
Login with Google support
Login with Microsoft support
Supports SSO
Two-factor authentication via SMS
Two-factor authentication via E-mail
Two-factor authentication via Hardware
Two-factor authentication via Software
Two-factor authentication via TOTP
Two-factor authentication via U2F

oauth details

  • 119434437228-oub0dlcoh7hi08817cqqchrma4ft5hpa.apps.googleusercontent.com - Shopify
  • E-mail: accounts-support@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/oVOzphKJdehEXxB1QZ8eaIozgjIn_8IepDFp8CsdmyKXBhFw3m62mfV_dQncguIhCd8
  • Privacy Policy: https://www.shopify.com/legal/terms
  • 407182546550-jursbltk3ek1batrdhns9pojkpnv63ke.apps.googleusercontent.com - Google Channel by Shopify
  • E-mail: merchant-marketing@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/DXVHGI1HipXFR30MfrFxXilMpDoGgAzkof0lZf0rOFQJ_Gj4vrdvrlxf7WfRRjrYqg
  • Privacy Policy:
  • 318569518246-8u1fprajrt7tv7b05f3moq6s16sdehov.apps.googleusercontent.com - Shop
  • E-mail: shopapp@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/0woK12lSJlLd7tOvI_W82thCA_AG13ypNXIj08SUj4UXkm6EcPNAIKSYP9gUr6KCo4Sk
  • Privacy Policy: https://shop.app/terms-of-service
  • 318569518246-rgivb6e8o5no0d13b0p3p4qb1472e7f0.apps.googleusercontent.com - Shop
  • E-mail: shopapp@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/0woK12lSJlLd7tOvI_W82thCA_AG13ypNXIj08SUj4UXkm6EcPNAIKSYP9gUr6KCo4Sk
  • Privacy Policy: https://shop.app/terms-of-service
  • 318569518246-ormhnnho72o5k9re1sfk65hiiqic92g4.apps.googleusercontent.com - Shop
  • E-mail: shopapp@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/0woK12lSJlLd7tOvI_W82thCA_AG13ypNXIj08SUj4UXkm6EcPNAIKSYP9gUr6KCo4Sk
  • Privacy Policy: https://shop.app/terms-of-service
  • 204695640520-rt73hecoqk1vqqtnfrtmjvf269nq8h4f.apps.googleusercontent.com - Shopify Flow
  • E-mail: google-sheets-for-shopify-flow@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/wgf20WNXZ50fCpNS24Y_KNsX8EQo2__HVGxfY6rf8owJ4naQ0g8lOfBbuPGkU3kh7eh8
  • Privacy Policy: https://flow-connectors.shopifycloud.com/terms
  • 455596398176-tk74teldpp406aeor7k3ti0d05k919jl.apps.googleusercontent.com - Shopify Audiences
  • E-mail: shopify-audiences-dev@shopify.com
  • Terms of Service: https://lh3.googleusercontent.com/ESB1ezzJA2KSBp82rbV_IVvgYo2_Z0kKAm7gzqlpNB7X7ODtLctSEJm9LRrpz4kDFJuu
  • Privacy Policy:
Shopify OAuth Grants
Is Shopify connected to your other business apps? Start a free trial of Nudge Security to see all app-to-app OAuth grants.
Learn more

Supply Chain

Apps in Shopify's supply chain
  • Skilljar
  • q4inc.com
  • Khoros
  • Google Workspace
  • HubSpot
  • Fastly
  • Vercel
  • Bevy
  • Salesloft
  • Google Tag Manager
  • Google Analytics
  • Marketo
  • Shopify
  • Bugsnag
  • Microsoft Intune
  • Salesforce.com
  • Prezly.com
  • Mailgun
  • SendGrid
  • Zendesk
  • GitHub
  • Northpass
  • Amazon Web Services (AWS)
  • Zapier
  • TeamViewer
  • Stripe
  • Klaviyo
  • Facebook
  • Drift
  • DocuSign
  • Atlassian
  • Apple Business Manager
  • Adobe
  • GlobalSign
  • Datadog
Shopify supply chain breach history
What's in Shopify's SaaS supply chain? Start a free trial of Nudge Security to manage software supply chain security at scale.
Learn more

Subdomains

Shopify subdomains
  • assets-cdn.shopify.com
  • securemail.shopify.com
  • www.gringgorgeous-thrift-shop.shopify.com
  • ir.shopify.com
  • forms.shopify.com
  • education.shopify.com
  • ww.shopify.com
  • resources.shopify.com
  • okta.shopify.com
  • pages.shopify.com
  • news.shopify.com
  • t.shopify.com
  • lp.shopify.com
  • dev.shopify.com
  • feeds.shopify.com
  • sl3.shopify.com
  • qa.shopify.com
  • labs.shopify.com
  • seasonalgifts-8578.shopify.com
  • cloud.shopify.com
  • image.shopify.com
  • updates.shopify.com
  • swag.shopify.com
  • my.shopify.com
  • opensource.shopify.com
  • inbox.shopify.com
  • fr.shopify.com
  • image.email.shopify.com
  • tracking.shopify.com
  • blogs.shopify.com
  • press.shopify.com
  • start.shopify.com
  • maintenance.shopify.com
  • payments.shopify.com
  • learning.shopify.com
  • marketing.shopify.com
  • summitweek2023.shopify.com
  • links.shopify.com
  • incoming.shopify.com
  • contact.shopify.com
  • salesforce.shopify.com
  • ok.shopify.com
  • ny.shopify.com
  • developer.shopify.com
  • www.badeaux.shopify.com
  • sales.shopify.com
  • files.shopify.com
  • unionstation.shopify.com
  • id.shopify.com
  • login-dev.shopify.com
  • signatures.shopify.com
  • signup.shopify.com
  • library.shopify.com
  • eu.shopify.com
  • vpn.shopify.com
  • market.shopify.com
  • portal.shopify.com
  • connect.shopify.com
  • buy.shopify.com
  • affiliates.shopify.com
  • em.shopify.com
  • mi.shopify.com
  • click.shopify.com
  • store.shopify.com
  • static3.shopify.com
  • beyondthebuild.shopify.com
  • webflow.shopify.com
  • security.shopify.com
  • content.shopify.com
  • docs-staging.shopify.com
  • api-dev.shopify.com
  • pl.shopify.com
  • myduffer.shopify.com
  • checkout.shopify.com
  • meetups.shopify.com
  • enterpriseenrollment.shopify.com
  • img.shopify.com
  • insights.shopify.com
  • promo.shopify.com
  • commerceawards.shopify.com
  • sl.shopify.com
  • engage.shopify.com
  • prod.shopify.com
  • web.shopify.com
  • expert.shopify.com
  • uk.shopify.com
  • slack.shopify.com
  • update.shopify.com
  • salesloft.shopify.com
  • contest.shopify.com
  • plus.shopify.com
  • test.shopify.com
  • forum.shopify.com
  • br.shopify.com
  • email.careers.shopify.com
  • offers.shopify.com
  • internal.shopify.com
  • stg.shopify.com
  • trust.shopify.com
  • smetrics.shopify.com
  • plusacademy.shopify.com

Regain control of SaaS security.

Nudge Security discovers all SaaS accounts ever created by anyone in your org within minutes of starting a free trial. Get a full SaaS inventory today, along with insights and automation to improve your SaaS security posture.