Does 'Built for Shopify' Mean an App Passed Security Review?
Built for Shopify is a performance badge, not a security clearance, so the vendor review is a BUILD you run yourself. The requirements page caps LCP at 2.5 seconds, CLS at 0.1 and INP at 200 milliseconds. Admin API requests need a p95 of 500ms or less at a 0.1% failure rate, and the app needs a minimum of 50 net installs. No security or data-handling requirements section exists on that page.
Your profile — see how the verdict shifts
- Confidence
- High — Shopify's Built for Shopify requirements page was read in full on 2026-09-05, and every quantified threshold on it is a performance, latency or adoption number. Largest Contentful Paint must be 2.5 seconds or less across a minimum of 100 calls over the last 28 days. Cumulative Layout Shift must be 0.1 or less and Interaction to Next Paint 200 milliseconds or less. The app must not reduce the storefront Lighthouse performance score by more than ten points. Admin requests must have a p95 value of 500ms or less with a 0.1% failure rate, across a minimum of 1,000 requests over the last 28 days. The app needs a minimum of 50 net installs from active shops on paid plans. The absence is the finding: no dedicated security, data-handling or compliance requirements section exists anywhere on that page. The only brush with the subject is a Prerequisites line requiring compliance with the Partner Program agreement, which is a contractual obligation rather than a tested control. There is also no separate Plus-certified tier. The single Plus-specific requirement on the page is that features exclusive to Shopify Plus must be hidden for non-Plus merchants, which is a merchandising rule. This is a definitional question rather than a feature gap, so no category browse applies: nothing on the App Store audits the security posture of another app, and a vendor list here would be padding.
- Reference scenario
- $20M–$150M GMV · Shopify Plus · a security or procurement function reviewing 3–10 new apps a year · several of them requesting customer, order or checkout-adjacent scopes
- As of
- September 2026
Decision at a Glance
| Your profile | Verdict | Why |
|---|---|---|
| Low-risk app requesting no customer-data scopes | WAIT | The badge plus the install-time permission screen is proportionate here. An app that cannot read personal data cannot leak it, and a full questionnaire for a theme utility spends review capacity you need elsewhere. |
| No formal vendor review process today | BUILD | Start with one page of questions, not a program. Five questions asked before every install beats a policy document nobody follows, and it takes about a day per app once the page exists. |
| Any app reading customer personal data | BUILD | The fork this page exists for. Badge criteria measure speed and adoption, so a fast app with a weak subprocessor chain qualifies exactly as easily as a careful one. Where data goes is a question only your review asks. |
| You hold SOC 2 or ISO 27001, or the app touches checkout | BUILD | Your auditors will ask how vendors get approved, and a platform badge is not evidence of a review. A decision record per app, with a date and the scopes requested, is the artifact that satisfies them. |
What Built for Shopify Badge Scope Actually Drives
| Outcome | Impact | How it works |
|---|---|---|
| Operational efficiency | High | A proportionate review completed at install replaces the after-the-fact scramble to establish which app held which customer records once something has already gone wrong. |
| Data & insight | High | Completed reviews accumulate into a data map naming which app holds which customer fields under which processor terms, which is what privacy requests and incident response both run on. |
| Customer experience | Medium | Screening on the badge keeps storefront pages fast, since a badged app must not reduce the Lighthouse performance score by more than ten points and must meet Core Web Vitals thresholds. |
| Revenue — indirect | Low | A documented vendor-approval process clears the procurement and partner questionnaires that otherwise stall a launch while somebody assembles the evidence by hand. |
Spend ceiling: Size the review to the scopes, not to the vendor's size. An app requesting no customer personal data deserves the badge check and the permission screen, which cost nothing. An app reading customer records deserves a day and five questions, inside a process that costs $6,000–$18,000 to design once (Deploi estimate, illustrative). Anything heavier than that gets abandoned before it earns its keep.
What buying enables (top apps)
- + A real performance screen: LCP at 2.5 seconds or less, CLS at 0.1 or less and INP at 200 milliseconds or less, measured over the last 28 days (verified Sep 2026)
- + An admin-latency bar of a p95 at 500ms or less with a 0.1% failure rate across a minimum of 1,000 requests (verified Sep 2026)
- + Evidence of genuine adoption, at a minimum of 50 net installs from active shops on paid plans (verified Sep 2026)
- + An assurance that features exclusive to Shopify Plus are hidden from non-Plus merchants, which keeps a demo honest (verified Sep 2026)
What building additionally unlocks
- + A written answer to where customer data is stored, processed and copied, which no badge criterion tests
- + A subprocessor list and a signed data processing agreement, the artifacts your own auditors ask for by name
- + A per-app data map across the whole portfolio, filling the gap left by the absence of a consolidated permissions view
- + A dated decision record, so an app approved two years ago can be re-examined against today's obligations
Find Your Verdict in 3 Questions
Does the app request access to customer personal data?
