Someone cloned my Shopify store: the first 24 hours, in order
Act now
A customer emails about an order you have no record of. You search your own brand name and find a store that looks exactly like yours, on a domain you have never owned, taking real money. This is the order to work in, and the reasons the order matters.
Speed feels like the priority. It is not. Doing the steps in the wrong order is what costs people their case, because the first report you send can destroy the evidence you needed for the second.
Hour one: capture, before you report anything
The instant a report lands anywhere, the operator may pull the store, change it, or move to a new domain. Whatever you did not save is gone, and you cannot un-send a report to get it back.
Save, in this order:
- The pages themselves. Print to PDF with the URL and date in the header, or use your browser's save-page function. Do the homepage, a product page, the about page and every policy page, including the ones that error.
- The page source. Right click, view source, save it. This is where image paths live, and an image served from your own content delivery network is the single most useful thing you can find.
- The product images. Download them. If they are byte for byte identical to yours, that is provable later and impossible to reconstruct once the store is gone.
- The registration record. A public registration lookup shows when the domain was created. A domain registered weeks ago, selling a brand that has existed for years, is the fact that turns a suspicion into a case.
- The platform. If the store runs on Shopify, its own storefront metadata will say so, and it identifies which shop it is. That decides which route is fastest.
Timestamp everything. A screenshot with no date is a picture. A screenshot with a capture time, next to a registration record and a page source, is evidence.
Hours two to four: the routes that need no signature
There are two families of report and the difference between them decides who can send them.
Reports that describe what a site is doing need no rights holder and no sworn statement. A safety report says this page is deceiving shoppers. An abuse report says this customer is violating your terms. Anyone can send these, including your agency, your developer, or a service acting for you. Your name does not have to be on them.
Reports that assert who owns what are different, and they are covered further down.
Start with the first family, in roughly this order of speed:
- Browser safety. A deceptive-site report does not remove the store. It puts a full-page warning in front of anyone about to buy from it. That is the part that stops the bleeding, and it usually moves faster than anything that requires a human to weigh a legal claim.
- The host. Every hosting provider publishes an abuse contact and every one of them has terms the store is breaking. Give them the evidence, not an accusation.
- The registrar. Registrars vary enormously. Some act on a well-evidenced abuse report. Others will not move without a formal dispute filing or a court order, and will tell you so. Check the registrar's own published policy and follow it exactly, because a report that ignores the stated process is the easiest one to close.
- The content delivery network and the payment processor. Both are worth a report and both are routinely skipped. A store that cannot take payment stops being profitable within the hour.
Each of these should reference the evidence you captured in hour one, with the means to re-check it. A report that says "this store is fake" gets closed. A report that says "this store serves these image files from this address, its domain was registered on this date, and here is how to confirm both" gets read.
Hours four to twenty-four: the notice that only you can send
A copyright or trademark notice reaches venues that an abuse report cannot. It also carries a sworn statement, made under penalty of perjury in most jurisdictions, that the seller is not authorised to use the material.
Only you can make that statement. Not your agency, not a monitoring service, not a contractor. The reason is simple and it is the whole reason this step sits last: only you know who you have authorised. Your own contracts and your own sales team know which resellers, distributors and regional partners exist. From the outside, an authorised distributor and a copycat can look identical.
Before you send one, check your own list. A notice filed against a legitimate distributor is worse than no notice at all, and it is the one mistake in this process that can be expensive.
Two more things to know before you press send:
- Your contact details usually travel with it. Venues routinely pass the complainant's details to the party complained about, and several publish notices in a public database. This is normal and it is not a reason to avoid filing. It is a reason to know it before rather than after.
- If the store runs on Shopify, there is a shorter path. Shopify publishes its own intellectual property complaint process, the rights holder files it directly, and it costs nothing. Check the platform before you research anything more complicated.
Day two onward: it will come back
A domain costs a few dollars. Removal is never permanent, and treating a takedown as the end of the story is how brands get surprised twice.
The useful measure is not whether one store came down. It is whether you find the next one before your customers do. Keep the evidence pack. The second store by the same operator is much faster to deal with, because the pattern is already written down: the same image source, the same page structure, often the same registrar.
And be careful about what counts as closed. A store that fails to load once is not gone. It is worth confirming it is offline on two separate checks, at least an hour apart, before you stop watching.
The short version
- Capture everything, with dates, before you report anything.
- Send the reports that need no signature: safety, host, registrar, CDN, payment.
- Check your own authorised list.
- Send the intellectual property notice yourself, knowing your details go with it.
- Keep watching, because it comes back.
The order is the point. Evidence first, because it is the only step you cannot redo.
Questions
What should I do first when I find a clone of my store?
Capture evidence before anything else. The moment a report lands, the operator may take the store down, change it, or move it to a new domain, and your evidence disappears with it. Save the page, the product images, the page source and the registration record first. Everything after that step is recoverable. That step is not.
Do I have to send a DMCA notice myself?
For a copyright or trademark notice, yes. It carries a sworn statement that the seller is not authorised, and only the rights holder can make that statement, because only the rights holder knows who they have authorised. Reports that describe what a site is doing, rather than assert who owns what, need no signature and no rights holder, so anyone can send those.
Which report gets the fastest result?
In most cases a browser safety report, because it does not wait for a human to weigh a legal claim and it protects shoppers while the slower routes run. It does not remove the store. It warns the people about to buy from it, which is the part that stops the damage.
Will the store operator find out who reported them?
On an intellectual property notice, usually yes. Venues routinely pass the complainant's contact details to the party complained about, and many publish the notice. On abuse and safety reports, that does not happen. Decide which you are comfortable with before you send, not after.
The clone came back on a new domain. Now what?
That is the normal outcome, not a failure. A domain costs a few dollars, so removal is never permanent. Keep the evidence pack from the first one: a reappearance by the same operator is faster to deal with because the pattern is already documented.