FindIP Shield for Shopify
Visitor risk detection for your storefront: VPN, proxy, Tor, hosting, and malicious-traffic signals for every consented visit. The app uses IP/network and event metadata while excluding names, emails, customer IDs, order details, cart contents, and payment data. Its Shopify Web Pixel runs in Shopify's strict sandbox, and events go directly from the shopper's browser to the FindIP Shield ingest service.
Requirements
- A Shopify store (any plan that supports apps)
- A free FindIP account
- A Shield site for your storefront domain
Installation
- Install FindIP Shield from the Shopify App Store.
- Open the app in your Shopify admin. It will ask for a public site key.
- Create a Shield site at findip.net → Shield → Sites → New site.
- Domain: enter the hostname your shoppers actually visit — your custom domain (
www.yourstore.com) if you have one, otherwiseyourstore.myshopify.com. - The domain must match — events from unregistered domains are rejected.
- Domain: enter the hostname your shoppers actually visit — your custom domain (
- Copy the site's public key (starts with
pub_). - Paste it into the app and select Connect Shield.
- The status card shows Connected when the key is accepted.
Verify your first event
Visit your storefront and view any product, then open your Shield site's event feed at findip.net. A page_viewed or product_viewed event should appear within seconds. If your store uses a consent banner, accept analytics consent first — the pixel only runs when Shopify permits analytics processing.
Data collection
What the pixel sends — standard Shopify analytics events (page view, product view, cart, checkout progress), reduced to metadata:
- Event name and timestamp
- Page origin and path — query strings and fragments are removed
- Page title and referrer
- Browser user agent, language, cookie availability, viewport size
- A random identifier scoped to the current browser session
What the pixel never sends:
- Names, email addresses, phone numbers, postal addresses
- Shopify customer, order, checkout, product, or variant identifiers
- Cart contents, product titles, SKUs, search queries
- Payment or card information
- Form contents, keystrokes, or page DOM content
Full details: privacy policy.
Consent behavior
The Web Pixel declares analytics processing to Shopify. Shopify's Customer Privacy system decides when it runs:
- Analytics consent granted (or not required in the visitor's region): events are sent.
- Consent denied or not yet given where required: the pixel does not emit events. If the visitor grants consent later, events start from that moment.
No configuration is needed in the app — this is enforced by Shopify's pixel sandbox.
Changing or disconnecting the key
Open the app and paste a different pub_ key to switch Shield sites; the change takes effect immediately. Uninstalling the app removes the Web Pixel and the app's access to your store, and deletes the store's authentication session from FindIP's systems.
Troubleshooting
| Symptom | Check |
|---|---|
| No events appear | Domain registered for the site key matches the storefront hostname exactly |
| No events appear | Analytics consent was granted (or your region doesn't require it) |
| No events on custom domain | Register the custom domain, not the .myshopify.com address |
| Key rejected on connect | Use the public key (pub_…), not the secret key |
| Events stopped after theme/domain change | Update the Shield site's domain to the new hostname |
Still stuck? See support — we aim to respond within two business days.
Terms
Shield's risk output consists of informational signals only; decisions you take based on them are yours. Free Shield sites are governed by the Shield Free Preview Terms in addition to the FindIP Terms of Service.