SHOPIFY ID-IMAGE SECURITY
Shopify ID verification security and privacy
PUBLISHED AUGUST 29, 2026 · 6 MINUTE READ
HonestGate keeps submitted ID images outside public Shopify Files, binds each upload to the installing store and paid order, and limits staff views to authenticated Shopify admin sessions through short-lived links. Merchants choose a 1–30 day raw-image retention period, while the reusable approval result is stored separately.
The ID-image path
- 1
A paid Shopify order creates the context
HonestGate does not accept a general public upload. The supported post-purchase surface must identify the store and paid order through Shopify's signed buyer context.
- 2
The app validates and normalizes the image
The initial release accepts supported JPEG and PNG images, validates their type and size, normalizes them, and removes embedded metadata before private storage.
- 3
Authenticated staff request a temporary view
A staff member opens the embedded app through the correct Shopify admin. The app authorizes the shop and produces a short-lived image link rather than exposing a permanent URL.
- 4
The image follows the retention schedule
The merchant's policy sets a raw-image deletion date from 1 to 30 days. A human decision can remain separately for its configured approval lifetime.
Shop-scoped access inside Shopify admin
HonestGate is a multi-tenant Shopify app: many stores can install the same service, but one store must not see another store's orders, images, decisions, or tickets. App records are scoped to the Shopify shop that created them. Staff access begins with an authenticated embedded Shopify admin session, and image authorization checks that shop context before generating a view.
The resulting image link expires after two minutes. That brief window supports a staff review without turning the ID into a reusable public asset. Merchants should still restrict app access to staff who need it, protect staff accounts with Shopify's available account-security features, and avoid copying images to email or other unmanaged systems.
Private image handling
Accepted images are stored in private, app-managed object storage. They are not placed in a theme, a product record, a customer metafield, or the merchant's public Shopify Files library. Embedded image metadata is removed during normalization. The first release does not extract a date of birth, address, or identity number into separate structured fields.
HonestGate version one does not use OCR, face matching, biometric scoring, or automatic document approval. Submitted ID images are not used to train an AI model. Authorized store staff inspect the first submission and make the decision.
Retention and deletion controls
Merchants select a raw-image retention period from 1 to 30 days. That setting determines when the app schedules the submitted image for deletion. Keeping the range narrow lets a merchant choose a practical review window without treating the raw document as a permanent customer record.
HonestGate also supports privacy-deletion workflows. The full handling of merchant, customer, and Shopify platform data is described in the Privacy Notice and Data Processing Addendum. Those documents, rather than this product overview, govern data processing and retention commitments.
The saved approval is not the ID image
A reusable approval stores the review result and its policy state, not another copy of the underlying ID image. It can include the approved minimum age, relevant dates, and whether the result has expired or been revoked. If enabled, a later eligible order can use that result only for the same Shopify customer account at the same store.
The raw image can therefore reach its deletion date while the approval remains active. A higher store minimum age, expiration, revocation, privacy-deletion flag, or account mismatch prevents reuse and sends the later order through a new review.
Security is a shared responsibility
| HonestGate provides | The merchant controls |
|---|---|
| Private app-managed image storage | Which authorized staff can access the app |
| Shop- and order-scoped records | The minimum age and review policy |
| Two-minute staff image links | A raw-image retention setting from 1 to 30 days |
| Separate raw-image and approval lifecycles | Whether and how long eligible approvals may be reused |
| Text-only in-app support tickets | Keeping ID images out of email and ticket text |
HonestGate supports a merchant's age-review process. It does not replace legal advice, guarantee regulatory compliance, or guarantee that a requested fulfillment hold will prevent every fulfillment.
Report a security or privacy concern
Send a concise description to team@agegateapp.com. Do not attach or email an ID image. Installed merchants can also create a text-only ticket from the Support area inside the HonestGate Shopify admin app.
Review the complete HonestGate workflow
See where the storefront prompt, paid order, private upload, manual decision, and eligible repeat-order approval fit.
Compare age gate and verification