Yes: Your verdict: BUILD — run the full vendor review, because badge criteria test speed and adoption rather than data handling.
No: Go to question 2.
Do you carry SOC 2, ISO 27001 or a contractual vendor-management obligation?
Yes: Your verdict: BUILD — auditors ask how vendors get approved, and a platform badge is not evidence that a review happened.
No: Go to question 3.
Does the app touch checkout, payments or fulfillment?
Yes: Your verdict: BUILD — run the 5-question review; a day per app is proportionate to what a checkout-path app can reach.
No: Your verdict: WAIT — the badge plus the install-time permission screen is proportionate here, and re-check the scopes at each update.
The TCC Scorecard — 12 Dimensions
TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →
| Dimension | Buy | Build | Why |
|---|---|---|---|
| Cost | |||
| Acquisition & implementation | Reading a badge and a review count costs nothing and takes a minute; a vendor review process is an estimated 2–4 weeks to design and roughly a day per app to run (Deploi estimate, illustrative). | ||
| Recurring fees | Neither lane carries a subscription, because no App Store product performs a security review of another app; the review lane's recurring cost is staff time at roughly a day per app. | ||
| Maintenance & upgrades | Shopify maintains the badge criteria and can revise them without telling you, while a questionnaire needs an annual refresh against your own contractual and regulatory obligations. | ||
| Switching & exit | Removing an app you never reviewed means guessing what data it holds; a completed review tells you exactly what to ask the vendor to delete and under which terms. | ||
| Risk | |||
| Vendor risk | Badge criteria measure the vendor's speed and adoption rather than its data handling, so a fast app with a weak subprocessor chain earns the badge as easily as a careful one. | ||
| Security & compliance surface | No dedicated security, data-handling or compliance requirements section exists on the Built for Shopify requirements page, so the badge answers none of the questions a review asks (verified Sep 2026). | ||
| Platform-deprecation exposure | Badge criteria belong to Shopify and can change, and an app can lose the badge over a performance regression unrelated to your risk; your own questionnaire is stable against that. | ||
| Value | |||
| Fit to requirement | Your requirement is knowing where customer data goes and who else touches it, and that question appears nowhere in the criteria; the review is the only lane that answers it. | ||
| Time to market | A badge check is instant, and a first-pass review adds roughly a day to an app decision, which is usually less than the procurement approval it sits inside. | ||
| Performance & scale | The badge is genuinely useful here: LCP at 2.5 seconds or less, CLS at 0.1 or less, INP at 200 milliseconds or less and a p95 of 500ms on admin requests are exactly the numbers worth screening for you (verified Sep 2026). | ||
| Data ownership & AI-readiness | A completed review leaves a data map behind: which app holds which customer fields, under which processor terms, with what retention. Nothing on a listing gives you that. | ||
| Focus & opportunity cost | One page of questions is proportionate for most stores and a full assurance program is not, so the failure to avoid is assuming the badge already covered it. | ||
The App Landscape
| App | Status | Pricing | Best for |
|---|---|---|---|
| Built for Shopify badge | Native — First-party Shopify certification. The requirements are performance, UX and adoption thresholds: LCP of 2.5 seconds or less across a minimum of 100 calls over the last 28 days, CLS of 0.1 or less, INP of 200 milliseconds or less, no more than a ten-point reduction in the storefront Lighthouse performance score, admin requests at a p95 of 500ms or less with a 0.1% failure rate over a minimum of 1,000 requests, and a minimum of 50 net installs from active shops on paid plans. No security, data-handling or compliance requirements section appears on the page, and there is no separate Plus-certified tier (verified Sep 2026). | No cost to merchants; the badge appears on qualifying listings (verified Sep 2026) | Screening apps for storefront speed, admin latency and real adoption before you spend review time on them |
| App permissions and activity review | Native — First-party Shopify. At install, an app declares the personal data it can view, such as customers, store owner and blog contributors, and the store data it can view and edit; after install you can review its activity and permissions from the app's about page. Shopify describes no consolidated cross-app permissions view, so a portfolio audit is a manual pass through each app in turn. This is the one security-relevant signal the platform actually surfaces (verified Sep 2026). | Included on every plan (verified Sep 2026) | Seeing what an app can reach before approving it, and re-checking after an update changes its scopes |
| Your own vendor security review | Build lane — Nothing on the App Store performs this. A vendor review is a questionnaire and a decision record: which scopes the app requests and why, where data is stored and processed, which subprocessors are involved, what the retention and deletion terms say, and whether the vendor will sign your data processing agreement. Sized to risk rather than to ceremony, that is one page of questions and about an hour of reading for most apps. | $6,000–$18,000 to design the process, then staff time per app reviewed (Deploi estimate, illustrative) | Any app requesting customer, order or checkout-adjacent scopes, badge or no badge |
The Build Path
- Use the badge for exactly what it measures: Built for Shopify is a real signal, and a useful one: it screens for storefront speed, admin latency and genuine adoption, all of which you would otherwise test yourself. Treat it as a filter that saves review time on slow or unproven apps, and never as a clearance that ends the review. An app without the badge is not disqualified either, since the criteria include install counts a new vendor cannot have yet.
