The FTC still expects your tiny shop to protect customer data. A three-person store on Shopify is not exempt from basic care because you are small. The Federal Trade Commission’s “Protecting Personal Information: A Guide for Business” is written in that tone on purpose: know what you have, keep only what you need, lock it, toss it securely, and have a plan if it leaks. You do not need a security theater budget. You need not to leave export CSVs on a laptop that also streams movies.
Customer data is names, emails, addresses, payment tokens, health notes if you take any, ID scans you should not have kept, and the message history in your shop app. If you would be embarrassed to tape it to the mailbox, it belongs in the “protect” pile. The Guide is defensive and practical. It is not a hacking tutorial. Follow it that way.
Customer data is an inventory problem
Map the places information lives: email, cart software, accounting, a spreadsheet, a phone full of photos of packing slips, a VA’s laptop, a leftover SaaS trial. The FTC starts with knowing what you have. Most leaks in a tiny shop are not genius attacks. They are a stolen bag, a reused password, or a file you emailed to yourself.
Keep only what you need to fill, bill, and support. If a launch is over, export what tax law requires and delete the rest from tools you no longer use. SaaS subscription creep is also copy creep. Close the extra copies. Payment card data has extra rules; use a processor and do not store card numbers in a notes app. That is not optional cleverness. That is the point of a processor.
Locks that a small shop can actually keep
- Unique passwords and a password manager. Reuse is how one breach becomes five.
- Multi-factor authentication on email, bank, and the store. Email is the keys to reset everything else.
- Device lock screens and full-disk encryption that modern laptops already offer. Turn them on.
- A separate user account for the VA with only the permissions they need. When they leave, revoke the same day.
- Backups you can restore, stored where a house fire or a stolen backpack does not take the only copy.
Physical paper still counts. A box of order printouts in the garage is customer data. Shred what you do not need. Publication 583 and other IRS recordkeeping rules tell you what to keep for taxes; they are not a reason to keep everything forever in a duffel.
A leak plan on one page
If a laptop walks off, you should know whom you will call: the bank, the platform, customers if their information was on the machine, and, when the facts require it, the authorities the FTC guide points you toward. Write the one-pager before you need it. State breach-notice laws differ; a small shop that sells across state lines should know it may have more than one. This is not a reason to panic. It is a reason to keep less, lock more, and skip the “we are too small” story.
Customer data is trust you can lose in an afternoon. The FTC already wrote the homework. Do the boring version. Then go sell the product. Security at this scale is mostly hygiene. Hygiene is a founder health issue too: less 3 a.m. dread when a phone disappears on a train.
Do not collect Social Security numbers or driver’s-license photos “in case.” If a payment processor or a shipping API already holds the piece you need, you do not need a second copy in a desktop folder named FinalFinal. Customer data wants fewer homes. Give it fewer. That is the smallest shop’s real advantage: you can still see every drawer. Open them. Empty the ones that should have been empty last year.
Phishing is how tiny shops actually get cleaned out. The FTC’s business guidance lives next to its consumer warnings for a reason. A fake “reset your store” email is not a technical puzzle. It is a pause: call the platform on a number you already have, not the number in the message. Customer data protection is often just not clicking. Practice that pause until it is boring.








