What Shopify Spy Tools Can See and How to Limit It
Can competitors see my Shopify sales?
Not your real sales. Shopify doesn’t publish orders or revenue, so spy tools such as PPSPY and Koala Inspector estimate them from what your store shows the public: products, prices, estimated traffic, your theme and apps. Even their makers call the figures estimates. You can hide some of that, and block their browser extensions, but not everything.
Note: The Shopify documentation and the spy tools’ own pages cited here were checked on 26 September 2026.
Your orders, revenue, customers and conversion rate stay inside your Shopify admin. The storefront API that themes use, which anyone can call without a key, can’t be used to read any customer or order data, according to Shopify’s documentation (Shopify Ajax API). What a store does publish, its catalogue, prices, theme and apps, is enough to guess from, and a good guess is what these tools sell.
How do spy tools estimate sales?
By modelling them from public signals, then watching what changes. The tools read some data straight from your storefront and estimate the rest.
What they read directly
Your product list, prices, variants, theme and installed apps come straight from your public pages. Koala Inspector’s makers say this part is exact, because it’s what the store itself publishes (Koala Inspector for product research). Tracking features then record changes over time: products added or removed, price and variant changes, a new theme, an app installed or dropped.
What they estimate
Koala Inspector describes a revenue estimate as three numbers multiplied together: how many people visit, what share of them buy, and the store’s average product price. Its extension fills those in with estimated traffic, your price range and average price, and which products seem to be selling, all modelled from what any visitor’s browser can see and never from a store’s private dashboard (Koala Inspector’s sales tracker guide).
PPSPY says its sales figures are estimates produced with artificial intelligence and claims more than 80.5% accuracy (PPSPY’s sales tracker). The same page says it could follow sales of individual products until September 2023, when Shopify removed the interface it relied on, and that it now estimates sales for whole stores instead.
How accurate are spy tool sales estimates?
Accurate enough to size up a store, not to know its numbers, and the tools say as much. Koala Inspector tells its users to read a figure as a range rather than a number. Its own worked example spans from a quarter below to half above the figure shown, and it calls its traffic and best-seller readings directional. PPSPY’s page gives its accuracy figure without saying how it was measured, and we found no independent test with a published method.
The quickest accuracy test is your own store. Look it up in one of these tools and compare the estimate with your Shopify reports for the same weeks. Whatever the gap, a competitor sees a rough size and a direction of travel, not your margins, your conversion rate or your customer list.
What else can they see?
Spy tools can see everything your Shopify storefront shows the public: every product, price, variant and SKU, plus a few signals that are easy to miss.
| What they can see | Where it comes from | Can you hide it? |
|---|---|---|
| Every product, price, variant, SKU and description | Product pages, your sitemap and your product data in JSON | Only by unpublishing a product, or putting the whole store in private mode |
| When each product was created, published and last updated | Timestamps in the same product data | Not for products you sell |
| Which products sell best, in order | Any collection opened with ?sort_by=best-selling |
Not with a setting: best-selling is one of Shopify’s standard sort orders |
| Your stock levels | A stock counter in your theme, if it shows one, and the cart | Turn the counter off; the cart behaviour stays |
| Your theme and its version | Your page source | No |
| Your apps | The scripts they load into your page source | Only by removing apps you no longer use |
| Your ads | Meta’s Ad Library | No |
| Your traffic | Third-party estimates | No, but they are estimates |
| Your orders, revenue, customers and conversion rate | Your Shopify admin only | Already private |
Most of this is public by design, because a storefront needs it to work:
- Product data. Shopify’s Ajax API, which themes use to load product details without a page reload, is unauthenticated. It returns a product’s description, prices, variants, SKUs and created and published dates (product reference). Storefronts also serve the catalogue at
/products.json. Shopify doesn’t document that address, but when we checked it on Shopify’s own Dawn demo store on 24 September 2026 it returned the products as JSON, each with its created, published and updated times, and no stock quantities. - Your sitemap. Shopify generates a
sitemap.xmlthat links all your products, pages, collections and blog posts (Shopify’s sitemap article). - Best-sellers. Collections accept a
sort_byparameter in the page address, and best-selling is one of the standard orders (Liquid collection object). - Stock. If someone asks the cart for more units than you have, Shopify adds the maximum available instead, which reveals your stock of a tracked item (Cart API reference).
- Theme. Your page source names your theme and its version. Search it for
Shopify.themeto see what yours says. - Ads. Meta lets anyone search all active ads running across its products (Meta Ad Library).
What can I hide?
You can hide less from spy tools than you would like, because a store has to show products and prices to sell them. These steps remove the extras.
- Turn off stock counts. If your product pages say “Low stock: 3 left”, switch the number off and keep the message. In Shopify’s Dawn theme it’s the Inventory count setting on the product page’s Inventory status block. The cart behaviour described above still applies to tracked items, so this slows people down rather than stopping them.
- Keep launches unpublished. A product that isn’t available on your online store doesn’t appear on your storefront or in its product data, so publish on launch day, not before.
- Use private mode before you open. Shopify’s private mode hides every page from visitors and search engines and shows a landing page instead (Restrict access to your online store). On our own password-protected demo store, the product feed redirects to the password page too.
- Use your own photos. A supplier’s product photos can be traced back to the supplier’s listing with a reverse image search.
- Remove apps you no longer use. Every app that loads on your storefront is visible in your page source.
What you can’t hide is the rest of the table: the products, prices and dates of everything you sell, your best-selling order, your theme and your active ads.
Does blocking spy extensions work?
Partly. It removes the one-click view for visitors who have a known spy extension installed, in desktop Chrome-based browsers. It can’t touch data the tools collect from their own servers, and it doesn’t make your store private.
X Shield, which we build, has a Spy extensions protection switch on its paid plans (X Shield’s plans). It checks the visitor’s browser for files that belong to more than 130 known spy, dropshipping and ad-research extensions, PPSPY and Koala Inspector among them, when the page loads and while it stays open. A match gets your blocked page instead of your store, and the block appears in X Shield’s Analytics with the extension’s name, so you can see how often it happens. To set it up, see how to block PPSPY and Koala Inspector in X Shield.
Know its limits before you rely on it:
- Desktop Chrome-based browsers only. It looks for extensions from the Chrome Web Store, in Chrome and similar browsers on a computer. Firefox, Safari and phones aren’t checked.
- Named extensions only. A new or renamed tool gets through until an X Shield update adds it to the list.
- Nothing server-side. Product data read by the tools’ own servers, traffic estimates and ad libraries are untouched.
- Another browser gets in. Anyone can open your store in a browser without the extension installed.
- Your own team can trip it. The list also covers some general Shopify helper extensions, so give your staff a private access link that skips every rule.
Scraping is a separate problem. X Shield’s Scraper network blocking, free today, turns away visits from cloud networks known for scraping, and Bot protection catches browser automation that doesn’t hide itself. Both only see visitors that load your pages in a browser and run their JavaScript. A script that requests /products.json directly never runs X Shield, or any other app that works through your theme, so none of them can stop it. See how to block scraper networks in X Shield.
Tip: X Shield, a free country and bot blocker for Shopify, includes scraper-network and bot blocking on its Free plan; spy-extension protection needs a paid plan.
Is it worth it? If extension users are what worries you, blocking them removes the easiest look at your store. If you want to protect your text and photos rather than your numbers, read how to disable right-click on Shopify and what that can and can’t do. Either way, a Shopify store is public by design: spend your effort on what you control, your stock counts, your launch timing and your own photography.