- Start from the scope list, not the questionnaire: The install-time permission screen tells you what an app can reach: the categories of personal data it can view, and the areas of store data it can view and edit. Route on that. An app requesting no customer personal data gets the badge check and a screenshot for the record; an app reading customer records gets the full five questions and a decision with a date on it.
- Write one page, not a program: Five questions carry almost all the value: which scopes and why, where data is stored and processed, which subprocessors touch it, what the retention and deletion terms are, and whether the vendor signs your data processing agreement. A review process heavier than the risk gets quietly abandoned within two quarters, which leaves you worse off than the short version you would have kept running.
- Re-check, because scopes change after install: Apps request new scopes at update time, and a review completed at install expires without announcing itself. Shopify describes no consolidated cross-app permissions view, so this is a manual pass through each app's page on a schedule you set. Once a year for low-risk apps and at every scope change for anything reading customer data is a defensible cadence.
- Effort band
- $6,000–$18,000 to design the questionnaire, scope policy and decision record, then roughly a day of staff time per app reviewed — Deploi estimate (illustrative); lands in the $10–25K contact-form band
- Typical timeline
- 2–4 weeks to design the process, then roughly a day per app to run it once the page exists (Deploi estimate, illustrative).
- Maintenance, honestly
- ~$3,000–$6,000/yr (Deploi estimate, illustrative): an annual refresh of the questionnaire against your own obligations, plus re-checks of installed apps whose scopes changed at an update. There is no subscription in this lane, because no product performs the work.
- What you own — and what you take on
- You own: the data map of which app holds which customer fields, the decision record behind every install, and the evidence your own auditors ask for. You take on: running the review before the install rather than after the incident, and a periodic manual pass, since Shopify describes no consolidated cross-app permissions view.
3-Year Total Cost of Capability
| Buy (app path) | Build (custom path) | |
|---|---|---|
| Year 0 (setup) | $0 (reading a badge and a listing costs nothing) | $6,000–$18,000 (questionnaire, scope policy, first reviews) |
| Years 1–3 (recurring) | $0, with the risk carried and unpriced | $9,000–$27,000 (3–10 reviews a year plus an annual refresh) |
| 3-year total | ≈$0 | ≈$15,000–$45,000 |
- † All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
- † Buy column: leaning on the platform's own signals (the badge, the review count and the install-time permission list), which cost nothing and perform no security review.
- † Build column: a proportionate vendor review process plus roughly a day of staff time for each of 3–10 apps a year; three-year horizon.
What the Sticker Price Hides
On the buy path
- — The badge measures speed, stability and adoption, so a fast app with weak data handling qualifies exactly as easily as a careful one
- — A high review count measures merchant satisfaction with features, which is a different question from where customer data goes
- — Shopify describes no consolidated cross-app permissions view, so a portfolio's total data exposure is not visible anywhere in the admin
- — Badge criteria belong to Shopify and can be revised, and an app can hold or lose the badge for reasons unrelated to your risk
On the build path
- — A review process heavier than the risk gets abandoned within two quarters, which is worse than a short one that survives
- — Vendors answer questionnaires with marketing copy, so ask for the data processing agreement and the subprocessor list rather than for assurances
- — Scopes change at app updates, so a review completed at install expires quietly and without notice
- — ~$3,000–$6,000/yr in upkeep plus roughly a day of staff time per app (Deploi estimate, illustrative)
What Merchants Say
Procurement teams describe treating the badge as a shortcut past their own review, then finding out the criteria are Core Web Vitals, admin latency and install counts.
The recurring pattern is a review that only happens after the incident, when nobody can say which installed app held the customer records in question.
