AccountCraft Journal
Launch GDPR Ready Shopify B2B Accounts Without Code Using AccountCraft
Build GDPR ready Shopify B2B accounts with Customer Account and Privacy APIs. Use a practical setup in 5 steps or skip extension code with AccountCraft.

You can build editable, GDPR-ready customer account pages on Shopify today using the Customer Account API, metafields, and the Customer Privacy API, and you do not need a custom storefront to do it. New Customer Accounts support profile blocks and full-page extensions, metafields let customers view and change their own data, and the collect_buyer_consent capability handles GDPR consent properly. The fastest route for most merchants is pairing these native tools with a no-code builder like AccountCraft.
TL;DR:
- Using metafields and the Customer Privacy API, merchants can enable customers to view, edit, and withdraw consent directly on account pages without custom storefronts.
- Profile blocks are ideal for quick, in-profile edits, while full-page extensions suit content-heavy features like wishlists or loyalty dashboards, and must be kept separate.
- Proper configuration of access scopes, including
customer_read_customersandcustomer_write_customers, is essential to ensure metafields are accessible and writable, preventing silent failures.- Compliance requires building a consent dashboard that respects regional GDPR rules by checking banners, recording decisions in Shopify’s system, and ensuring removing or changing consent is effortless.
- Tools like AccountCraft simplify setup and management via visual builders, avoiding code maintenance while ensuring data remains within Shopify APIs and GDPR policies are upheld.
Table of Contents
- What You Can Build: Profile Blocks vs Full-Page Extensions
- Implementation Checklist: Metafields, Scopes, Targets, and Capabilities
- GDPR in Accounts: Rights, UI Patterns, and the Customer Privacy API
- Design and QA: Keep Account UI Native, Accessible, and Reliable
- Author Perspective and What Merchants Actually Need
- Step-by-Step: Setting Up New Customer Accounts
- Testing and Debugging Customer Account Extensions
- Security Beyond GDPR: Access Controls and Data Handling
- Our Take: Build for the Customer, Not Just the Checklist
- Try AccountCraft for Editable, Compliant Account Pages
- FAQ
- Sources
What You Can Build: Profile Blocks vs Full-Page Extensions
Shopify’s customer account UI extensions give you two main ways to extend the native account experience: profile blocks and full-page extensions. Each fits a different kind of feature, and picking the wrong one leads to clutter or a page that feels disconnected from the rest of the account.
Profile blocks render inline on the default profile page and work best for small, contextual additions:
- An editable nickname or display name field tied to a customer metafield.
- Communication preference toggles customers can flip without leaving the profile page.
- Short account-level announcements or loyalty tier badges.
Full-page extensions get their own route and content area, which suits content-rich features that need room to breathe:
- A wishlist page listing saved products with remove and add-to-cart actions.
- A loyalty or rewards dashboard showing points, tiers, and redemption history.
- A dedicated subscriptions or returns management page.
The decision rule is simple: if the feature is a quick edit someone makes while already managing their profile, build a block. If it is a destination customers navigate to on its own, build a full-page extension. Shopify’s own guidance recommends keeping custom content contextual to the native account UI rather than bolting on unrelated functionality, which keeps the account section feeling like one coherent product instead of a patchwork.
Implementation Checklist: Metafields, Scopes, Targets, and Capabilities
Building editable account fields and consent management requires a handful of configuration steps that are easy to miss on a first pass. Here is the order that avoids most debugging headaches:
- Define your metafields in
shopify.app.tomlusing declarative custom data definitions, for example[customer.metafields.app.nickname], and setaccess.customer_account = "read_write"so the field is both visible and writable from the account extension, per Shopify’s metafield documentation. - Request Level 1 protected customer data access in your app configuration, and include the
customer_read_customersandcustomer_write_customersaccess scopes, without which metafield reads and writes will silently fail. - Choose your extension targets deliberately: use
customer-account.profile.block.renderfor inline blocks andcustomer-account.page.renderfor standalone pages. Keep the two in separate extensions, since a full-page target cannot coexist with other targets in the same extension. - Enable the right capabilities in
shopify.extension.toml, includingapi_accessandnetwork_accessfor data fetching, andcollect_buyer_consentif your extension will touch consent state, following the capabilities reference. - Call
applyTrackingConsentChangewhenever a customer updates their consent preferences, and persist the change through Shopify-managed state rather than a separate database.
On the data layer, fetch customer metafields through the Customer Account API and write updates with the metafieldsSet mutation. Always check the userErrors array on the response before assuming a save succeeded, and show a loading state while the async request resolves so customers do not submit the same edit twice.
