Consenfy

DPDPA consent and data rights for Indian Shopify stores

Most banners log a click. The Act asks you to prove a decision.

Consenfy gates tracking against what the shopper actually chose, and keeps an uneditable, notice-stamped record of it in your own Shopify store.

Free for everything the law requires. Pro is $7/month. Not legal advice.

yourstore.myshopify.com

What just got recorded

S6(10)
status
awaiting a decision
analytics
blocked
marketing
blocked
personalization
blocked
notice ver.
-
recorded
-

Try it. This is the decision logic, running in your browser. Nothing is sent anywhere.

What the product actually does

Built against the Digital Personal Data Protection Act, 2023 — not a GDPR checklist with Indian labels stuck on.

S6(1), S7(a)

Consent that is enforced

Choices run through Shopify's Customer Privacy API, so managed pixels are actually gated. Essential processing stays locked on — checkout is not a cookie toggle.

S6(10)

A record you can show

Every decision written once, never edited, stamped with the notice version on screen at the time. Emails and IPs stored as keyed hashes, not plain text.

S11 to S14

Rights you can fulfil

A storefront form covering all six rights, feeding a queue you can work. Erasure logs its own proof.

S5, S6(3)

Versioned notices

Publishing a change creates a new immutable version, so past consents stay tied to the wording actually shown.

S8(6)

A breach console, not a filing bot

Record what happened and keep a timeline. It won't decide whether an incident is notifiable, and it can't file with the Board for you.

S8(9), S13

Your obligations, not our guess

Reads your settings and states what applies to you. Where we haven't asked, it says so rather than assuming.

Where the data lives

Compliance records go into your own Shopify store as metafields and metaobjects, under a namespace reserved to the app. We read and write them through Shopify's API — we don't keep a second copy of your customers.

Pricing that doesn't gate the law

If you never pay, you can still collect consent, enforce it, keep the evidence, and answer every rights request — including erasure. You pay only when doing it by hand starts to hurt.

Consenfy Pro

$7 / month

  • Everything in Free
  • Full consent history with search and CSV export
  • Deadline tracking and per-type guidance on rights requests
  • One-click data-summary generation and bulk erasure
  • Command Center — per-customer view, bulk actions
  • Audit Log Viewer
  • Consent trends beyond 14 days
  • The dated Consent & Rights Record

Coming to the Shopify App Store

Submission is in progress. We won't fake an "Install now" button that goes nowhere — here's where things actually stand.

Shopify

Consenfy is going through Shopify's app review. Once approved, you'll install it directly from the Shopify App Store. Shopify has to separately approve Protected Customer Data access before the app can show some customer fields by name — that's their rule, not a Consenfy paywall.

Free plan on install. Pro is billed through Shopify at $7 USD / 30 days.

The parts merchants usually get wrong

In ordinary English, with citations. Not a substitute for the Gazette text or for a lawyer.

It almost certainly applies to you

There is no revenue, size, or order-volume threshold in the Act. S3(a) covers digital data collected in India, including paper you later type in. S3(b) reaches processing outside India when it serves people in India.

Six conditions for consent that counts

Free

No "accept or you can't browse" wall.

Specific

Not one box for analytics, ads and profiling together.

Informed

The notice was shown before they decided.

Unconditional

Not bundled inside T&C acceptance.

Unambiguous

Silence and scrolling are not a yes.

Affirmative

They acted on purpose. Pre-ticks fail.

There is no GDPR-style legitimate-interest test — S7 is a closed list. Taking the order, charging and shipping run on S7(a), so don't ask permission for those.

One real deadline, and it isn't thirty days

Only grievance has a number: respond within no more than 90 days Rule 14(3). Access, correction and erasure have no numeric deadline in the Rules — erasure is "upon receipt". Any tool printing a GDPR-style "30 days" against those is describing a different statute.

Penalties are maxima, not invoices

BreachSectionMay extend to
Reasonable security safeguardsS8(5)₹250 crore
Failure to notify a breachS8(6)₹200 crore
Children's-data obligationsS9₹200 crore
Significant Data Fiduciary dutiesS10₹150 crore
Any other provision — including consent and noticen/a₹50 crore

S33(2) requires the Board to weigh mitigation and how promptly you acted. Records are evidence you tried; they are not a shield on their own.

2023

The Act

Notice, consent, rights and penalties defined.

Now

Rules and the Board

DPDP Rules, 2025 and the Board are live. Breach intimation already applies.

Expected ~May 2027

Consent duties bite

Phased in by notification. The record you'll want then is the one you start keeping now.

What a store tool can't close

Consenfy covers consent on your storefront. Marketplace and quick-commerce checkouts aren't yours to collect for; WhatsApp and SMS lists built elsewhere are still your consent problem, plus India's DLT rules. Security, breach reporting and erasure follow the data across every system you hold it in. Anyone selling a banner as whole-business compliance is overselling it.

Straight answers

I already have a cookie banner. Is that enough?

Usually not. Most banners record a click without gating trackers, and most are GDPR tools whose categories don't map onto this Act. The harder gap is S6(10): an "accepted" flag with no notice version is weak proof.

Will turning off marketing break checkout?

It must not, and Consenfy locks essential processing on. Orders, payment, and delivery run on S7(a), not on cookie consent.

Do I need a Data Protection Officer?

A formal DPO is an S10 duty for a notified Significant Data Fiduciary. Almost every store instead needs a published contact person under S8(9) who can answer questions about processing. Those are different jobs.

Does Consenfy make my store compliant?

No. It can collect valid consent, enforce known trackers, keep evidence, and run a rights queue. It can't decide what is lawful for your business, write policies you can rely on without review, or take responsibility for the rest of your stack. You remain the Data Fiduciary.

What happens if I uninstall?

Compliance records live in your store's reserved namespace, inside your own Shopify store — not ours. Shopify's uninstall/redact webhooks are how the session data tied to your install is removed from our host. Deleting the app does not rewrite the Act.

Is this the same as a GDPR plugin?

No. DPDPA has one uniform category of personal data, no data-portability right, no legitimate-interest balancing test, and only one numeric grievance ceiling. An app that offers "portability" or "legitimate interest" as if they were Indian-law features is describing a different statute.