PrivacyForgeSign In
Back to Blog

Shopify POS Marketing Consent: One Customer, Two Records

Shopify POS and your online store capture marketing consent separately. Audit what happens when the two customer profiles merge — the result is irreversible.

PFMariyan ValevAug 23, 2026 · 14 min read
GuideGuide

Key Takeaways

  • Shopify captures marketing consent through two different flows: an online checkout checkbox, and an in-store prompt attached to receipt selection that Shopify's documentation describes as appearing when a customer "checks out for the first time with you".
  • When you merge two customer profiles, Shopify's documented rule is explicit: "If the customer is subscribed to email and SMS text marketing in one profile, but not in the other, then the merged profile is subscribed." The merge cannot be undone.
  • "Not subscribed" is not the same as "refused" — Shopify documents it as "the customer hasn't subscribed", which covers both the shopper who declined and the one nobody asked. That is exactly the distinction Article 7(1) asks you to evidence.
  • A customer with two unlinked profiles has two sets of personal data. An Article 15 response that finds only one of them is an incomplete response, not a fast one.
  • Merchants have been asking Shopify for POS marketing-consent tooling since at least January 2021, and one 2022 thread on in-store opt-in was still unanswered in December 2025. The silence is the compliance risk.

Introduction

Your best customer bought a jacket in the shop on Saturday and a pair of boots online on Tuesday. Somewhere in your Shopify admin there is a decent chance that is now two people — two profiles, two email records, and two independent answers to the question "may we market to this person?"

That would be a tidy data-hygiene problem if the two answers always agreed. They do not. In-store and online consent are collected at different moments, in different words. And when you notice the duplicate and merge it, Shopify resolves the disagreement for you, in one direction, permanently. This article covers what the platform does, which GDPR provisions it puts in play, and how to reconcile the two records before a subject access request does it for you.

This is informational content, not legal advice.

In-store and online consent are separate records because they are separate collection events. Each has its own wording, its own moment, and its own affirmative act — and Recital 32 requires consent to be a clear affirmative act for the purposes it covers. Two events mean two things to evidence, not one.

Consent under the GDPR is not a status you hold about a person; it is a thing that happened, which you must be able to reconstruct. Article 7(1) puts it plainly: "Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data." Two collection points produce two demonstrations — or, if you have not planned for it, one demonstration and one gap.

What the in-store opt-in actually asks

Shopify POS collects marketing consent through the customer receipt selection flow, which is "turned on by default." Shopify's documentation states: "When a customer checks out for the first time with you, they're prompted to select whether they want to receive marketing communications from you before they accept their receipt."

The customer sees one of three phrasings: "Sign up to receive exclusive offers via email", "Sign up to receive exclusive offers via SMS", or "Sign up to receive exclusive offers via email and SMS". Note what they do not say. They name a benefit — exclusive offers — and a channel, but no controller, no purpose beyond offers, no retention period, and no link to your privacy notice.

There is a second wrinkle worth knowing before you audit anything. For those opt-ins to display at all, Shopify requires you to "activate SMS and email marketing in your Shopify admin Checkout settings in the Marketing options section" — the in-store prompt is gated behind an online checkout setting. If someone toggled that off during a checkout redesign, the shop floor stopped asking, and nothing announced it.

What the online opt-in asks instead

Online, Shopify documents three subscription routes: "adding their email address and checking a checkbox in the checkout", "opting in when signing into their customer account", and "adding their contact information to a newsletter sign-up on your online store". Double opt-in adds a confirmation step, requiring the customer "to click a link in an email to confirm" — which parks them at Pending, one of the six subscription states Shopify's segment reference documents alongside Subscribed, Not subscribed, Unsubscribed, Invalid and Redacted.

So the same shopper can hold a Pending status online, having never clicked the confirmation link, and a Subscribed status in store, having tapped a button next to the words "exclusive offers". Those are not the same consent, and they are not equally evidenced. Our position: treat the double-opted-in record as your strongest evidence and the receipt-flow tap as your weakest, and never let a merge quietly promote the weaker one. You will market to fewer people — but a list you can defend is worth more than one you cannot.

Shopify's merge rule is documented and one-directional: "If the customer is subscribed to email and SMS text marketing in one profile, but not in the other, then the merged profile is subscribed." If either record says yes, the survivor says yes — and "After the profiles are merged, you can't reverse the process."