Pro Tip: Build and test your full-page and block extensions as separate projects from day one. Retrofitting a block extension into a full-page one later means rebuilding most of the target configuration.
GDPR in Accounts: Rights, UI Patterns, and the Customer Privacy API
GDPR gives customers specific rights that your account pages need to support directly, not just mention in a privacy policy. The right to access and the right to rectification under Article 16 mean customers should be able to see and correct their own data without emailing support, and the right to withdraw consent under Article 7 should be just as easy as giving it in the first place.
Controllers must respond to rectification and access requests without undue delay, and at most within one month of receiving them, with a possible two-month extension for complex cases. An editable account page that lets customers fix their own data removes most of that burden before a request is even filed.
On the technical side, Shopify’s Customer Privacy API exposes shopify.customerPrivacy state, including visitorConsent, shouldShowBanner, and saleOfDataRegion, and you save updates through applyTrackingConsentChange.
A few UI patterns make this work in practice:
- Build a consent dashboard inside the account section rather than hiding consent toggles in a settings submenu.
- Check
shouldShowBannerbefore deciding whether to surface a consent banner, so customers who already decided are not asked again. - Record every consent decision in Shopify-managed state instead of a custom table, so it stays in sync with checkout and marketing consent elsewhere on the store.
Keep withdrawal exactly as visible and as easy as opting in. A consent toggle that is one click to enable and three clicks to disable is not actually compliant in spirit, even if it technically works.
Design and QA: Keep Account UI Native, Accessible, and Reliable
Custom account pages fail most often not because of broken code but because they look and behave like a separate app bolted onto Shopify. A few rules keep that from happening:
- Use Polaris web components like page, section, card, and button so your custom blocks inherit the same spacing, typography, and interaction patterns as the native account UI.
- Keep profile block content directly relevant to profile management. A wishlist does not belong on the main profile page; it belongs on its own route.
- Guard against missing or still-loading data, especially on order-specific pages where order details can arrive after the rest of the page has rendered.
- Test direct linking to full-page extensions, not just in-app navigation, since customers may bookmark or share account URLs.
Pro Tip: Test your consent dashboard and any region-specific banners from an EU-based test account as well as a non-EU one; saleOfDataRegion behavior differs by region and is easy to miss if you only test from one location.
Localization deserves the same testing rigor as functionality. A metafield label that works in English can overflow or truncate in German or French, and a consent banner that only shows correctly in one locale is a compliance gap, not a cosmetic bug.
Author Perspective and What Merchants Actually Need
Most merchants do not need a custom-built extension pipeline to solve this problem. AccountCraft transforms Shopify’s New Customer Accounts into a block-based builder, letting you create personalized account pages without writing code or touching your theme.
Its Block Builder lets you add components like wishlists and custom data fields the same way you would arrange sections in a theme editor, and consent management is built in rather than layered on top. Because it works through Shopify’s own APIs, customer data stays inside Shopify rather than syncing to an external database, which helps with data protection and GDPR compliance.
For merchants who want the functionality described above without maintaining extension code themselves, that combination of no theme changes, native data storage, and built-in consent handling covers much of what a custom build would require.
Step-by-Step: Setting Up New Customer Accounts
Getting New Customer Accounts running on a Shopify store starts in the admin, not in code. First, switch your store’s customer accounts setting from Classic to New Customer Accounts under Settings, then Customer accounts, which changes the login and account experience for every customer going forward.
Once that is active, the next step is deciding which extensions you actually need. If you are building with Shopify CLI, scaffold a new customer account UI extension with shopify app generate extension, selecting the customer account extension type, which creates the boilerplate for either a block or full-page target.
From there, declare your metafields and access scopes in shopify.app.toml, set the capabilities your extension needs in shopify.extension.toml, and deploy a development version to a test store so you can see the block or page rendering inside a real account. Shopify’s CLI gives you a preview URL that reflects changes without a full redeploy each time.
If writing and maintaining that extension code is not something your team wants to take on, a builder like AccountCraft handles the same configuration (metafields, targets, capabilities) through a visual interface, which is worth considering before committing engineering time to a custom build.
Finally, test the full account flow end to end: registration, login, profile editing, and any full-page routes you have added, on both desktop and mobile, before pushing to your live store.

Testing and Debugging Customer Account Extensions
Customer account extensions fail in a few predictable ways, and most of them show up during testing rather than in production if you check for them early.
The most common issue is a metafield that appears readable but will not save, which almost always traces back to a missing or incorrectly scoped access definition in shopify.app.toml. Double-check that access.customer_account is set to read_write, not just read, and that your app has both customer_read_customers and customer_write_customers scopes approved.