If You Change Your Mind Later
If you bought and outgrow it
Relying on the badge leaves nothing to exit and nothing to show. When an app is removed, or a vendor has an incident, you are reconstructing from memory which data it held and which scopes it carried, and no admin screen fills that gap after the fact. The whole cost lands at the worst possible moment, which is what makes the free lane expensive.
If you built and want out
The review outputs stay yours and keep working. A scope policy, a questionnaire and a decision record per app port to any platform and satisfy any auditor asking how vendors get approved. Even if you stop running the process, what you already documented remains the fastest map of which app holds which customer data, which is exactly what an incident response needs first.
When This Answer Changes
We're watching for:
- ▸ Shopify adding a security or data-handling section to the Built for Shopify requirements page, which carries none today
- ▸ A separate Plus-certified tier appearing, since the only Plus-specific requirement today is that Plus-exclusive features must be hidden for non-Plus merchants
- ▸ Shopify surfacing a consolidated cross-app permissions view, which no current documentation describes
Verdict change log:
No changes since first publication (September 2026).
Common Questions
Does the Built for Shopify badge mean an app is secure?
The Built for Shopify badge certifies performance, UX and adoption, not security. Badge thresholds cap LCP at 2.5 seconds, CLS at 0.1 and INP at 200 milliseconds. Admin requests need a p95 of 500ms or less at a 0.1% failure rate, and the app needs 50 net installs from paid shops. No security or data-handling requirements section exists on that page.
What should a vendor review cover that Built for Shopify doesn't?
A vendor review covers where customer data goes, which the badge never tests. Ask which access scopes the app requests and why, where data is stored and processed, and which subprocessors touch it. Then ask what the retention and deletion terms are, and whether the vendor will sign your data processing agreement. Budget about a day per app for those 5 questions.
Is there a Shopify app that vets other apps for security?
No Shopify app audits another app's security posture. Built for Shopify certifies performance and adoption instead, requiring a minimum of 50 net installs and a p95 of 500ms on admin requests. The App Store's one security-relevant signal is the install-time permission list, showing what personal and store data an app can view. Shopify describes no consolidated cross-app permissions view.
Your Next Steps
If you're going with BUILD(matches your selected profile)
- List every installed app and the personal-data scopes it holds, since no consolidated cross-app view exists
- Write the five questions on one page: scopes, storage location, subprocessors, retention, data processing agreement
- Set a risk threshold so low-scope apps clear in minutes and customer-data apps get the full review
- Record a decision and a date for every install, because that record is what an auditor asks to see
- Re-check scopes at app updates, since a review completed at install expires quietly
If you're going with WAIT
- Read the badge for what it certifies: Core Web Vitals, admin latency and 50 net installs
- Read the install-time permission screen before approving, and keep a screenshot for the record
- Skip the full review only where the app requests no customer personal data at all
- Diary a re-check whenever the app requests new scopes at update time
Official Docs & Sources
- Built for Shopify requirements — shopify.dev
- Installing apps and reviewing permissions — Shopify Help Center
- Plus Technology Certification requirements — Shopify Help Center
Official documentation linked for verification — our verdicts and estimates are our own.
Related Decisions
Can You See Every App's Access Scope in One Place?
Shopify discloses an app's data-access scopes at install and afterward one app at a time from its about page, with no consolidated view across the app fleet.
Can You Trust Every App Store App to Honor GDPR Deletion?
Shopify rejects any App Store app that fails to answer the mandatory compliance webhooks, with a 30-day action window. Custom apps sit outside that scope.
Do Custom Apps Inherit Any of Shopify's Compliance Vetting?
Shopify's app review covers both public app types, listed and unlisted. Custom apps are never described as reviewed, and compliance webhooks follow the App Store.
Should You Build or Buy Protected Customer Data Access on Plus?
No app grants protected customer data access; Shopify grants it per app. On Plus, build the custom app when the workflow is yours; buy a certified app when one fits.
Shopify Theme Sections: Buy Premium or Build a Section Library?
A custom theme section library wins at mid-market campaign tempo; below the floor, a premium theme is the right call.
Want a vendor review that people actually run?
We write the one-page version first: five questions, a scope threshold that routes low-risk apps through in minutes, and a decision record your auditors accept. Then we map what your installed apps already hold, since Shopify surfaces permissions app by app and never in one place.
Contact us todayVerdict scored for the reference scenario above. Estimates are not quotes; review effort scales with the number of apps and the scopes they request. Badge criteria quoted from Shopify's Built for Shopify requirements documentation as of September 2026 and re-verified quarterly, since Shopify revises those thresholds over time. Full scoring anchors: see the TCC methodology.
Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.