- Short answer
- Anyone holding the link can open it; Shopify says a shared link shows only limited order details, such as the items, the total and the discounts.
- Same browser, no login
- 3 weeks from the order confirmation email — Shopify's window while the customer stays in the same browser
- A different browser
- 2 weeks without a login, across a maximum of 5 different browsers
- When the window closes
- Customer-account login, or the order number plus the email or phone used at checkout — both, not either
- Expiry is tracked per browser
- One browser can still open the page while another asks for a login — Shopify times each browser separately
- Your own admin view
- Opening your customer's order status page from admin shows the same limited details — Shopify cites the customer login requirement
- Not a setting you control
- No merchant control over these windows on the Shopify pages we read in August 2026
Can anyone with the link open it?
Yes — the URL is not the lock. Shopify documents forwarding as something customers do on purpose, and answers it by limiting what the page renders:
Customers can choose to share the link to their order status page with friends to inform them about their purchases. However, when customers share their order status page link, only the limited order details display.
So the reply to a customer asking whether it was safe to forward the link carries a scope, not a yes or a no. What the person they forwarded it to reads is the limited order details — a set Shopify names once and reuses for exactly this case, listed field by field under What someone without those credentials sees.
For the customer themselves the page is a shipment tracker: what it lists are the shipment stages Shopify documents for a supported carrier, not a payment view. Access is the variable — and it runs on a clock.
How long the link opens without a login
There are two windows, and the browser decides which one applies. Shopify states the first plainly: customers "can access their order status page from their order confirmation email for 3 weeks without logging in, when using the same browser."
Open that same link somewhere else and the clock is shorter. "When using different browsers, customers can access their order status page for 2 weeks without logging in, across a maximum of 5 different browsers." Expiry is tracked per browser — Shopify's own phrase is the expiry period for their browser — so a customer whose laptop still opens the page while their phone asks for a login is not describing a bug.
The login requirement itself is not old, which matters when a long-standing customer insists the link used to just open. Shopify announced new login requirements for the order status page on March 21, 2024, in a changelog post named for exactly that.
What the five-browser cap actually counts
The cap lives inside one Shopify sentence — 2 weeks without logging in, across a maximum of 5 different browsers — and that sentence is the only place Shopify states it. Shopify's unit is the browser — the word its sentence uses — so one person moving between a phone, a home laptop and a work machine has spent three of the five.
The three-week and two-week windows are stated for access without logging in. Sharing gets a sentence of its own: "when customers share their order status page link, only the limited order details display." So when the ticket is about a forwarded link, that is the sentence to quote.
When a browser's two- or three-week window runs out, the customer isn't stranded — Shopify's documented next step is the route below.
What Shopify asks for once the window closes
The order status page does not go dark when a no-login window expires — it asks. Shopify's instruction is that the customer clicks Log in, then takes one of two routes.
The first is the ordinary one: log in to their customer account. The second exists for customers who never created one, and it is where merchants misread the requirement — Shopify asks them to "Provide both of the following credentials": their order number, and the email address or phone number used during checkout. Both, together. Either one alone is not what the page accepts.
The order number is the half customers assume they have lost. Shopify notes it "can be retrieved from their order confirmation email or SMS receipt" — usually the same message they are writing to you about, so the fastest reply is a pointer, not a lookup in your admin.
What someone without those credentials sees
Shopify names the limited order details once, for the case where a browser's expiry period has passed and no credentials were provided, and applies the same limit to a shared link. The examples Shopify gives of what displays, and the examples it gives of customer information that isn't displayed:
What Shopify lists as shown, and what it lists as not displayed
| Order detail | On a limited view |
|---|---|
| Items purchased | Shown |
| Order total | Shown |
| Discounts applied | Shown |
| The order's status | Shown, with a supported carrier |
| Customer name | Not shown |
| Shipping and billing addresses | Not shown |
| Payment methods | Not shown |
| Shipping method | Not shown |
| Tracking number | Not shown |
Shopify Help Center — Understanding order status pages, read August 22, 2026.
The withheld half answers the privacy question you are actually being asked: an address, a payment method and a tracking number are precisely the fields that make a forwarded link feel risky, and Shopify states they aren't displayed.
The shown half carries one condition of its own, and it is on the status row: Shopify says the order status isn't displayed when the shipment goes with an unsupported carrier.
That limited view is not reserved for whoever a link gets forwarded to — Shopify applies it when you open the page from your own admin too:
You can visit a customer's order status page from your Shopify admin. However, you can only access limited order status page details due to the customer login requirement.
What you control is narrower than it looks. You decide whether a login link is displayed, inside Shopify's own limits: customer accounts have to be set up with Show login links toggled on, and login links don't display on stores using legacy customer accounts, or on stores that have turned them off.
What you cannot move is the clock: we found no merchant setting or plan gate over the 3-week, 2-week or 5-browser numbers on Shopify's order status page documentation, its changelog post, or the sibling pages in that Help Center folder, read on August 22, 2026. So the honest reply to the ticket is a scope: the link opened, and the fields Shopify names for that view include the items, the total, the discounts and — with a supported carrier — the order's status, not the address, the payment method or the tracking number.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy