Build vs. Buy>Trust, Legal & Compliance>Custom App Compliance Vetting Gap

Do Custom Apps Inherit Any of Shopify's Compliance Vetting?

Written by Deploi EditorialReviewed by Martin Dejnicki, Director of SEO & AI SearchUpdated September 2026Pricing verified September 2026

Custom apps inherit none of Shopify's compliance vetting, which makes the review a BUILD you fund yourself. Shopify documents that both public app types, listed and unlisted, undergo app review; the custom-apps documentation never mentions review at all. The mandatory compliance webhooks follow App Store distribution, so they miss custom apps too. Budget $15,000–$40,000 for the review your own app will never receive (Deploi estimate, illustrative).

Your profile — see how the verdict shifts

VerdictBUILD with the assurance work budgeted in, because a custom app inherits no vetting at all · BUY a reviewed public app whenever one genuinely covers the workflow and inherit the baseline free · nothing on the App Store back-fills the review
Buy score
3.6
Build score
7.8
Confidence
HighShopify's custom-apps help page was read on 2026-09-05, and the load-bearing sentence is precise: there are two types of public apps, listed and unlisted, and both undergo Shopify's app review process and can be installed from the Shopify App Store. Worth stating exactly what the documentation states. The phrase 'custom apps do not undergo Shopify's app review process' is not literal page text; it is a correct inference from a page that describes review for the two public types while the custom-apps section never mentions review at all. That distinction matters in practice, because teams routinely say unlisted when they mean custom, and an unlisted public app is reviewed. The second half comes from Shopify's app-compliance documentation: any app distributed through the Shopify App Store must respond to data subject requests, and an app that does not answer the mandatory compliance webhooks will be rejected. The obligation follows App Store distribution, so it does not reach a custom app either. Plus is what makes this a live decision rather than a hypothetical, since only stores on a Shopify Plus plan can use custom apps that contain Shopify Function APIs, while stores on any plan can use public apps containing functions. On the market side, the Store Management security and operations categories were browsed in full and returned cookie-consent apps, fraud and bot blockers and accessibility widgets. Nothing audits, scans or vets a merchant's own custom app, which makes this market empty rather than thin.
Reference scenario
$20M–$150M GMV · Shopify Plus · in-house or agency dev bench · 2–5 custom apps for internal tooling · at least one of them reading customer or order data
As of
September 2026

Decision at a Glance

Your profileVerdictWhy
Custom app with no customer-data scopesBUILDBuild it, and keep the review proportionate: a threat model, least-privilege scopes and a note of what it can reach. An internal tool that cannot read personal data cannot leak it, and days of assurance work is the right size.
Custom app reading customer or order dataBUILDBuild it with the full assurance budget attached. Shopify's review never examines this app, so the deletion path, retention rules and access logging that review would have checked are yours to design, run and evidence.
Custom app containing Shopify Functions on PlusBUILDOnly stores on a Shopify Plus plan can use custom apps that contain Shopify Function APIs, so this lane exists because of the plan. The entitlement changes nothing about the review gap; it just makes the choice available more often.
A reviewed public app already covers the workflowBUYInstall it. Both listed and unlisted public apps undergo Shopify's app review, and any app distributed through the App Store must answer data subject requests within 30 days. That baseline arrives free with the install and costs weeks to reproduce.

What Custom App Compliance Vetting Gap Actually Drives

OutcomeImpactHow it works
Operational efficiencyHighA custom app matches the internal process exactly rather than approximately, which removes the spreadsheet and the manual step a half-fitting public app always leaves behind.
Data & insightHighA custom app keeps internal process data inside systems you already query, instead of copying it into a vendor's database where retrieving it becomes an export request.
Revenue — indirectMediumA documented assurance record for internal apps clears the security sections of enterprise and retail partner reviews that would otherwise pause a contract for weeks.
Customer experienceLowCustomers never see an internal tool, and they do feel a deletion request answered slowly because nobody wrote down what the custom app held.

Spend ceiling: Size the assurance spend to the data the app touches, not to the app itself. A custom app with no customer-data scopes deserves a threat model and a scope review measured in days. One reading customer records deserves the full $15,000–$40,000 treatment (Deploi estimate, illustrative), because Shopify's review will never look at it and your auditors eventually will.