Read that against the field it operates on. Credit where it is due: Shopify tracks withdrawal separately, as Unsubscribed — "not currently subscribed to email marketing but was previously subscribed". What Not subscribed cannot tell you is whether the customer was ever asked: Shopify defines it as "the customer hasn't subscribed", which covers the shopper who saw the receipt prompt and declined and the shopper nobody asked because the prompt never appeared.

That is the crux. The merge rule is not a GDPR breach by Shopify; it is a platform default, and under Article 5(2) the controller — you — is "responsible for, and be able to demonstrate compliance with" the principles. Merge a Subscribed profile with a Not subscribed one and you may have just started marketing to someone who declined at the till, with nothing in the surviving record to show they did. And because the merge rule is written only as "subscribed… but not in the other", the documentation does not say how a profile in the distinct Unsubscribed state is treated. That matters: Article 7(3) requires withdrawal to be as easy as giving consent, so a merge that reinstated a withdrawn consent would run the other way. Check that pairing manually rather than assuming it is safe.

There is also an accuracy dimension. Article 5(1)(d) requires personal data to be "accurate and, where necessary, kept up to date", with "every reasonable step" taken to rectify inaccurate data "without delay". A consent flag that says yes when the person said no is inaccurate personal data, and the irreversibility of the merge means the reasonable step has to happen before you click.

One piece of good news, and a genuinely thoughtful design choice: Shopify will not merge profiles where either has been deleted or redacted, where a redaction request is under way, or where, in its words, "A customer data request is in progress." An in-flight erasure or access request blocks the merge — which protects the rights request, but not the consent state on any ordinary Tuesday.

Can You Default POS Customers to Subscribed?

No. Recital 32 of the GDPR states: "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." A default that enrols in-store customers into marketing unless they object is inactivity rather than a clear affirmative act, and it fails on the plain wording of the recital — whatever the equivalent online setting allows.

This is not a hypothetical concern about a feature nobody wants. On 22 August 2024, a merchant asked Shopify exactly this, in these words: "Why is there no way to default this to yes like we can for the ecommerce store?" A Shopify staff member replied two days later that the request would be forwarded to the Retail Development Team. In the entire thread, nobody mentions the GDPR, consent, or compliance at all.

The request is understandable — the merchant describes staff having to find an inconspicuous toggle, so enrolment comes out inconsistent. But the fix for inconsistent asking is to make the asking consistent, not to stop asking. If your in-store opt-in rate looks poor next to your online one, it is worth checking which of the two is actually collecting a clear affirmative act.

Shopify is unambiguous about where this responsibility sits: "You're responsible for ensuring that your email opt-in collection methods comply with regional laws and regulations." The platform gives you the tools and the defaults. The lawful basis is yours.

It can. Article 15(1) gives the data subject the right to confirmation of whether their data is processed and access to that data, plus the purposes, the categories of personal data, the recipients, and the storage period. A search that finds one of a customer's two profiles answers for half the data you hold.

Nothing in Article 15 lets you scope the answer to the records your search happened to surface. If a customer shops in store under a second email address — the one they gave for a receipt — the profile created at that till is as much "personal data concerning him or her" as the account they log into online.

This is where the duplicate-profile problem stops being marketing hygiene and becomes a rights-request issue, and it deserves the same discipline as the rest of your DSAR workflow — see our guide to automating data subject access requests for the intake and search patterns that make a complete response repeatable.

The same split shows up in your Article 30 record, which must document the purposes of processing, the categories of data subjects and personal data, and the categories of recipients. If in-store and online marketing feed different lists through different tools, that is more than one flow to describe. And the small-business exemption is narrower than merchants assume: Article 30(5) disapplies the obligation below 250 employees unless the processing risks rights and freedoms, involves special categories of data, or — the one that catches almost every shop — is "not occasional". Marketing that runs to a customer list on a schedule is hard to describe as occasional, so most shops should assume the record is required. Our guide to records of processing activities walks through the structure.

