Policies, Taxes & GDPR/Privacy Basics for Stores
Under Settings > Policies, Shopify offers templates for Refund Policy, Privacy Policy, Terms of Service, and Shipping Policy that you can generate and edit to match your business.
Store policy pages
Under Settings > Policies, Shopify offers templates for Refund Policy, Privacy Policy, Terms of Service, and Shipping Policy that you can generate and edit to match your business.
These policies should be linked in your footer and are often required by payment providers before they approve your account for processing payments.
Real-life example: Store policies are the printed rules pinned near a shop counter — 'no returns after 7 days', 'we don't share your phone number' — set expectations clearly before a dispute happens.
- Refund Policy — return window, conditions, process
- Privacy Policy — what customer data you collect and how it's used
- Terms of Service — rules governing use of your store
- Shipping Policy — delivery times, costs, delays
Tax basics in Shopify
Shopify can calculate taxes automatically based on your store's location and your customer's shipping address, using rates you configure or region-specific defaults.
Tax rules vary a lot by country and region (VAT, GST, sales tax) — Shopify provides the calculation engine, but you (or an accountant) are responsible for correct rates and registration.
Real-life example: Shopify's tax engine is a calculator that adds the right tax once you tell it the rules — it does the arithmetic, but you still need to know which local tax laws apply to your business.
- Tax settings live under Settings > Taxes and duties
- Rates can be set by country, state/province, or override for specific products
- Shopify does not file taxes for you — it only calculates them at checkout
GDPR and customer privacy basics
GDPR (General Data Protection Regulation) is a European Union law about how customer personal data is collected, stored, and deleted — it applies if you have EU customers, regardless of where your business is based.
Shopify provides tools like data request/erasure webhooks and cookie consent banners to help merchants stay compliant, but the responsibility to configure and honor these stays with the store owner.
Real-life example: GDPR compliance is like a library policy that says a member can ask what records the library has on them, and ask for those records to be deleted — Shopify gives you the forms, but you must actually process the requests.
1. Publish a clear Privacy Policy
2. Enable a cookie consent banner (built-in or app) for EU visitors
3. Respond to any customer data request or deletion request promptly
4. Only collect customer data you actually need for the order/marketing