When Commerce Policies Change: What Regulated Merchants Can Learn from Shopify’s Vape Decision

18 Aug 2026
Albert Wood
Albert Wood
When Commerce Policies Change: What Regulated Merchants Can Learn from Shopify’s Vape Decision

Shopify’s recent decision to prohibit the sale of Electronic Nicotine Delivery Systems (ENDS) has created an immediate challenge for merchants operating in the vaping industry.

Affected businesses were given a limited window to remove these products from their stores. For merchants that have spend years building their eCommerce operations around Shopify, the impact extends well beyond removing products from a catalog. It can affect checkout, payments, customer experience, integrations, marketing, fulfillment and ultimately revenue.

But this situation deserves a balanced perspective.

Shopify is one of the world’s leading commerce platforms, and for many businesses, including manufacturers, distributors and B2B organizations, it offers tremendous advantages in scalability, security, performance, ecosystem and speed to market.

At the same time, regulated industries operate under a different set of risks.

The lesson from Shopify’s ENDS policy change isn’t that merchants should avoid SaaS platforms. It is that companies operating in regulated, age-restricted or higher-risk categories need to consider platform and operational risk as part of their overall commerce strategy.

Two Weeks can be a Very Short Time in eCommerce

For a small merchant with a relatively simple store, moving products to another platform may sound straightforward.

For an established eCommerce business, it rarely is.

A modern commerce operation can include thousands of products and variants, years of customer and order history, ERP integrations, inventory systems, tax engines, shipping platforms, payment providers, age-verification services, marketing automation, analytics, product feeds and custom business logic.

A migration may require addressing:

  • Product catalogs, variants, media and inventory
  • Customer ad historical order data
  • URLs, redirects, structured data and SEO equity
  • ERP, CRM, PIM, OMS and 3PL integrations
  • Payment processing and stored payment methods
  • Age and identity verification
  • Shipping and geographic restrictions
  • Tax and compliance requirements
  • Analytics, advertising and marketing integrations
  • Custom functionality and business workflows

That is why an emergency migration is fundamentally different from a planned replatforming project.

The immediate objective may be business continuity. Optimization can follow.

SaaS vs. Open Source is Not the Real Question

It would be easy to look at this situation and conclude that regulated merchants simply shouldn’t use SaaS commerce platforms.

We don’t believe that’s the right conclusion.

SaaS platforms provide substantial benefits. Infrastructure, security, platform updates, scalability and many operational responsibilities are handled by the platform provider. That can allow merchants to focus more resources on customers, products and growth.

Open-source or independently hosted platforms can provide greater control over certain parts of the technology stack, but that control comes with additional responsibility.

Hosting, security, performance optimization, patches, upgrades, PCI considerations and ongoing technical maintenance have to be managed by the merchant and its technology partners.

Neither model is automatically better.

The better question is:

Which commerce architecture best matches the merchant’s business model, regulatory environment and risk profile?

For most conventional merchants, platform-policy risk may be relatively low.

For businesses selling regulated or age-restricted products, however, it should be part of the platform-selection process from the beginning.

Compliance and Platform Approval are Different Things

This is one of the most important lessons for regulated merchants.

A business may be legally permitted to sell a product and still face restrictions from companies required to complete the transaction.

Those companies can include:

  • Commerce platforms
  • Payment gateways
  • Payment processors
  • Acquiring banks
  • Card networks
  • Shipping carriers
  • Advertising platforms
  • Marketplaces
  • Cloud and technology providers

Legal compliance answers one question:

Are we legally permitted to sell this product?

Commercial approval answers another:

Will the companies required to operate and complete the transaction support this business category?

Those questions are related, but they are not the same.

That distinction should be evaluated before selecting a platform, payment provider or other critical commerce technology.

Payments Deserve Just as Much Attention as the Commerce Platform

When merchants evaluate an eCommerce platform, a tremendous amount of attention naturally goes toward storefront functionality.

But for regulated businesses, payment infrastructure can be equally important.

Accepting a credit card involves more than connecting a gateway. Behind the transaction can be a processor, acquiring bank, card network, issuing bank and multiple risk and compliance requirements.

A payment gateway may technically integrate with a commerce platform while the underlying processor or acquiring bank may not approve a particular product category.

Regulated merchants should therefore understand:

  • Whether their business category is explicitly supported
  • How the merchant will be underwritten
  • Which acquiring relationships support the account
  • Whether reserves or settlement delays may apply
  • How fraud and chargebacks will be managed
  • Whether payment tokens are portable
  • Which commerce and ERP platforms are supported
  • What happens if underwriting requirements change
  • Whether an approved secondary payment option is available

The key is to validate both technical compatibility and business approval before building the checkout experience around a payment provider.