The second common failure is a full-page extension that renders blank or throws a target conflict error, which typically means a full-page target was declared alongside a block target in the same extension file. Since full-page targets cannot coexist with other targets in the same extension, splitting them into separate extension projects early avoids this.
For consent-related extensions, test with collect_buyer_consent both enabled and disabled in your extension’s capabilities to confirm applyTrackingConsentChange calls fail gracefully when the capability is missing, rather than throwing an unhandled error that breaks the whole page.
Use Shopify CLI’s local preview and the browser’s network tab together: the preview shows you the rendered UI, and the network tab shows whether your GraphQL mutations are actually reaching the Customer Account API or failing silently. A userErrors array that is not being checked is a frequent source of “it looks like it saved but didn’t” bugs.
Security Beyond GDPR: Access Controls and Data Handling
GDPR compliance covers consent and data subject rights, but it does not cover everything you need to think about when customers can edit their own account data directly.
Access scopes should be requested at the minimum level your extension actually needs. Requesting customer_write_customers when your extension only reads data expands your attack surface for no functional benefit, and Shopify’s app review process will flag scope requests that do not match your extension’s stated purpose.
Validate every write server-side as well as client-side. A metafield write exposed through metafieldsSet should never trust unvalidated input straight from a form field, particularly for anything that feeds into pricing, loyalty point balances, or other logic elsewhere in your store.
Merchants running several apps that touch customer data should also audit which apps have write access to customer records at all, since each additional app with broad scopes is another potential point of failure. For a broader look at hardening a Shopify store against data and account risks, this roundup of Shopify security plugins covers tools merchants use alongside their own account customization work.
Finally, log consent and data-edit events separately from your general app logs. If a customer later disputes what they consented to or when they updated a field, having a clean, queryable record of consent and edit events saves far more time than reconstructing it from general application logs after the fact.

Our Take: Build for the Customer, Not Just the Checklist
The industry conversation around Shopify B2B customer accounts tends to treat GDPR consent as a checkbox to clear and editable fields as a nice-to-have. Both framings undersell what is actually at stake. A customer who can fix their own shipping address or update their communication preferences without emailing support is a customer who stays. Consent management that is genuinely easy to withdraw, not just technically compliant, builds more trust than any amount of privacy-policy language.
Where most merchants go wrong is treating the account page as an afterthought bolted onto checkout, rather than a retention tool in its own right. The data stays in Shopify either way. The question is whether customers can actually use it.
If you take one thing from this guide, prioritize the consent dashboard and the editable profile fields before you build anything flashier like loyalty tiers or wishlists. Compliance and basic account control are the foundation; everything else is decoration on top of it.
— Barikreativa
Try AccountCraft for Editable, Compliant Account Pages
If everything above sounds like more configuration than your team has time for, a tool like ours can help close that gap. We provide a visual Block Builder that offers editable fields, wishlists, and consent management as described in this guide, without requiring extension code or TOML files.

Customer data stays inside Shopify throughout, since the tool works entirely through Shopify’s own Customer Account and Customer Privacy APIs rather than an external system. Start on our Free plan to see the builder on your own store, and move to Pro or Plus as your account pages grow.
FAQ
What are Shopify’s New Customer Accounts?
New Customer Accounts are Shopify’s current account system, which supports profile blocks and full-page extensions that merchants can use to add editable fields, wishlists, or dashboards to the customer account experience. They replace the older Classic customer accounts and are configured directly in the Shopify admin.
Which Shopify app scopes do I need for editable customer data?
You need customer_read_customers and customer_write_customers access scopes along with Level 1 protected customer data access to read and write customer metafields through the Customer Account API. Without both scopes approved, metafield writes will fail even if the field itself is correctly defined.
How do I manage GDPR consent in a Shopify account page?
You read current consent status through shopify.customerPrivacy properties like visitorConsent and shouldShowBanner, then save any changes with applyTrackingConsentChange from the Customer Privacy API. Your extension also needs the collect_buyer_consent capability enabled to make those calls.
Can I add a wishlist or loyalty dashboard without custom code?
Yes. AccountCraft’s Block Builder lets you add components like wishlists and custom profile fields to your Shopify account pages without writing extension code or modifying your theme, while keeping the underlying data in Shopify through the same official APIs.
How long do I have to respond to a customer data request?
Under GDPR, you must respond to access or rectification requests without undue delay and at most within one month, with a possible two-month extension for complex requests. Letting customers edit their own data directly in their account reduces how often these formal requests come in at all.