# FindIP Shield for Shopify

> **App Store status (August 23, 2026):** Submitted to Shopify App Review and
> pending approval. The listing is configured for full visibility after
> publication.

FindIP Shield for Shopify adds visitor risk detection to your storefront: VPN,
proxy, Tor, hosting/datacenter, and malicious-traffic signals for every
consented storefront visit without sending names, emails, customer IDs,
order details, cart contents, or payment data.

The app installs a Shopify Web Pixel that runs in Shopify's strict pixel
sandbox. Events go directly from the shopper's browser to the FindIP Shield
ingest service; they never pass through the app's backend.

## Requirements

- A Shopify store (any plan that supports apps)
- A free FindIP account — [findip.net](https://findip.net)
- A Shield site for your storefront domain

## Installation

1. Install **FindIP Shield** from the Shopify App Store.
2. Open the app in your Shopify admin. It will ask for a public site key.
3. Create a Shield site at [findip.net](https://findip.net) → **Shield → Sites
   → New site**.
   - **Domain**: enter the hostname your shoppers actually visit.
     - Custom domain: `www.yourstore.com`
     - No custom domain: `yourstore.myshopify.com`
   - The domain must match — events from unregistered domains are rejected.
4. Copy the site's **public key** (starts with `pub_`).
5. Paste it into the app and select **Connect Shield**.
6. The status card shows **Connected** when the key is accepted.

### Verify your first event

Visit your storefront and view any product, then open your Shield site's
event feed at findip.net. A `page_viewed` or `product_viewed` event should
appear within seconds. If your store uses a consent banner, accept analytics
consent first — the pixel only runs when Shopify permits analytics processing.

## What the pixel sends

Standard Shopify analytics events (page view, product view, cart, checkout
progress), reduced to metadata:

- Event name and timestamp
- Page origin and path — query strings and fragments are removed
- Page title and referrer
- Browser user agent, language, cookie availability, viewport size
- A random identifier scoped to the current browser session

## What the pixel never sends

- Names, email addresses, phone numbers, postal addresses
- Shopify customer, order, checkout, product, or variant identifiers
- Cart contents, product titles, SKUs, search queries
- Payment or card information
- Form contents, keystrokes, or page DOM content

Full privacy details: [findip.net/privacy](https://findip.net/privacy) and the
app's [privacy information](https://github.com/findip-net/findip-shield-shopify/blob/main/PRIVACY.md).

## Consent behavior

The Web Pixel declares analytics processing to Shopify. Shopify's Customer
Privacy system decides when it runs:

- Analytics consent granted (or not required in the visitor's region): events
  are sent.
- Analytics consent denied or not yet given where required: the pixel does not
  emit events. If the visitor grants consent later, events start from that
  moment.

No configuration is needed in the app — this is enforced by Shopify's pixel
sandbox.

## Changing or disconnecting the key

Open the app and paste a different `pub_` key to switch Shield sites; the
change takes effect immediately. Uninstalling the app removes the Web Pixel
and the app's access to your store, and deletes the store's authentication
session from FindIP's systems.

## Troubleshooting

| Symptom | Check |
| --- | --- |
| No events appear | Domain registered for the site key matches the storefront hostname exactly |
| No events appear | Analytics consent was granted (or your region doesn't require it) |
| No events on custom domain | Register the custom domain, not the `.myshopify.com` address |
| Key rejected on connect | Use the **public** key (`pub_…`), not the secret key |
| Events stopped after theme/domain change | Update the Shield site's domain to the new hostname |

Still stuck? See [support](https://findip.net/support/shopify) — we aim to
respond within two business days.

## Terms

Shield's risk output consists of informational signals only; decisions you
take based on them are yours. Free Shield sites are governed by the
[Shield Free Preview Terms](https://www.findip.net/docs/shield/terms-free-preview.md) in addition to the
[FindIP Terms of Service](https://findip.net/terms).

---

Canonical page: https://www.findip.net/docs/shield/shopify · Markdown: https://www.findip.net/docs/shield/shopify.md · All Shield docs in one file: https://www.findip.net/llms-full.txt
