Industries
Can an e-commerce store sell its data to AI companies?
On this page
- What does an online store keep that AI buyers ask for?
- What does one order leave behind?
- Which buyers say they want e-commerce data?
- Is licensing our customer data a “sale” under California law?
- What does our own privacy policy have to do with it?
- Can a provider pull our data through a Shopify app?
- What could an online store’s data be worth?
- How does a store owner start?
An e-commerce store can license operational history when orders, support tickets and returns preserve how the business worked. As of October 2026, twelve providers name store records, platforms or the industry; customer fields affect the scope.
What does an online store keep that AI buyers ask for?
A record of what people bought, asked about and sent back, tied to how the store described, stocked and shipped it. Polyshares’ Shopify guide (checked September 2026) says “Each Shopify order links a customer to the products and variants bought, discounts, shipping, fulfillment status and payment”, and that over years this is “a detailed record of real buying behavior, including repeat purchases and returns”. Miro Advisory describes the e-commerce workflow as “Order through fulfillment, support, return or retention”.
| Record | Where it usually lives | Customers’ personal data in it |
|---|---|---|
| Orders, refunds and transactions | Shopify or another store platform | Names, email, phone, billing and shipping addresses, order notes |
| Product catalog and inventory | Store platform, inventory or ERP tool | Little or none |
| Support tickets | Gorgias or Zendesk. Polyshares says Gorgias tickets “center on orders: returns, shipping delays, sizing questions and refunds” | Customers’ own words, often with order details |
| Returns and exchanges | A returns app or the store platform | Names, addresses, reasons for return |
| Supplier and 3PL correspondence | Email, purchase orders, spreadsheets | Suppliers’ staff, as business contacts |
| Email and SMS campaigns | A marketing platform | Subscriber lists and engagement |
Orders, tickets and returns can carry customer identifiers and free text.
What does one order leave behind?
A chain of linked records, most of them naming the customer. For example, a dress ordered from a hypothetical 25-person apparel store on Shopify:
- The checkout. The customer enters her name, email, phone and address, and uses a discount code. Leaves: an order, a customer record, a transaction.
- Fulfillment. The warehouse picks and ships it; tracking goes out by email. Leaves: a fulfillment event, a shipping label.
- The question. The parcel stalls in transit and she writes in. Leaves: a support ticket with her words and the order number.
- The return. The dress runs small; she exchanges it for another size through the returns app. Leaves: a return record with a reason, a second order.
- Afterward. She gets a review request and joins the email list. Leaves: a review, a subscriber record.
Steps 3 and 4 record what went wrong, how the store answered and what the customer did next. Her identity runs through every step, so the privacy questions below decide the scope.
Which buyers say they want e-commerce data?
Twelve have an explicit match as of October 2026. Applied to all 25 providers, the listing rule accepts an own-page reference to store records, an e-commerce platform or the e-commerce/retail industry. Ten name records, systems or a collection from a store; Replay and Scale AI name the industry only. That last category does not establish demand for a particular order table or catalog.
| Provider | Type | What its pages say |
|---|---|---|
| Avelence | Introducer; buys no data | Shopify among the tools it names; “Commerce and retail” on its profile form |
| Corpus | Licenses directly | Shopify under Customer, sales & finance, a store-system match |
| FileYield | Listing marketplace | A Retail/Consumer category including “purchase histories, loyalty program records, cart abandonment patterns” |
| idler | Licenses directly | ShelfLife, “A digital twin of a real e-commerce company” built from its operational data over the past decade |
| Mercor | Licenses directly | Retail & E-commerce: “Order records, inventory logs, listings” |
| Miro Advisory | Introducer | “E-commerce & retail” among highlighted industries; “E-commerce and fulfillment” among systems |
| Polyshares | Licenses directly | Export guides for Shopify and Gorgias |
| Replay | Licenses directly | Industry-only match: e-commerce among the industries it shows; no store platform or order table named there |
| Scale AI | Licenses directly | Industry-only match: DTC E-commerce and Retail & Consumer among its industries; no store platform or order table named there |
| Sell My Business Data | Introducer | Shopify, and “Orders, invoices, fulfillment events, customer history, logistics data and supplier information” |
| Telegraph Lab (affiliated with Data Licensing Report) | Licenses directly | “Retail & ecommerce” among target industries; Shopify among the operating-record sources |
| Troveo | Licensing agent | “Retail & E-commerce” snapshots, including a “Fashion E-commerce Platform”; Shopify among the systems it lists |
idler’s ShelfLife page does not say how customer data was handled; ask any provider which customer fields it removes, and where.
Is licensing our customer data a “sale” under California law?
It can be, if the store meets one of the California Consumer Privacy Act’s thresholds. The act defines a sale as “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating” a consumer’s personal information to a third party “for monetary or other valuable consideration” (Civil Code §1798.140(ad)).
