Ecom Store Pro

Who can open your customer's Shopify order status page?

Updated ·
At a glance
Short answer
Anyone holding the link can open it; Shopify says a shared link shows only limited order details, such as the items, the total and the discounts.
Same browser, no login
3 weeks from the order confirmation email — Shopify's window while the customer stays in the same browser
A different browser
2 weeks without a login, across a maximum of 5 different browsers
When the window closes
Customer-account login, or the order number plus the email or phone used at checkout — both, not either
Expiry is tracked per browser
One browser can still open the page while another asks for a login — Shopify times each browser separately
Your own admin view
Opening your customer's order status page from admin shows the same limited details — Shopify cites the customer login requirement
Customer-account sign-in
On current customer accounts with sign-in links on: a one-time 6-digit code, no password; sessions persist up to 365 days
Track with Shop link off
Removes the order status page link; Shop still tracks any order with a valid tracking number
Your staff
Orders > View is store-wide — no per-order or per-customer restriction, outside two exceptions Shopify names
Not a setting you control
No merchant control over these windows on the Shopify pages we read in August 2026

Yes — the URL is not the lock. Shopify documents forwarding as something customers do on purpose, and answers it by limiting what the page renders:

Customers can choose to share the link to their order status page with friends to inform them about their purchases. However, when customers share their order status page link, only the limited order details display.
Shopify — Shopify Help Center — Understanding order status pages, read August 22, 2026 ·

So the reply to a customer asking whether it was safe to forward the link carries a scope, not a yes or a no. What the person they forwarded it to reads is the limited order details — a set Shopify names once and reuses for exactly this case, listed field by field under What someone without those credentials sees.

For the customer themselves the page is a shipment tracker: what it lists are the shipment stages Shopify documents for a supported carrier, not a payment view. Access is the variable — and it runs on a clock.

There are two windows, and the browser decides which one applies. Shopify states the first plainly: customers "can access their order status page from their order confirmation email for 3 weeks without logging in, when using the same browser."

Open that same link somewhere else and the clock is shorter. "When using different browsers, customers can access their order status page for 2 weeks without logging in, across a maximum of 5 different browsers." Expiry is tracked per browser — Shopify's own phrase is the expiry period for their browser — so a customer whose laptop still opens the page while their phone asks for a login is not describing a bug.

The login requirement itself is not old, which matters when a long-standing customer insists the link used to just open. Shopify announced new login requirements for the order status page on March 21, 2024, in a changelog post named for exactly that.

What the five-browser cap actually counts

The cap lives inside one Shopify sentence — 2 weeks without logging in, across a maximum of 5 different browsers — and that sentence is the only place Shopify states it. Shopify's unit is the browser — the word its sentence uses — so one person moving between a phone, a home laptop and a work machine has spent three of the five.

The three-week and two-week windows are stated for access without logging in. Sharing gets a sentence of its own: "when customers share their order status page link, only the limited order details display." So when the ticket is about a forwarded link, that is the sentence to quote.

When a browser's two- or three-week window runs out, the customer isn't stranded — Shopify's documented next step is the route below.

What Shopify asks for once the window closes

The order status page does not go dark when a no-login window expires — it asks. Shopify's instruction is that the customer clicks Log in, then takes one of two routes.

The first is the ordinary one: log in to their customer account. The second exists for customers who never created one, and it is where merchants misread the requirement — Shopify asks them to "Provide both of the following credentials": their order number, and the email address or phone number used during checkout. Both, together. Either one alone is not what the page accepts.

The order number is the half customers assume they have lost. Shopify notes it "can be retrieved from their order confirmation email or SMS receipt" — usually the same message they are writing to you about, so the fastest reply is a pointer, not a lookup in your admin.

How do you get a locked-out customer back in?

Pick the route by what the customer still has. Shopify's order tracking guide adds that orders sync to the customer's Shop account.

Which route to point a customer to, by what they still have

If the customer still hasPoint them toWhat Shopify says about it
The email address on their customer profileCustomer-account sign-inOn current customer accounts, they already have an account; with sign-in links on, a one-time 6-digit code, no password
A Shop accountThe Shop appOrders from your store sync to it automatically
The order number and the checkout email or phoneLog in, then both credentialsBoth together, as above

Shopify Help Center — Customer accounts; Order tracking at Shopify; Understanding order status pages; read October 5, 2026.

On the current customer accounts, Shopify says a customer with a profile in your admin already has an account and can sign in with the email address on that profile; when you turn on sign-in links, they sign in with a one-time 6-digit code — "A password isn't required to sign in." There, "Sign-in sessions persist for up to 365 days", against a no-login window of 3 weeks at most. Of the windows Shopify states, the first row's is the longest. On legacy customer accounts, customers must first register on a separate page or accept an account invite.