  1. Check the gate first. In Shopify admin, confirm SMS and email marketing are active in Checkout → Marketing options. If they are off, your POS has not been showing the opt-in, and your in-store consent rate for that period measures nothing.
  2. Find the duplicates before you merge them. Search on email, phone and name separately. Duplicates created at a till usually differ in exactly one field, which is why a single-field search misses them.
  3. Record the pre-merge state. For every pair, note both consent statuses and dates before merging. Once merged, "you can't reverse the process" — and the losing record's status is the evidence you will wish you had.
  4. Resolve conflicts by recency and quality, not by default. Where one profile says subscribed and the other does not, decide deliberately: the most recent clear affirmative act wins, and a documented double opt-in beats an undocumented tap. Then merge.
  5. Log the resolution as its own consent event. Who, when, which wording, which channel, and what you decided. A defensible consent record survives the merge; a status flag does not — what a defensible proof-of-consent record must contain sets out the field set.
  6. Fix the collection point. Give shop staff one script and one moment to ask, so the in-store record is created the same way every time.

Common Mistakes to Avoid

The worst mistake is treating the merge as data cleanup. It is a consent decision wearing a tidy-up costume, it is irreversible, and it is usually made by whoever noticed the duplicate — often whoever is least equipped to judge it. Route it like a consent change.

Second: reading Not subscribed as a refusal. Shopify defines it as "the customer hasn't subscribed", so it holds both the shopper who declined and the one nobody asked. A suppression policy built on that field alone cannot tell a respected "no" from an unrecorded silence.

Third: assuming an in-store opt-in covers online marketing, or the reverse. The wording differs, the moment differs, and Recital 32 requires consent for the purposes it covers. "Exclusive offers" is thin cover for a different programme.

Fourth: measuring in-store opt-in rate without checking the prompt was displayed. A conversion rate for a question nobody asked is not a low number; it is no number.

How PrivacyForge Helps

The gap here is not really about Shopify. Consent evidence lives wherever it was collected, and nothing in a storefront's admin is designed to reconcile two collection points into one defensible answer.

PrivacyForge keeps the consent record separate from the marketing flag: each event stored with its timestamp, the exact wording shown, the channel it came through, and any later withdrawal — so a merge changes which list someone is on without erasing what they were actually asked. Its data-mapping module gives the in-store and online flows their own entries in your Article 30 record, and its DSAR workflow searches across identifiers rather than the single address a request arrived from. Compliance scoring flags collection points where consent is captured but not evidenced.

None of that removes the need to decide what a conflicting pair of records means. It does mean the decision is made once, on the evidence, and is still there a year later.

Frequently Asked Questions

Can customers opt in to email marketing at Shopify POS?

Yes. Shopify POS presents the marketing opt-in through the customer receipt selection flow, with the wording "Sign up to receive exclusive offers via email" or the SMS equivalent. Shopify's documentation says the prompt appears when a customer "checks out for the first time with you". The opt-ins only display if SMS and email marketing are activated in your admin Checkout settings under Marketing options.

The merged profile ends up subscribed. Shopify's documentation states: "If the customer is subscribed to email and SMS text marketing in one profile, but not in the other, then the merged profile is subscribed." The merge is permanent — "After the profiles are merged, you can't reverse the process." Record both consent states and dates before merging, because the losing record's status is not recoverable afterwards.

Can I default POS customers to subscribed like my online checkout?

No. Recital 32 of the GDPR states that "silence, pre-ticked boxes or inactivity should not therefore constitute consent", so enrolling in-store customers unless they object is not valid consent. A merchant asked Shopify for exactly this feature in August 2024. The fix for inconsistent in-store enrolment is a consistent asking process, not a default that removes the question.

Does an in-store opt-in cover my online marketing too?

Not automatically. Recital 32 requires consent to be given for the purposes the processing covers, and the in-store prompt names a specific benefit — "exclusive offers" — through a named channel. If your online programme is a different purpose, a different frequency, or a different channel, the in-store tap is weak evidence for it. Match the consent you rely on to the wording the customer actually saw.

Is my DSAR response complete if the customer has two Shopify profiles?

No. Article 15(1) covers all personal data concerning the data subject, not the records your first search returned. A customer who gave a different email at the till has a second profile holding real personal data. Search on email, phone and name before responding, and note that Shopify blocks profile merges while a customer data request is in progress.

Conclusion

Two collection points, two consent records, one irreversible merge rule that resolves in favour of marketing. None of that is hidden — it is in Shopify's own documentation, in plain sentences — but it sits across several help pages, and no one page tells you that the merge rule quietly decides what the other two meant.

The practical fix is small and worth doing this week: check the in-store prompt is switched on, find your duplicates, and write down both consent states before you merge anything. Everything else follows from having the evidence rather than the flag.

Start by writing down what each of your collection points actually asks, then turn it into a proof-of-consent record you can point at rather than a status you hope is right.

Sources