What buying enables (top apps)

  • + Shopify's app review, which both listed and unlisted public apps undergo before reaching the App Store (verified Sep 2026)
  • + The mandatory compliance webhooks and a 30-day action window, carried by the vendor for its copy of the data (verified Sep 2026)
  • + API version migrations, patching and support absorbed by a vendor doing the work for every merchant at once
  • + A same-day install that needs no engineering capacity at all

What building additionally unlocks

  • + A workflow matching your internal process exactly, which is the honest reason to build and a real one
  • + Internal data staying inside systems you control rather than being copied into a vendor's database
  • + Shopify Functions inside a custom app, which only Shopify Plus stores can use (verified Sep 2026)
  • + Access scopes cut to exactly what the tool needs, rather than to what a general-purpose vendor requests

Find Your Verdict in 3 Questions

  1. Does a reviewed public app already cover the workflow?

    Yes: Your verdict: BUY — installing it inherits Shopify's app review and the App Store deletion obligation at no extra cost.

    No: Go to question 2.

  2. Will the custom app read customer or order data?

    Yes: Your verdict: BUILD — budget $15,000–$40,000 for the assurance work, because no review will ever look at this app (Deploi estimate, illustrative).

    No: Go to question 3.

  3. Does the work need Shopify Functions?

    Yes: Your verdict: BUILD — only Shopify Plus stores can use custom apps containing Shopify Function APIs, so scope the review to match what the function reads.

    No: Your verdict: BUILD — keep the review light and proportionate, then re-check whenever the app's access scopes expand at a release.

The TCC Scorecard — 12 Dimensions

TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →

DimensionBuyBuildWhy
Cost
Acquisition & implementationA reviewed public app installs the same day, while a custom app plus the assurance work Shopify will never do is an estimated 8–16 weeks of build and review combined (Deploi estimate, illustrative).
Recurring feesA public app bills every month indefinitely, whereas a custom app carries no subscription and a real annual assurance cost in its place.
Maintenance & upgradesThe vendor absorbs Shopify's API version changes and re-enters review with every submission; a custom app's upkeep and its periodic re-review both belong to you.
Switching & exitLeaving a public app means an export request and whatever the vendor retains, while retiring your own custom app means revoking a token and deleting data whose shape you already know.
Risk
Vendor riskA public app can be sold, sunset or delisted and a custom app has no vendor to lose; the trade is that its only reviewer is your own team.
Security & compliance surfaceThis dimension is the whole fork. Listed and unlisted public apps both undergo app review and must answer the mandatory compliance webhooks, while a custom app is described nowhere as reviewed (verified Sep 2026).
Platform-deprecation exposurePublic apps carry version migrations on your behalf, whereas a custom app inherits Shopify's release cadence directly and nobody sends a reminder when something changes.
Value
Fit to requirementA custom app matches your internal process exactly, which is the honest reason to build one; that fit is real, and it arrives without a compliance backstop.
Time to marketA same-day install against an estimated 8–16 weeks for a custom app with its assurance work included (Deploi estimate, illustrative).
Performance & scaleBoth lanes run against the same Shopify APIs under the same per-app rate budget, so neither one wins this dimension on throughput.
Data ownership & AI-readinessA custom app keeps internal data inside systems you already query rather than copying it to a vendor, which is a genuine advantage and a reason the review matters more rather than less.
Focus & opportunity costBuilding means owning the assurance work permanently, so budget it at the estimate rather than discovering it at the audit, which is where most teams meet it.

The App Landscape

AppStatusPricingBest for
Shopify app review (listed and unlisted public apps)NativeFirst-party Shopify process, and the baseline a custom app opts out of. Shopify documents two types of public apps, listed and unlisted, and states that both undergo Shopify's app review process and can be installed from the Shopify App Store. Any app distributed through the App Store must also respond to data subject requests within 30 days, and one that fails to answer the mandatory compliance webhooks will be rejected. The custom-apps documentation never mentions review at all (verified Sep 2026).Included; app review costs the merchant nothing and happens before an app reaches the App Store (verified Sep 2026)Any workflow a reviewed public app already covers, where the review and the deletion obligation arrive with the install
Compliance and security appsCategoryThe category a search lands in, and it holds nothing for this decision. The Store Management security and operations categories were browsed in full and returned cookie-consent apps such as Consentmo and Pandectes, fraud and bot blockers, and accessibility widgets. None audits, scans or vets a merchant's own custom app. No product back-fills Shopify's review after the fact, which is why this market is empty rather than thin (verified Sep 2026).Nothing in the category prices this; the apps present solve other problemsCookie consent, fraud filtering and accessibility, which are real needs and not this one
Custom app plus your own assurance reviewBuild laneThe lane this page is about. A custom app never enters Shopify's review, so the controls that review would have checked belong to you: least-privilege access scopes, a documented deletion path for customer data, retention rules, access logging, and a re-review whenever scopes change. On Plus this lane also unlocks Shopify Functions, since only stores on a Shopify Plus plan can use custom apps that contain Shopify Function APIs (verified Sep 2026).$15,000–$40,000 for the assurance work alongside the build (Deploi estimate, illustrative), then annual upkeepInternal tooling and Plus-only Functions work where no reviewed public app covers the workflow