- Who it covers. A for-profit business that does business in California and has gross annual revenue over $25 million, adjusted to $26,625,000 from January 1, 2025; or that “annually buys, sells, or shares the personal information of 100,000 or more consumers or households”; or that earns half its revenue from selling or sharing it. A consumer is a California resident, so the count is of California customers.
- What follows if it covers you. Consumers can opt out of sale or sharing. Covered businesses generally must provide an opt-out link; the Attorney General describes exceptions, including honoring opt-out preference signals.
- De-identified data. Information that “cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer” is de-identified only if the business also takes reasonable measures, publicly commits not to re-identify it and binds recipients by contract (§1798.140(m)). Order files keep addresses, purchase dates and order numbers that can point back to a person; how de-identification works covers what has to go.
Texas defines a sale in similar terms; its version and thresholds are on the legal page.
What does our own privacy policy have to do with it?
It records what customers were told, and the California act holds a covered business to it. Its notice rule requires a business to say “whether that information is sold or shared”, and bars using personal information “for additional purposes that are incompatible with the disclosed purpose” without new notice (§1798.100(a)(1)).
Three things to check before customer records go into scope:
- The policy’s sale and sharing section. If it says the store does not sell personal information, a license of identifiable order data would not match what customers were told.
- Shopify’s opt-out page. Shopify offers a data-sharing opt-out page, “a dedicated page in your online store” where visitors can opt out of the sale or sharing of their data. If the store has one, ask how a provider would honor those opt-outs.
- Policy changes. Frankfurt Kurnit’s October 1, 2026 commentary says “For data already collected, companies are bound by prior commitments unless they obtain consent.” The legal page adds the FTC’s warning on quiet changes.
Can a provider pull our data through a Shopify app?
Only within Shopify’s API terms, which restrict AI training on store data and passing it on to third parties. Shopify’s API License and Terms of Use, updated February 27, 2026, say app developers may not use information derived from the API or Merchant Data “to create, develop, train, fine tune, or improve any machine learning or artificial intelligence systems”, except with Shopify’s prior written consent or, for one store’s Merchant Data, “the relevant Merchant’s consent” (section 2.3.24). The same terms bar transferring data received from Shopify “(including anonymous, aggregate or derived data)” to a third party unless needed for the app’s service or “expressly authorized by the Merchant or Shopify” (6.2.8).
Shopify’s developer rules add two limits. Apps reach orders “created within the last 60 days” by default, and older orders need the read_all_orders scope, which requires Shopify’s approval. Apps handling protected customer data must “respect and apply customer decisions to opt out of any data sharing such as a ‘data sale’”. For an app or connector, identify the consent route and data-transfer permission in the proposal. An admin CSV export changes the extraction method; it does not settle the rights in customer data or the proposed use.
What could an online store’s data be worth?
Telegraph Lab, which is commercially affiliated with Data Licensing Report (how the site makes money), has described to Data Licensing Report one online-retailer transaction it handled: three buyers were approached, two made offers, and the owner received $300,000 within two weeks of the first conversation. It is one transaction, not an average or an estimate, and the description does not say which records were licensed or how customer data was handled.
The other figures are providers’ own published ranges, as of October 2026, not offers: Polyshares “$100K to $2M, and above for large records”; Replay $10K–$100K for 20 to 50 employees and $100K–$1M for 50 to 250 (Replay); Scale AI “$10K–$1M+ illustrative value per data partnership”; and Telegraph Lab $100K–$4M, subject to data review and agreed terms. The company-value guide compares those ranges. For a store, years of orders joined to tickets and returns are what the inventory should show.
How does a store owner start?
With exports the owner makes, counted before anyone outside sees them.
- List the systems. Store platform, helpdesk, returns app, email marketing, 3PL portal and supplier email, each with its oldest record.
- Export orders and products from Shopify. Shopify emails date-range order exports, and the order file includes Email, Phone, Billing Name, Shipping Name, both addresses and Notes (Shopify).
- Export support tickets. Zendesk’s CSV export leaves out “ticket comments, or ticket descriptions”; its JSON export normally keeps comments but leaves them out when a ticket exceeds 1 MB. These built-in exports are unavailable on Team plans, although the API is available on all plans. Polyshares’ guide says Gorgias message exports cover only the most recent 30 days of the selected period.
- Count them. The free sample tool reads CSV files in your browser, counts rows and dates, recognizes Zendesk ticket headers, and replaces detected contact details. Shopify files can contain multiple rows per order; count unique order numbers separately. Check name and note columns yourself and drop any you are unsure of. Nothing is uploaded unless you choose to.
- Settle the customer-data question. With your privacy policy and the California thresholds above, decide whether identifiable order data is in, out or in only after de-identification.
- Apply. The application needs no files; state the years of orders and whether customer fields are in scope.
Which systems hold this industry's records?
Providers named on this page
Get offers
Find the next step for your company’s data.
- No records or exports needed to apply
- Free for businesses
- Your company profile comes to our team for review