Shopify partner account closed without any fault

I’m looking for insight from other Shopify Partners who may have experienced something similar.

I have been a Shopify developer for several years and have worked on a large number of Shopify stores. A few months ago, my Partner account became the subject of a security investigation. Shopify informed me that an obfuscated payment skimmer had been detected and requested incident reports, forensic analysis, root-cause information, and impact assessments.

I repeatedly explained that I did not knowingly create, deploy, or distribute any payment skimmer and cooperated with the investigation to the best of my ability. However, I was unable to provide the level of forensic evidence Shopify requested because I did not have access to enterprise-level forensic tools or investigators.

Recently, Shopify informed me that:

* My Partner account will remain closed.

* My apps have been delisted and merchants have been asked to migrate away from them.

* I am prohibited from creating new Partner accounts, apps, or services on the platform.

* I may submit an appeal.

My question for the community is:

Has anyone experienced a similar Partner Governance enforcement action and successfully appealed it? If so, what type of information or context was most helpful during the appeal process?

I’m not asking anyone to review Shopify’s decision. I’m simply trying to understand whether there are examples of successful appeals and what Shopify generally looks for when reviewing them.

Can someone please advise whether it’s okay to create a new Shopify account using my passport, considering I submitted my National ID (NID) for verification on my previous account?

I’m not trying to bypass anything—I just want to understand whether using a different government-issued ID for identity verification is allowed after my previous account was closed. Has anyone been in a similar situation or received guidance from Shopify on this?

Thank you.

That sucks, and I’m sorry that happened. Did Shopify give you any information on how they concluded your account was responsible? It sounds like it came out of nowhere.

No, they didn’t. In fact, they’re asking how my account was allegedly involved, which is incredibly frustrating because I never intentionally did anything like this.

This account was connected to over 500 stores throughout more than four years of work, and I was never flagged for anything remotely similar. I’ve always focused on helping merchants and building legitimate projects.

Honestly, I don’t even know what to say anymore. It feels like my dream is being taken away. I had apps, clients, and years of work invested in this account, and now I’m being asked to explain something I never knowingly did.

Hi @Shipo-studio,

I am so sorry you are going through this. To be completely honest, winning an appeal for a security ban involving a payment skimmer is extremely difficult. Shopify protects its checkout process very strictly.

If you did not write the bad code, Shopify will assume your developer account was hacked or a third-party code package you used was infected. When they ask for an investigation, simply saying “I did not do it” does not help them. They need to know exactly how the bad code got in.

For your appeal, you do not need expensive enterprise tools. You just need to show a clear paper trail. Check your own computer for malware. Review your code commit history to see exactly when and where the bad code was added. Look at anyone else who had access to your apps or API keys.

To have any chance at a successful appeal, you must show Shopify exactly how the breach happened and outline the strict new security steps you have put in place to prevent it from ever happening again. Keep your appeal calm and focused purely on the facts. Hang in there, and good luck!

Yes, I have been trying for many days. I submitted a report prepared with the help of a professional, but they kept asking for more information—when it happened, which stores were affected, who had access to my accounts, WhatsApp conversations showing when I granted access, what work was performed, and even scans of my app code.

I provided everything I could. I reviewed the code they shared and couldn’t find it in any of the stores I had worked on. Since I no longer had access to those stores, I could only inspect the storefront code. Despite all of this, they were still not satisfied.

At that point, I didn’t know what else I could provide because I genuinely never did anything like this. The frustration became overwhelming, and I told them that if they truly believed I had done something wrong, they could delete the account because I had no additional evidence left to give. I also mentioned that I would move on and use another Partner account. After that, they took this action.

I am so sorry you were pushed to that breaking point; the frustration of being unheard is incredibly draining.

For advice, please avoid trying to open a new account with any of your previous details like your IP, ID, or bank info right now, as Shopify’s systems will likely flag and ban it instantly. Take some time to step away from the stress and perhaps focus on private development work or consulting where you don’t have to rely on the Partner dashboard for a while.

Hope this helps.

Thank you,i really appreciate :folded_hands:t2:
I am thinking to create another account using my passport and new Gmail account.
I don’t know else what to do.

Hi everyone,

I am writing this out of sheer frustration and confusion. My Shopify Partner account was suddenly put under review by the Ecosystem Governance and Risk team, and I am completely stuck.

Like many others I’ve read about here, my entire account has been locked down. My payouts are completely paused, and my income is frozen while this review is pending. I am incredibly stressed because I have clients relying on me, and my active earnings are just sitting there.

Here are the details of my situation:

  • Account Type: I am a Shopify partner working with developer tools and client stores.
  • Current Status: My Partner Dashboard shows a warning banner, and my payouts have been frozen without any clear timeline.
  • The Notification: I received an email stating my account is under review, but it did not give a specific reason or assign a clear ticket number.

I have already responded to the initial notification email with my clean details, and I have stopped bumping the thread to ensure I do not lose my place in the queue. However, I have not received a single update or human response yet. Regular support chat advisors tell me they cannot see this queue and can only forward it to the internal team.

Has anyone else dealt with this specific type of block recently? How long did it actually take for a human reviewer to get back to you and release your payouts?

If any Shopify Community Moderators or Ecosystem Governance team members are reading this, please could you help look into my case or escalate it? This is severely impacting my business and my livelihood.

Thank you to anyone who can offer advice or help.


Hello there @Shipo-studio I’m so sorry that you have experienced this.
Partner governance actions like this are normally subject to very close review particularly when a security flag is involved. From my experience in dealing with merchants, apeals are more likely to be successful if you have independent third party validation such as a security audit report, a clean code review from a recognized company, or hosting level logs that show there are no unauthorized injection points. Even in the absence of enterprise forensics, a well-documented timeline of changes, access logs for the app, and a history of re-deployments can potentially illuminate motivation and identify lapses in the original analysis.

Hi @Shipo-studio .

Really difficult situation, and it is clear you are handling it professionally.

For your appeal, these are the things that tend to carry the most weight.

Write a clear timeline of everything. When you last accessed each store, what changes were made, and whether anyone else had access to your code or deployment pipeline.

Investigate whether any third party tools or dependencies you use could have been compromised. Supply chain attacks are very common, and Shopify reviewers understand this.

Get a freelance cybersecurity professional to review your code and confirm they found no evidence of anything intentional. It does not need to be enterprise level to carry weight.

Include references from merchants you have worked with who can speak to your integrity and professionalism.

Keep the appeal factual, detailed, and professional throughout. Hope you get a fair hearing!

Hi,
Yeah this really frustrating :disappointed_face: Any update?

Thank you so much for the information.

After Shopify closed my account, I submitted an appeal, but it’s been weeks and I still haven’t received a response.

Following their instructions, I hired a cybersecurity professional and provided everything they requested, including details of who had access to my account, our communications, when I granted access, a review of my app code, and information about the client projects I worked on. Unfortunately, none of it seemed to satisfy them. They continued requesting additional evidence, such as a hard drive analysis and a forensic incident report, and I’m still not sure whether they would even accept it.

What has been most difficult is that they keep asking me to acknowledge that I carried out actions that I never did. I’ve been using this account for five years and have worked with more than 1,000 Shopify stores during that time. I have never intentionally engaged in the activity they are accusing me of.

Can someone please advise whether it’s okay to create a new Shopify account using my passport, considering I submitted my National ID (NID) for verification on my previous account?

I’m not trying to bypass anything—I just want to understand whether using a different government-issued ID for identity verification is allowed after my previous account was closed. Has anyone been in a similar situation or received guidance from Shopify on this?