When you migrate customer accounts to Shopify, most of the account moves as data: profiles, email addresses, saved addresses, phone numbers, order history and often tags and marketing-consent status all import cleanly. What does not move is the password. Passwords are stored as one-way hashes on your old platform and can’t be transferred, so every returning shopper sets a new one — via an account-activation invitation or a password reset on first login. That single fact is what “account migration” really means: the records come across, the credentials don’t. Plan the communication around it, and returning customers barely notice the switch.
What can migrate
The customer record is portable. When you export from WooCommerce, Magento, BigCommerce or a custom store and import into Shopify, you can bring:
- Customer records — name, email address, phone number and (usually) the account creation date.
- Saved addresses — default and additional shipping/billing addresses attached to each customer.
- Order history — past orders, line items and totals, imported and linked back to the right customer so their purchase history is intact.
- Tags and segments — VIP flags, wholesale markers, source tags and other labels you use for segmentation.
- Marketing-consent status — whether each customer opted in to email (and often SMS), so you don’t lose your legally-collected subscriber base or accidentally email people who never opted in.
Done properly, a returning customer logs in and sees their addresses and past orders exactly where they expect them. The work is in the mapping — matching old fields to Shopify’s schema and making sure order history joins to the correct customer by email.
What cannot migrate
Passwords. This is the one hard limit, and it surprises people. Passwords are never stored as readable text — your old platform keeps a one-way cryptographic hash, deliberately designed so the original password can’t be recovered, even by the platform itself. There is no export that contains the password, and Shopify has no way to accept a foreign hash. So passwords simply do not transfer between platforms. Any tool or agency that claims to “migrate passwords” is either misunderstanding the process or overpromising.
That means the login step changes for every customer. It’s not a failure of the migration — it’s an inherent property of how passwords work everywhere. Your job is to handle the transition gracefully rather than pretend it isn’t happening.
Can / can’t at a glance
| Customer data | Migrates to Shopify? |
|---|---|
| Name, email, phone | Yes — imported as the customer record |
| Saved shipping/billing addresses | Yes |
| Order history | Yes — linked to the customer by email |
| Tags / segments | Yes |
| Marketing-consent (email/SMS) status | Yes — carry it over accurately |
| Store credit / loyalty points | Sometimes — depends on the app, often needs a separate export/import |
| Password / login credentials | No — one-way hashes can’t transfer |
Why it matters
Loyal, returning customers are your most valuable traffic — they convert higher and cost nothing to reacquire. A botched account migration hits exactly those people. If order history is missing, addresses are wrong, or a returning shopper hits a login wall with no explanation, the friction lands on your best customers at the worst moment. Some abandon the purchase; some assume the site was hacked; some just don’t come back. That’s a direct, avoidable hit to repeat sales. Getting the customer import and the login change right isn’t a nice-to-have — it protects the revenue that’s hardest to win back.
The login change and your two options
Because passwords can’t come across, every customer needs to set a new one. You have two main approaches:
- Account-activation invitations. Shopify can send each imported customer an invitation to activate their account and choose a password. This is proactive — customers set up their login before they next shop. The trade-off is you’re sending a batch of emails, so timing and copy matter, and deliverability on a large send needs care.
- Password reset on first login. You import the accounts quietly and let customers use the normal “forgot password” flow the first time they try to log in after launch. This avoids a mass email, but a customer who doesn’t realize their old password stopped working can get confused at checkout.
Many stores use a blend: a clear heads-up email before launch, then the reset flow available on day one, with activation invitations for high-value segments. There’s no single right answer — it depends on your list size, sending reputation and how login-heavy your buying flow is.
Consent and data handling
Marketing-consent status is the part people quietly get wrong, and it carries legal weight. Carry over the accurate opt-in status for each customer — do not import your whole customer list as “subscribed” because it’s convenient. Emailing people who never opted in breaches consent rules (GDPR, CAN-SPAM and similar) and torches your sender reputation. Map the consent field deliberately, keep opted-out customers opted-out, and treat the migration as a chance to reconcile your list, not to reset everyone to subscribed. The same care applies to any SMS consent.
Communication planning
The smoothest migrations tell customers what’s coming. Plan the comms as part of the project, not an afterthought:
- Before launch — a short note to your list that the store is moving and their account and order history are coming with them, but they’ll set a new password on their next visit.
- At launch — clear messaging on the login page and in your activation/reset emails explaining why the old password no longer works and exactly how to get back in.
- Support-ready — brief your support team (or your help docs) so the first login questions have a ready answer.
Framing the password reset as a routine security step, not a problem, is usually enough to keep returning customers calm.
Reconcile after the import
Once customers are imported, verify before you celebrate. Compare customer counts between the old platform and Shopify, spot-check a sample of records for correct addresses and consent status, and confirm order history attached to the right customers rather than creating orphan orders or duplicate profiles. Reconciliation is the same discipline that keeps products from going missing after a migration — count, sample, confirm. It belongs on your broader Shopify migration checklist alongside redirects and checkout testing.
Common mistakes
- Assuming passwords transfer. They can’t. Plan the activation/reset flow from the start instead of discovering it at launch.
- Forgetting consent. Importing everyone as subscribed is a compliance and deliverability risk — carry the real opt-in status.
- No comms plan. Silence turns a routine password reset into a support flood and a trust problem. It’s a recurring theme in WooCommerce-to-Shopify migration problems.
- Skipping reconciliation. Not checking counts and sample records means you find the missing or mis-linked accounts after customers do.
When to get help
If your store is small and your customer list is short, a careful CSV import plus a clear email may be all you need. Get help when the customer base is large, order history is deep, loyalty or store-credit balances are involved, or you can’t afford returning customers hitting friction at launch. Those are the migrations where the import mapping, the activation flow and the comms all have to line up — and where an experienced store migration team earns its fee. If you’re still weighing whether to move at all, our migrate-to-Shopify solution overview walks through the trade-offs, and a free profit audit can pressure-test the plan before you commit.
Worried about your customer accounts in a migration? Send us your store details — we’ll plan the customer import, the activation flow and the comms so returning shoppers have a smooth first login. See our store migration service or get a free profit audit.