GDPRChecker

Home / Help Center / Install the GDPRChecker Shopify app

Getting Started

Install the GDPRChecker Shopify app

Connect a verified Shopify store, authorize the app, and enable its Theme App Embed without editing Liquid theme files.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

September 2026

Reading time

3 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

When to use this

Use the official Shopify app for a Shopify storefront that has already been added to GDPRChecker and verified. The app installs the runtime through a Shopify Theme App Embed, so you do not need to paste code into theme.liquid.

You need permission to install apps on the Shopify store and access to the GDPRChecker account that owns the verified site. Use the store's permanent address ending in .myshopify.com, even when customers visit a custom domain.

The integration loads GDPRChecker in the storefront head and synchronizes visitor choices with Shopify's Customer Privacy API. Shopify checkout, Customer Events, custom pixels, and third-party apps should still be reviewed separately.

Step-by-step instructions

  1. Open the verified Shopify site in GDPRChecker

    Sign in to the GDPRChecker account that owns the website, select the verified Shopify site, and open Setup > Install Script. The Shopify app is reusable across customers: each store installs the same GDPRChecker app, but receives its own Site ID and Ping Token.

  2. Select Shopify under Platform guides

    Choose Shopify, then enter the permanent store domain ending in .myshopify.com. Use the permanent Shopify domain shown in Shopify Admin > Settings > Domains, even if shoppers visit a custom domain. Select Connect Shopify to start the secure Shopify install flow.

    GDPRChecker install protection page with Shopify selected and the Shopify connection card visible
    Select Shopify, enter the permanent .myshopify.com domain, then connect or re-check the installation. Site-specific credentials are not shown in public screenshots.
  3. Authorize the Shopify app

    If Shopify asks you to sign in, use an account that can install apps for that store. Review the requested permissions and select Install or Approve. GDPRChecker stores the Shopify offline token securely and writes only this site's Site ID, Ping Token, API base, and runtime mode into the app installation metafields.

  4. Recover safely after an uninstall and reinstall

    Uninstalling the app removes its Shopify authorization and can turn off its Theme App Embed. To recover, install the same GDPRChecker app again from the current site's Setup > Install protection > Shopify card, then complete the Shopify authorization flow. Return to GDPRChecker and confirm the connection card says Installed before selecting Check now. GDPRChecker ignores a delayed uninstall notification from the previous installation, so an old retry cannot overwrite the newly authorized connection. Re-enable and save the App Embed on the currently published theme if the status says disabled, not found, or unknown.

    GDPRChecker Shopify connection card used to reconnect a store after reinstalling the app
    Start a fresh connection from the verified site's Shopify card. Do not reuse an old authorization or installation URL after an uninstall.
  5. Open the published theme editor

    After authorization, open Shopify Admin > Online Store > Themes and customize the currently published theme. Do not enable the app only on an unpublished draft theme; customers are protected only on the theme that is live.

  6. Enable GDPRChecker in App embeds

    In the theme editor, open App embeds from the left sidebar, find Consent protection by GDPRChecker, and turn it on. This injects the GDPRChecker runtime through Shopify's Theme App Embed system without editing theme.liquid.

    Shopify theme editor App embeds panel with GDPRChecker Consent protection enabled
    Turn on Consent protection by GDPRChecker in App embeds. The preview should show the consent banner after the runtime loads.
  7. Save the theme

    Select Save in the theme editor and wait until the Save button is disabled again. Leaving the editor before saving means the App Embed may still be off on the published storefront.

  8. Confirm the banner appears on the storefront

    Open the storefront or theme preview and confirm the GDPRChecker banner appears with Reject non-essential, Manage preferences, and Accept all. This proves the storefront runtime is visible; it does not yet prove checkout, pixels, or third-party app behavior.