The Build Path

  • Say custom, not unlisted: Shopify documents two types of public apps, listed and unlisted, and both undergo app review before they can be installed from the App Store. Custom apps are the ones outside that process. Teams use the two words interchangeably, and the swap hides the entire risk: an unlisted app was reviewed, and a custom app was not. Fix the vocabulary before the risk conversation, or the conversation reaches the wrong answer.
  • Check the public shelf before you build: A reviewed public app that genuinely covers the workflow brings Shopify's review and the App Store deletion obligation along with it, at no cost and no engineering time. That baseline takes weeks to reproduce. Search properly first, and treat a half-fitting app honestly rather than as an excuse: half-fitting usually means a second app later, which is its own kind of expensive.
  • Rebuild the parts of review that mattered: Four controls carry most of the value that app review would have provided. Cut access scopes to least privilege at the first release. Build a deletion path deliberately, since the mandatory compliance webhooks follow App Store distribution rather than the app. Write retention rules with dates on them. Log access, so a later question about who read what has an answer.
  • Treat Plus as the reason this choice keeps appearing: Only stores on a Shopify Plus plan can use custom apps that contain Shopify Function APIs, while stores on any plan can use public apps that contain functions. Plus merchants therefore reach for a custom app far more often than anyone else, which is exactly why the review gap deserves a budget line rather than an assumption.
Effort band
$15,000–$40,000 for the assurance work alongside a custom app build — threat model, scope minimization, deletion path, retention rules and access logging — Deploi estimate (illustrative); spans the $10–25K and $25–75K contact-form bands
Typical timeline
8–16 weeks for a custom app with its assurance work included, against a same-day install for a reviewed public app that already fits (Deploi estimate, illustrative).
Maintenance, honestly
~15% of the assurance budget per year (Deploi estimate): roughly $2,500–$6,000/yr (Deploi estimate, illustrative) for scope re-reviews when the app changes, retention checks and an annual read against your own obligations. There is no subscription, and no external reviewer unless you hire one.
What you own — and what you take on
You own: the app, its data, its access scopes, and every control Shopify's review would otherwise have checked. You take on: being the only reviewer that app will ever have, which means writing down what good looks like before the first release rather than after the first question from an auditor.

3-Year Total Cost of Capability

Buy (app path)Build (custom path)
Year 0 (setup)$2,000–$9,000 (implementation and configuration)$15,000–$40,000 (assurance work alongside the build)
Years 1–3 (recurring)$10,800–$54,000 (a $300–$1,500/month illustrative band)$7,500–$18,000 (scope re-reviews, retention checks, upkeep)
3-year total≈$12,800–$63,000≈$22,500–$58,000
Illustrative cumulative cost over 36 months$0$11k$21k$32k$43kMo 0Mo 12Mo 24Mo 36Buy (app path)Build (custom path)
Illustrative cumulative cost across three years, with one deliberate omission: the build column counts only the assurance work, not the custom app's own feature build. Even so the two lines land close together, which is the point. Build for fit rather than for price, and count the compliance backstop you are giving up as a line item rather than a footnote.
  • All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
  • Buy column: a reviewed public app on a mid-market tier, held as an illustrative band since the fitting app depends on the workflow, plus implementation.
  • Build column: only the assurance work Shopify's review would otherwise have covered, excluding the custom app's own feature build, which varies with the workflow; three-year horizon.

