Skip to content

WooCommerce vs Shopify: who owns your attribution data

On WooCommerce the order records sit in a database on hosting you choose, with source fields written onto each order. On Shopify they sit on Shopify's servers and reach you through an export and an API with limits. Neither gives you a finished attribution answer.

By , Founder & CEOPublished 4 min read

Run the numbers for your store: the free ad platform over-reporting checker.

WooCommerce keeps orders in a database on hosting you choose and, with Order Attribution switched on, writes each order's source onto the order. Shopify keeps orders on its servers, exposes an order's first and last visit through its API, and lists no UTM column in its documented order export. An outside app reads only the last 60 days of Shopify orders unless Shopify approves more. So "ownership" here means who can read the raw fields and which fields exist, not who holds legal title.

What does each platform record about where an order came from?

With WooCommerce's Order Attribution feature enabled, the store saves the referring source, UTM parameters, device type and session page views as order metadata. The documentation says the feature follows a last-click model, that the data exists only for orders placed while the feature is on, and that its cookies expire with each session, so it can't follow a visitor across sessions.

Shopify's Admin API describes an order's journey through the store: a first visit and a last visit, each with landing page, referrer, source and UTM parameters. Days to conversion run from the first session since the last order, or from the first session within a 30 day attribution window if more than 30 days have passed since the last order.

Both records say who sent the buyer. Neither estimates what caused the sale.

Who can read the raw orders, and how?

On WooCommerce, orders sit in tables in your WordPress database. Since WooCommerce 8.2 new installs use High-Performance Order Storage, which moves order data into four custom order tables, and the documentation's own test steps delete the attribution fields from order metadata tables, which shows where they live. An administrator can also generate REST API keys with read access only, and the API pages its results at 10 items by default.

On Shopify you work through the admin or the API. The Orders page exports a CSV whose documented columns include a Source field described as the order's source, for example web, draft order or POS, and no UTM, referrer or landing-page column. Apps reading through the API get the last 60 days of orders unless Shopify approves the read_all_orders scope. Fields with a name, address, phone or email fall under Shopify's level 2 protected customer data, which can add a data protection review for public apps. In data-protection terms, Shopify's addendum has the merchant acting as data controller and Shopify as data processor for customer personal data, except for the services in its Appendix E.

What does that change for measurement?

This part is reasoning from the documentation, not a measurement.

  • On WooCommerce you can join orders to GA4 by transaction ID through the database, the REST API or an export, without anyone's approval. Running it is on you or your host: hosting, backups and the consent setup.
  • On Shopify the source per order comes through the API or an app, not the CSV, and a tool that can only see 60 days can't rebuild last year's attribution from orders alone.
  • On both, the order's own source is a first-party record you can check GA4 against. It isn't evidence of cause.

How do you check what your own orders record?

Take the orders from your last email send or paid campaign, where you know the link that was clicked.

  1. WooCommerce: open each order and read the Order attribution box (origin, source type, UTM campaign, device type). In the Orders table, read the origin column.
  2. Shopify: ask your developer or app to query the order's customerJourneySummary in the Admin API and compare firstVisit and lastVisit with the link you used. Check the ready field first: the API marks whether the attributed sessions have been created yet.
  3. Count the misses: orders that show Direct, Unknown or blank.

Pass: the recorded source names the campaign link with its UTM parameters intact. Fail: Direct or blank for orders you know came from a tagged link, which points to a stripped UTM, a blocked cookie, or the feature being off on that date. Then reconcile the store's order count with GA4 for one closed week, as in the tracking post.

Sources, 30 September 2026: Order Attribution Tracking (WooCommerce, 2026); High-Performance Order Storage (WooCommerce, 2026); WooCommerce REST API documentation (WooCommerce, 2026); Access scopes (Shopify, 2026); CustomerJourneySummary (Shopify, 2026); CustomerVisit (Shopify, 2026); Exporting orders (Shopify Help Center, 2026); Work with protected customer data (Shopify, 2026); Data Processing Addendum (Shopify, 2026).

Frequently asked questions

  • Does WooCommerce store UTM parameters on each order?
    Yes, when its Order Attribution feature is enabled. It saves the referring source, UTM parameters, device type and session page views as order metadata, follows a last-click model, and only covers orders placed while the feature is on.
  • Can I export UTM parameters from Shopify orders?
    Not from the standard CSV: its documented columns include Source (web, draft order, POS) but no UTM columns. The Admin API exposes UTM parameters on an order's first and last visit, and apps read only the last 60 days of orders unless Shopify approves read_all_orders.
  • Who is the data controller for my store's customer data?
    Shopify's data processing addendum has the merchant acting as data controller and Shopify as data processor for customer personal data, except for the services in its Appendix E. On self-hosted WooCommerce you run the software, so check the agreements with your host and plugin vendors.

Go deeper: Causal attribution, explained.

Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.

Keep reading

Terms in this article

Browse the full glossary

Your platforms guess.
We run the math.

Upload a GA4 export and see what each channel caused, next to last-click, in 1–2 minutes. The read is yours to keep.

Free, in your browser: your file is not uploaded. The full read is €99, refundable within 30 days. Prices exclude VAT.
Or book a 30-min call.