Who is liable for ADA violations on a Shopify store?
The brand is. Shopify provides the infrastructure, but ADA demand letters and lawsuits name the merchant, not the platform. The store owner is responsible for the accessibility of everything a customer encounters, including themes, apps, content, and custom code. Platform defenses do not transfer.
The platform does not absorb your risk
Shopify's terms place responsibility for legal compliance squarely on the merchant. That is not unusual; no commerce platform underwrites accessibility for its tenants. The platform ships accessible defaults in its checkout and core components, and it publishes guidance, but the storefront you actually operate is a stack of theme customizations, third-party apps, scripts, and merchandiser-uploaded content. Plaintiff firms know this. Their demand letters and filings name the brand whose site failed the user, because that is the party the ADA reaches: the operator of the place of public accommodation, not the software vendor behind it.
Themes and apps are your stack, and your exposure
Most ADA issues on Shopify stores come from the layers the merchant chose. A theme with broken heading structure, an app that injects an unlabeled chat widget, a mega menu that traps keyboard users, a checkout upsell that never receives focus: all of these are part of the store the merchant presents to the public. You cannot pass that exposure back to the theme developer or the app vendor in a demand letter. Their contracts disclaim it, and plaintiffs have no reason to chase them when the merchant is the named operator. Choosing the theme and the apps was the merchant's decision, and the risk travels with it.
Content counts as much as code
Even a technically clean theme produces an inaccessible store when the content is not maintained. Product images uploaded without alt text, promo banners with text baked into the image, color contrast broken by a campaign background, videos with no captions: these are merchant-side failures, updated daily by marketing and merchandising teams. Plaintiff scanning focuses on exactly these surfaces, because they are the most common and the most visible. A store can pass an automated scan of its template and still fail a real user test on its homepage, because the homepage changed this morning.
Headless does not change the answer, just the workload
Going headless on Shopify removes even the guardrails the platform provides, since the storefront markup is now entirely the merchant's. The legal answer stays the same: the operator is responsible. But the practical workload grows, because every component that the theme used to handle, from navigation announcements to focus management on route changes, has to be built and maintained by the merchant's team. Headless merchants who assume the accessibility story moved with the architecture are the ones who get surprised.
What this means for who fixes what
Treat accessibility as a merchant-owned program with three layers. First, vet themes and apps before install: run a scan and a keyboard pass on anything you add to the store. Second, control content: require alt text on uploads, set contrast rules for campaign creative, caption videos before publishing. Third, monitor production on a cadence, because a store that was compliant in January is not necessarily compliant now. The platform gave you the tools. The exposure is yours, and so is the fix.