What the Sticker Price Hides

On the buy path

  • App review covers the vendor's obligations rather than your configuration, so an over-scoped install is still your risk to carry
  • The subscription never stops, and a workflow the app only half-fits usually becomes a second app rather than a cheaper one
  • An app can be sold, sunset or delisted, and the internal process it carried leaves with it
  • The vendor's deletion obligation covers the vendor's copy of the data, so your own retention rules still need writing

On the build path

  • Custom apps enter no review, so the first external examination is likely to come from an auditor or a regulator
  • Access scopes drift upward as features are added, and nothing in the platform prompts a re-review
  • A deletion path has to be built deliberately, because the mandatory compliance webhooks follow App Store distribution rather than the app itself
  • ~$2,500–$6,000/yr in scope re-reviews and retention checks (Deploi estimate, illustrative)

What Merchants Say

Engineering teams describe reaching for a custom app because it beats procurement on speed, then learning at audit time that faster also meant unreviewed.
community-reported (2026 research corpus)
The word people use is unlisted and the app they mean is custom, a distinction that only surfaces when somebody asks which review it went through.
community-reported (2026 research corpus)

If You Change Your Mind Later

If you bought and outgrow it

Removing a reviewed public app means revoking access, requesting deletion under the obligations that came with its App Store distribution, and confirming what the vendor retains. The internal process it carried leaves with it, so document how the workflow actually runs before you uninstall rather than afterwards, because that knowledge is the part no export includes.

If you built and want out

Nothing strands, since the app, its data and its access token are all yours to retire on your own timeline. What persists is the obligation: a retired custom app still held customer data, so the deletion and retention rules you wrote are what let you answer for it later. Keep the assurance record with the code rather than in somebody's inbox.

When This Answer Changes

We're watching for:

  • Shopify introducing any review, attestation or scanning step for custom apps, which no current documentation describes
  • A custom app's access scopes expanding at a release, which is the moment your last review stopped being accurate
  • A reviewed public app appearing that covers the workflow you built for, since installing it would inherit the baseline free

Verdict change log:

No changes since first publication (September 2026).

Common Questions

Do custom Shopify apps go through Shopify's app review?

Shopify documents app review for public apps only. The custom-apps page states that there are two types of public apps, listed and unlisted, and that both undergo Shopify's app review process. The custom-apps section never mentions review. The mandatory compliance webhooks and their 30-day action window follow App Store distribution, so a custom app inherits neither.

Is there an app that vets our custom Shopify app for compliance?

No product does this. The Store Management security and operations categories were browsed in full and returned cookie-consent apps such as Consentmo and Pandectes, fraud and bot blockers, and accessibility widgets. Nothing audits or scans a merchant's own custom app. A Plus merchant running 5 custom apps has 5 apps that nobody outside the team has ever reviewed.

Should we build a custom app or install a reviewed public one?

Install the reviewed public app whenever one genuinely covers the workflow, because its review and its deletion obligation come free with the install. Build custom when no public app fits, or when the work needs Shopify Functions, which only Plus stores can use inside a custom app. Budget $15,000–$40,000 for the assurance work Shopify's review will never perform (Deploi estimate, illustrative).

Your Next Steps

If you're going with BUILD(matches your selected profile)

  1. Write down which of your apps are custom and which are public, since unlisted public apps are reviewed and custom apps are not
  2. Cut each custom app to least-privilege scopes before the first release, because scopes drift and nothing prompts a re-review
  3. Build a deletion path deliberately, since the mandatory compliance webhooks follow App Store distribution rather than the app
  4. Make retention rules and access logging release criteria rather than follow-up tickets
  5. Tie the next review to a scope change instead of to a calendar date

If you're going with BUY

  1. Search the App Store properly before building, since a reviewed app brings the compliance baseline free
  2. Check what the app requests at install, because review covers the vendor's obligations and not your configuration
  3. Confirm the vendor's retention and export terms at signup rather than at cancellation
  4. Document how the workflow runs internally, since that knowledge leaves with the app

Official Docs & Sources

Official documentation linked for verification — our verdicts and estimates are our own.

Building custom? Budget the review nobody else will run.

We scope the assurance work next to the build rather than after it: least-privilege scopes, a deletion path that matches what the App Store obligation would have required, retention rules with dates, and access logging. You get the internal tool you wanted and an answer ready for the first auditor who asks who reviewed it.

Contact us today

Ecommerce development at Deploi

Verdict scored for the reference scenario above. Estimates are not quotes; assurance effort scales with the data an app touches and with your own regulatory obligations. Platform behavior quoted from Shopify's custom-apps and app-compliance documentation as of September 2026, where review is described for public apps and the custom-apps section is silent on it. Full scoring anchors: see the TCC methodology.

Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.

No affiliate links. No paid placement. We make money building and integrating solutions — not on referral fees.