That row depends on a setting you own: the sign-in links toggle.

The Shop row runs on a default: Shopify says Track with Shop "is activated by default for all Shopify stores", and once a customer installs the app and creates an account, their orders sync to it — though Shopify says "you need to provide complete tracking information for your orders" for them to be tracked accurately in Shop.

What someone without those credentials sees

Shopify names the limited order details once, for the case where a browser's expiry period has passed and no credentials were provided, and applies the same limit to a shared link. The examples Shopify gives of what displays, and the examples it gives of customer information that isn't displayed:

What Shopify lists as shown, and what it lists as not displayed

Order detailOn a limited view
Items purchasedShown
Order totalShown
Discounts appliedShown
The order's statusShown, with a supported carrier
Customer nameNot shown
Shipping and billing addressesNot shown
Payment methodsNot shown
Shipping methodNot shown
Tracking numberNot shown

Shopify Help Center — Understanding order status pages, read August 22, 2026.

The withheld half answers the privacy question you are actually being asked: an address, a payment method and a tracking number are precisely the fields that make a forwarded link feel risky, and Shopify states they aren't displayed.

If you are thinking of switching the Track with Shop link off for privacy, know what the switch covers. Shopify says that regardless of whether Track with Shop displays, customers "can still use Shop to track any order with a valid tracking number". In Shop, a valid tracking number is enough to track an order whether or not the button displays — and the tracking number is one of the fields the limited view leaves out. Switching the link off changes what your page shows, not who can track the order in Shop.

The shown half carries one condition of its own, and it is on the status row: Shopify says the order status isn't displayed when the shipment goes with an unsupported carrier.

That limited view is not reserved for whoever a link gets forwarded to — Shopify applies it when you open the page from your own admin too:

You can visit a customer's order status page from your Shopify admin. However, you can only access limited order status page details due to the customer login requirement.
Shopify — Shopify Help Center — Understanding order status pages, read August 22, 2026 ·

What you control is narrower than it looks. You decide whether a login link is displayed, inside Shopify's own limits: customer accounts have to be set up with Show sign-in links toggled on — the order status page documentation writes Show login links — and login links don't display on stores using legacy customer accounts. Why the link stays hidden, and where that toggle sits is its own question.

What you cannot move is the clock: we found no merchant setting or plan gate over the 3-week, 2-week or 5-browser numbers on Shopify's order status page documentation, its changelog post, or the sibling pages in that Help Center folder, read on August 22, 2026.

So the honest reply to the ticket is a scope: the link opened, and the fields Shopify names for that view include the items, the total, the discounts and — with a supported carrier — the order's status, not the address, the payment method or the tracking number.

Who on your team can see the full order?

The limited view you get from admin is the order status page. The order itself is a different surface: Shopify's store permissions describe an order's "customer information, shipping information, tags, and metafields", and who on your team reaches them is a staff-permission setting.

Three lines in that permission list decide who you hand access to:

  • Orders > View "allows users to view orders", and Shopify says that within a store you can't restrict permissions to individual orders, products, or customers. Outside the two exceptions below, a teammate who needs one order can open the rest.
  • Viewing is separate from changing. Manage order information is the permission that edits customer and shipping information, so someone who only answers "where is my parcel" tickets can hold View without it.
  • Customer profiles sit under their own Customers > View permission, which "allows users to view customer profiles".

Shopify names two exceptions that narrow access further: app and channel permissions, and, for B2B, restricting a user to their assigned company locations. Outside those, you grant each permission across every order, not order by order.

About This Article

This page was written by AI. Separate AI agents that did not write it check its figures and claims against official sources and test its links and interactive tools. A human editor sets the site's editorial direction, topics and rules and checks that pages are complete and display correctly, but does not check their facts or edit their text. Details may change — always confirm critical data at shopify.com.

Editorial Policy

Related questions

Orders & customers
Why don't login links show on your Shopify order status page?

Shopify documents two causes: the store uses legacy customer accounts, or the links are turned off in Settings > Customer accounts.

Updated October 5, 2026

Shipping & fulfillment
How does order status work with a custom email fulfillment service in Shopify?

A custom email service doesn't update the order status automatically: after fulfillment, you track with the service and update the order yourself.

Updated October 5, 2026

Orders & customers
What can you do when Shopify won't let you edit an order?

A store rule blocked the edit, not a bug — of the seven order rules Shopify states, it names an official way out for only two.

Updated September 29, 2026

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.