    Shopify storefront preview showing the GDPRChecker consent banner
    The storefront preview should show the GDPRChecker banner after the App Embed is enabled and saved.
  9. Re-check the Shopify connection in GDPRChecker

    Return to GDPRChecker and select Check now in the Shopify connection card. Confirm Sync status is Synced, Theme App Embed is Enabled, and the last successful check has a recent time. If it reports Action required, reopen the published theme, enable the embed, save, and check again.

  10. Test common storefront pages

    Use a fresh browser session with extensions disabled. Test the homepage, a product page, cart, and any campaign landing page. Make sure Reject non-essential keeps optional tracking disabled, Accept all grants the selected categories, and Manage preferences lets the visitor withdraw consent.

  11. Review Shopify-specific surfaces separately

    Theme App Embeds cover the Online Store, not every Shopify surface. Separately test Checkout, the order-status or thank-you page, new Customer Accounts, Customer Events, custom pixels, and third-party app pixels. Shopify-managed pixels and each third-party app must honor Customer Privacy independently.

Expected result

The Shopify installation is linked to the selected GDPRChecker site, the GDPRChecker App Embed is enabled on the published theme, and the dashboard reports the storefront runtime as connected.

The consent interface appears according to your published GDPRChecker configuration, and visitor choices are passed to Shopify Customer Privacy on storefront pages. Continue to audit custom pixels, Customer Events, checkout settings, and third-party app behavior independently.

Troubleshooting

Authentication required

Open the connection from Setup > Install Script while signed in to GDPRChecker. Do not reuse an old /shopify/install link from another browser session, because the connection must be tied to the signed-in account.

Verified site not found

Confirm the selected GDPRChecker site is verified and matches this store. Use the current Connect Shopify button from that site's setup page; an archived or replaced site ID cannot be installed.

The app is installed but no heartbeat appears

In Shopify Admin, open Online Store > Themes > Customize > App embeds, enable GDPRChecker, and select Save. Confirm you edited the published theme, then open the live storefront in a private window and re-check the connection.

The dashboard says Theme App Embed is disabled or not found

Select Open Shopify themes, customize the currently published theme, open App embeds, enable GDPRChecker, and save. Return to GDPRChecker and select Check now. A draft theme does not protect the published storefront.

Sync failed

The status card shows the last safe failure reason. Reconnect the app if it was uninstalled or its access token expired. The shop-level uninstall webhook is checked from the store; Shopify privacy compliance webhooks are app-level settings managed in the Shopify app configuration.

Shopify says the app is installed, but GDPRChecker still says Uninstalled

Refresh the GDPRChecker setup page, then start a fresh Connect Shopify flow from that same verified site. Shopify can retry an earlier uninstall notification after a new authorization; GDPRChecker uses Shopify's original event timestamp so a stale notification is ignored. If the card still does not change to Installed after a fresh authorization, keep the Shopify Admin and GDPRChecker pages open and contact support with the safe status message shown on the connection card. Do not share OAuth URLs, access tokens, Site IDs, or Ping Tokens.

FAQ

Is this a reusable Shopify app or a custom app per customer?
It is a reusable GDPRChecker Shopify app. Each customer installs the same app through Shopify OAuth, and GDPRChecker writes that store's own Site ID and Ping Token to the installation. A new customer does not need a newly published app.
Do I need to edit theme.liquid?
No. The official integration uses a Theme App Embed. Enable it in the theme editor and save the published theme.
Which Shopify domain should I enter?
Enter the permanent domain ending in .myshopify.com, not the custom storefront domain.
Does the app control every Shopify pixel and checkout script?
No. It protects the installed storefront runtime and synchronizes storefront consent. Review Customer Events, custom pixels, checkout controls, and third-party app settings separately.
Do I need a new app for reinstalling or for another customer?
No. Reinstall the same reusable GDPRChecker app from the current verified site's Shopify connection card. Each authorization is bound to that store and its own GDPRChecker site credentials.

GDPRChecker help articles provide product guidance and do not constitute legal advice. Use them for setup and troubleshooting, and consult qualified counsel for legal interpretation.

Need hands-on verification?

Use the compliance scanner or open your dashboard to finish setup and go live.