Build for Portability, Not Just Performance

Every merchant wants a fast, attractive and high-converting website.

Regulated businesses should add another objective:

Portability.

The organization should understand how quickly critical parts of the commerce operation could be recovered, replaced or migrated if a technology relationship unexpectedly changed.

That doesn’t mean maintaining a second eCommerce platform waiting in the background.

It means avoiding unnecessary concentration of business-critical information and processes inside a single system.

A more resilient architecture may include:

  • Independent control of the domain and DNS
  • Regular exports of product, customer and order information
  • Product images and digital assets stored outside the commerce platform
  • ERP or OMS ownership of critical operational data
  • Independent CRM and customer records where appropriate
  • Documented integrations and data flows
  • Payment relationships that have been properly underwritten
  • Documented compliance and fulfillment rules
  • Backup and disaster-recovery procedures
  • An emergency migration and business-continuity plan

The goal isn’t to eliminate SaaS dependencies. Nearly every modern business depends on SaaS technology.

The goal is to understand which dependencies could materially interrupt the business and have a plan for them.

Platform Selection is Different for Regulated Industries

For most eCommerce projects, the platform conversation typically centers around functionality, integrations, scalability, user experience, total cost of ownership and time to market.

Regulated merchants should expand that evaluation.

Before selecting or replatforming to a commerce platform, they should understand:

  • Whether their products are permitted under current platform policies
  • Whether restrictions differ based on payment method
  • Which payment providers support their category
  • Whether age or identity verification can be integrated
  • Whether products can be restricted geographically
  • How shipping and fulfillment regulations will be handled
  • How easily business data can be exported
  • Which operational systems remain independent of the storefront
  • What options exist if platform or payment policies change

These aren’t reasons to avoid modern SaaS commerce.

They are reasons to perform more rigorous discovery before making a long-term technology decision.

What Should Merchants do Now?

For merchants directly affected by Shopify’s ENDS policy, the first priority is continuity.

A rushed attempt to recreate every feature of an existing store may not be realistic.

Instead, businesses may need to establish a minimum viable commerce operation first: preserve critical data, establish an approved payment relationship, maintain compliance, protect important SEO URLs and reconnect the systems necessary to continue accepting and fulfilling orders.

More sophisticated functionality can then be restored in phases.

For merchants in other regulated industries, the current situation provides an opportunity to evaluate their architecture before they’re forced to.

Ask a simple question:

If one critical technology provider changed its policy tomorrow, how quickly could our business adapt?

If the answer isn’t clear, that’s a business-continuity issue worth addressing.

The Broader Lesson for eCommerce

Shopify’s decision should not be interpreted as an argument against Shopify or SaaS commerce.

Shopify remains an excellent platform for a wide range of B2C and B2B businesses, and ioVista works closely with Shopify to help organizations modernize and scale their commerce operations.

But every platform has acceptable-use policies, contractual requirements and business considerations.

For companies operating in regulated or higher-risk industries, those factors deserve the same attention as features, design and development costs.

A strong commerce strategy therefore isn’t simply about choosing the best platform.

It’s about building an operation that can continue serving customers as technology, regulations and business requirements evolve.

Prepare Before You Have to Migrate

For more than 20 years, ioVista has helped manufacturers, distributors and eCommerce organizations evaluate platforms, migrate complex commerce environments and integrate the systems behind them.

For businesses operating in regulated industries, that process requires looking beyond the storefront.

Our team can evaluate platform architecture, payment dependencies, ERP and CRM integrations, data portability, compliance workflows, SEO migration requirements, hosting considerations and business-continuity readiness.

The objective isn’t to predict which policy will change next.

It’s to make sure your commerce operation is prepared to adapt when something does.

Albert Wood
Albert Wood linkedin

Albert Wood is an accomplished eCommerce Business Analyst. As a technology futurist and sales motivator at ioVista, Albert is dedicated to transforming struggling eCommerce businesses into thriving enterprises. With a keen focus on client’s business processes, user experience (UX), and leveraging the power of digital marketing, he helps businesses optimize their online presence and drive sustainable growth. Albert’s passion is for virtual reality (VR), augmented reality (AR), and mixed reality (MR), immersing himself in unforgettable experiences and exploring the limitless possibilities they offer. His enthusiasm for these emerging technologies fuels his drive to push the boundaries of innovation in eCommerce.

Get in Touch






    Let’s work together to create outstanding digital experiences.

    With 20+ years of industry experience, ioVista understands your eCommerce needs and delivers best-in-class solutions that help you gain a competitive edge.

    Platform Assessment

    TOP