Shopify Ecom

Does the Built for Shopify badge mean an app is safe with your customer data?

Published ·
At a glance
Short answer
Partly — a badged app must keep meeting App Store rules, security included, but the badge criteria pages list no separate data-protection test.
Documented criteria
Help Center: Performance, Design, Integration; requirements page adds Prerequisites, including App Store requirements, and Category-specific; neither has a security section.
Security standard
The overview's "Safety, security, and reliability" standard asks for responsible data handling and ongoing App Store compliance.
Rules for every app
App Store rules require TLS and only necessary scopes; protected customer data needs review for public apps, badge or not.
Data protection review
Shopify "might ask" for a data protection review "if we select your app" — selective, not routine.

What does the Built for Shopify badge actually check?

The Help Center names three criteria — Performance, Design and Integration; the developer requirements page has five sections: Prerequisites, Performance, Integration, Design and Category-specific (what an app has to pass). A separate data-protection test for the badge appears on no criteria page we read on September 16, 2026 — the requirements page, the Built for Shopify overview and the Help Center badge section.

The developer overview lists five quality standards, one titled "Safety, security, and reliability". It opens with merchants wanting store data handled responsibly, then asks for clean install and uninstall plus ongoing compliance with App Store requirements and the Shopify API License and Terms of Use — both already badge prerequisites.

Merchants want to know that their apps are handling store data responsibly. Apps need to use certain APIs and extensions to ensure that they install and uninstall cleanly.
Shopify — About Built for Shopify, shopify.dev, read September 16, 2026 ·

Where do the customer-data rules for a badged app come from?

A badge prerequisite says the app "needs to continue to meet the requirements" of the App Store (the app "will be audited for these requirements when you apply"), and section "3. Security" of those App Store requirements asks for a valid TLS/SSL certificate and only "the access scopes that are necessary". That binds every app in the App Store, badged or not.

Protected customer data is a second rule set: for a public app both of its levels show "Requires review", and Shopify approves access "if the requested data is the minimum amount required". A deeper check is selective — Shopify "might ask for a detailed review", contacting the developer "if we select your app for a data protection review". The "Requires review" rule for protected customer data applies to any public app that requests that data, badged or not.

What should you still check before installing a badged app?

The permissions screen. Shopify "might" run a data protection review, and the badge is re-checked "annually" against its standards, so neither replaces reading what an app asks for at install.

Whether a badged app asks for more than it needs is answered by how to tell whether an app is asking for too much; the Help Center lists the badge criteria as performance, design and integration.


About This Article

Related questions

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.