FindIP Shield for Shopify
Visitor risk detection for your storefront: VPN, proxy, Tor, hosting, and malicious-traffic signals for every consented visit — with no personal data collected. The app installs a Shopify Web Pixel that runs in Shopify's strict sandbox; events go directly from the shopper's browser to the FindIP Shield ingest service.
Requirements
- A Shopify store (any plan that supports apps)
- A free FindIP account
- A Shield site for your storefront domain
Installation
- Install FindIP Shield from the Shopify App Store.
- Open the app in your Shopify admin. It will ask for a public site key.
- Create a Shield site at findip.net → Shield → Sites → New site.
- Domain: enter the hostname your shoppers actually visit — your custom domain (
www.yourstore.com) if you have one, otherwiseyourstore.myshopify.com. - The domain must match — events from unregistered domains are rejected.
- Domain: enter the hostname your shoppers actually visit — your custom domain (
- Copy the site's public key (starts with
pub_). - Paste it into the app and select Connect Shield.
- The status card shows Connected when the key is accepted.
Verify your first event
Visit your storefront and view any product, then open your Shield site's event feed at findip.net. A page_viewed or product_viewed event should appear within seconds. If your store uses a consent banner, accept analytics consent first — the pixel only runs when Shopify permits analytics processing.
Data collection
What the pixel sends — standard Shopify analytics events (page view, product view, cart, checkout progress), reduced to metadata:
- Event name and timestamp
- Page origin and path — query strings and fragments are removed
- Page title and referrer
- Browser user agent, language, cookie availability, viewport size
- A random identifier scoped to the current browser session
What the pixel never sends:
- Names, email addresses, phone numbers, postal addresses
- Shopify customer, order, checkout, product, or variant identifiers
- Cart contents, product titles, SKUs, search queries
- Payment or card information
- Form contents, keystrokes, or page DOM content
Full details: privacy policy.
Consent behavior
The Web Pixel declares analytics processing to Shopify. Shopify's Customer Privacy system decides when it runs:
- Analytics consent granted (or not required in the visitor's region): events are sent.
- Consent denied or not yet given where required: the pixel does not emit events. If the visitor grants consent later, events start from that moment.
No configuration is needed in the app — this is enforced by Shopify's pixel sandbox.
Changing or disconnecting the key
Open the app and paste a different pub_ key to switch Shield sites; the change takes effect immediately. Uninstalling the app removes the Web Pixel and the app's access to your store, and deletes the store's authentication session from FindIP's systems.
Troubleshooting
| Symptom | Check |
|---|---|
| No events appear | Domain registered for the site key matches the storefront hostname exactly |
| No events appear | Analytics consent was granted (or your region doesn't require it) |
| No events on custom domain | Register the custom domain, not the .myshopify.com address |
| Key rejected on connect | Use the public key (pub_…), not the secret key |
| Events stopped after theme/domain change | Update the Shield site's domain to the new hostname |
Still stuck? See support — we aim to respond within two business days.
Terms
Shield's risk output consists of informational signals only; decisions you take based on them are yours. Free Shield sites are governed by the Shield Free Preview Terms in addition to the FindIP Terms of Service.