Securing your Shopify POS setup

Having a security strategy for your business helps keep your Shopify POS device, transactions, and customer data safe. This guide outlines best practices for POS security and tools for reacting to threats to your POS data, such as lost or stolen POS devices.

Protecting your Shopify POS device

To protect your Shopify POS devices from unauthorized access, use the following security settings built into iOS and Android devices:

  • Find my device: lets you track the location of your device if it's lost or stolen.
  • Remote wipe: lets you erase your device's data if it's lost or stolen.
  • Auto-lock: automatically locks the screen within a set time frame when the device isn't supervised by staff.

To make sure the screen lock on your device is secure, set a strong PIN. A strong PIN is composed of all different digits.

If a device is lost or stolen, then you can log the device out or remove it remotely from your Shopify admin.

If you manage large numbers of devices, then you can use MDM (Mobile Device Management) software to manage all of your devices simultaneously. You can use Apple Configurator for iOS devices or an Android recommended MDM for Android devices.

With most MDM configurations, you can manage the following security settings on all of your devices from one device:

  • Enforce passcode.
  • Lock and wipe a device.
  • Reset-clear the passcode.
  • Track device location.
  • Manage updates.

Learn more about Mobile Device Management.

Protecting your Shopify POS data

To protect your POS data, keep your iOS or Android device, and Shopify POS up to date. Apple and Google release patches for known security vulnerabilities in their operating system (OS) updates. Shopify POS updates also resolve bugs and security related vulnerabilities.

You can turn on the following automatic updates on your iOS device:

Most Android updates happen automatically, but you can manually check for system updates. You can also activate automatic app updates.

If you want to prevent instant system or app updates, then you can use an MDM (Mobile Device Management) software. Consider having a quick release plan for Apple and Android updates to make sure you're up to date with the latest features and security fixes.

Checkout security for Shopify POS

Checkout security for Shopify POS includes tap limits on payment cards and customizable payment options on Shopify POS that allow you to control what kind of transactions to accept.

Guidelines for tap limits

Tap limits are the maximum amount a customer can pay with their card using a tap function. Tap limits are determined by the bank that issues the card and are in place to protect you and your customers against fraud.

The following guidelines apply to tap limits:

  • Tap limits vary between card and region.
  • Some regions allow tapping a card and entering a PIN to approve higher value payments.
  • Tap limits might be higher or unlimited for mobile wallets such as Apple Pay, Google Pay, and Samsung Pay.
  • Tap to Pay on iPhone and Tap to Pay on Android have the same limits as card readers.
  • Tap limits are enforced by cards and the banks that issue them and not by Shopify Payments. Tap limits aren't configurable.

The Shopify card readers prompt customers to insert the card and enter their PIN as needed. For higher tap limits, encourage customers to pay with mobile wallets.

Customizable payment options

You can control the payment options for individual POS devices. For example, if your store accepts payment cards, then you can deactivate manual payment card entry as fraud mitigation. Learn more about managing payment options for an individual POS device.

Managing staff permissions

Keep your store settings and data safe by setting appropriate POS roles and permissions for each staff member. Roles and permissions determine how much access each staff member has to view data and perform actions within the POS app. You can also restrict POS staff from performing certain actions on the POS app without approval from another POS staff with appropriate permissions.

To keep your Shopify admin data secure, you can restrict POS staff from accessing your Shopify admin by adding POS only users from Settings > Users in your Shopify admin.

Shopify POS staff PIN security

You can create a 4 to 6 digit personal identification number (PIN) for each staff member to access Shopify POS. PINs can be generated randomly or set manually through Shopify POS or the Shopify admin.

For security reasons, staff must enter the correct PIN into Shopify POS in the following situations:

  • To log in. The PIN access is tied to specific locations and subscription plans.
  • When a checkout error occurs.
  • When the checkout is canceled.
  • When a tip is canceled.
  • When a POS Go device reboots to unlock before checking for software updates.

If staff forget their PIN, then authorized users can generate a new PIN in Shopify POS or the Shopify admin. PIN changes require the Manage Point of Sale staff permission.

Two-step authentication warnings in Shopify POS

If your store requires two-step authentication for all users or for the user who logged in to a POS device, then Shopify POS might display a warning dialog after the user enters their PIN. A persistent banner is also displayed in the overflow menu. Learn more about enforcing two-step authentication and setting up two-step authentication.

These warnings display only on POS devices where the user logged in before setting up two-step authentication. If the user has set up two-step authentication after their last login, then the POS login must still be repeated with a two-step authentication challenge.

To remove the warning dialog and banner, a user with permissions to log in to Shopify POS must log out of each affected POS device, and then immediately log back in and complete two-step authentication. This is a 1-time task for each affected device.

If you don't want Shopify POS devices to require two-step authentication, then update your two-step authentication enforcement settings. If two-step authentication is required for all users, then change the requirement to specific users, and then turn off the requirement for each user with POS login permissions. If two-step authentication is already required only for specific users, then turn off the requirement for any user account that was used to log in to an affected POS device.

Manage Nearby device log in

You can manage login requests for Shopify POS from nearby devices using Nearby device log in. The Allow nearby device log in setting is turned on by default in your Shopify admin.

To approve login requests, staff must have the POS device setup role.

You can also control which Login duration options staff can select when they approve a nearby device log in:

  • Today only: The login is valid for the current day only. This option is turned on by default.
  • Forever: The login doesn't expire. This option is hidden by default in Shopify POS. You can make this option available in your Shopify admin.

Steps:

  1. From your Shopify admin, go to Point of Sale > Settings.

  2. In the Customization section, click any of the customizable elements to open the POS editor.

  3. Click the Settings icon in the POS editor menu bar.

  4. In the Nearby device log in section, turn on or turn off Allow nearby device log in.

  5. Optional: Under Login duration options, tap View or Hide next to the Today only and Forever option.

  6. Click Save.

Monitoring your business using Shopify POS reports

You can monitor staff, product, and transaction activity to ensure compliance with your business protocols. The following POS report types are available in your Shopify admin:

  • Retail sales reports
  • Product and variant sales reports
  • Vendor sales report
  • Sales by staff member report
  • Total sales by POS location

Consider having a security incident reporting and response procedure that's suitable for your business needs.

Training staff on Shopify POS security

Train staff on POS security best practices, such as creating secure passwords and your businesses security incident reporting and response procedures. Regularly training staff on the importance of POS security helps keep your store's and customer's data secure.

Next steps

After you secure your Shopify POS setup, you can customize the Staff training checklist to prepare your staff to work with Shopify POS.