SaltAISaltAI
Allergen Compliance27 March 202610 min read

Allergen Compliance Software: What Shopify Food Merchants Need

If you sell food online, allergen compliance is not a box-ticking exercise — it is a legal obligation with real consequences for real people. In the UK, Natasha's Law came into force in October 20

If you sell food online, allergen compliance is not a box-ticking exercise — it is a legal obligation with real consequences for real people. In the UK, Natasha's Law came into force in October 2021, requiring full ingredient and allergen labelling on all pre-packed for direct sale (PPDS) foods. In the US, the Food Allergen Labeling and Consumer Protection Act (FALCPA) mandates clear declaration of the nine major allergens on packaged food labels. Between these two regulatory frameworks, food merchants selling across borders face a compliance challenge that spreadsheets and manual processes simply cannot keep up with.

The problem is compounded on Shopify specifically. The platform was built for commerce, not compliance. Product descriptions, variant structures, and metafields were never designed with allergen declarations in mind. Merchants who rely on copy-pasted ingredient lists, static PDF menus, or handwritten labels are one product reformulation away from a serious mislabelling incident — the kind that can trigger a recall, an enforcement notice, or worse.

This post covers what allergen compliance software actually does, what to look for when evaluating tools for your Shopify store, and how to build a system that protects your customers and your business. Whether you run a small artisan bakery, a growing meal kit brand, or a multi-SKU snack business, the principles here apply directly to your operation.

What UK and US Allergen Law Actually Requires From Online Food Sellers

Understanding your legal baseline is the first step before evaluating any software. In the UK, the Food Information to Consumers Regulation (FIC) requires that the 14 major allergens — including cereals containing gluten, nuts, milk, eggs, sesame, and sulphur dioxide — are emphasised in the ingredients list, typically in bold. For PPDS foods sold online and collected in person, this information must appear on the physical label at the point of sale. For distance selling (delivery), allergen information must be available before purchase is completed and confirmed at the point of delivery.

In the US, FALCPA requires declaration of the nine major allergens: milk, eggs, fish, shellfish, tree nuts, peanuts, wheat, soybeans, and — added under the FASTER Act in 2023 — sesame. Declarations must appear on the principal display panel or information panel of the label. For online food sellers, the FTC's guidance on disclosure means that allergen information presented only in a downloadable PDF or buried in a FAQ is unlikely to meet the spirit of the law, and state-level food safety regulations add further requirements in places like California and New York.

The practical implication for Shopify merchants is this: allergen information must be accurate, up to date, and visible at the product level — not just on a general allergens page. If a customer places an order for a hazelnut brownie and your product page does not clearly declare tree nuts, you are exposed to liability regardless of whether a label appears on the box that arrives at their door.

Why Manual Processes Break Down as Your Catalogue Grows

Many food merchants start with a workable manual system: a shared spreadsheet listing ingredients and allergens for each SKU, updated by the person who formulates the recipes. This works when you have ten products and one person managing everything. It becomes dangerous the moment you scale, diversify your supplier base, or introduce seasonal variants and limited-edition lines.

The core failure mode is version control. When a supplier changes a chocolate couverture to one that now contains soya lecithin, that change needs to propagate instantly to every product that uses that ingredient — across your Shopify store, your printed labels, your customer-facing menu, and your internal kitchen documentation. In a manual system, it typically does not. The spreadsheet gets updated by one team member, but the Shopify product description stays unchanged for three months until someone notices, or until a customer with a soya allergy has a reaction.

A secondary failure mode is human transcription error. Copying allergen data from a supplier specification sheet into a product description by hand introduces error at every step. Studies in food manufacturing consistently show that manual data entry generates error rates of between 1% and 5% per transaction — and in allergen management, even a single error can be the difference between a safe product and a recall. Compliance software addresses both failure modes by centralising allergen data, linking it to ingredients rather than products, and pushing updates automatically across every touchpoint.

Core Features to Look for in Allergen Compliance Software

Not all allergen tools are built equally, and some marketed as "allergen management" software are little more than digital versions of the same spreadsheet you are already using. The features that actually reduce risk and save time are specific and worth evaluating carefully before committing to any platform.

Ingredient-level allergen mapping is the most important feature. Rather than manually tagging each product with its allergens, a proper system lets you define ingredients once — including their allergen profile — and then builds allergen declarations automatically when you assemble a recipe. Change the allergen status of one ingredient and every product using it updates immediately. This is the single biggest safeguard against the version control failures described above, and it is the architecture that separates serious compliance tools from glorified spreadsheets.

Shopify-native integration matters enormously for merchants on the platform. A standalone compliance tool that requires you to export data, reformat it, and manually import it to Shopify every time something changes defeats the purpose of automation. Look for tools that write allergen data directly to product metafields, surface declarations in product descriptions, and ideally support Shopify's structured data so that allergen information is also visible to search engines and third-party apps in your stack. Allergen Matrix is built specifically for this use case, handling the Shopify integration layer so merchants do not have to. Audit trail and change logging round out the core feature set — you need to be able to demonstrate, if challenged by a food safety inspector, that your allergen data was accurate on any given date.

How to Structure Your Allergen Data in Shopify

Getting allergen data into Shopify correctly is a separate challenge from managing it upstream. Shopify's native product structure — title, description, variants, tags, metafields — does not have a dedicated allergen field, which means merchants need a deliberate approach to where and how allergen information lives in their store.

Metafields are the right home for structured allergen data in Shopify. Unlike product descriptions, metafields can be queried programmatically, displayed conditionally in your theme, and read by third-party apps without scraping unstructured HTML. A well-designed allergen compliance setup will use a metafield namespace — something like food.allergens — with individual fields for contains, may contain, and free-from declarations. This structured approach also makes it possible to filter products by allergen status, which is increasingly expected by customers with allergies who want to browse safely.

Your product description should still include a human-readable allergen summary, both for accessibility and to meet the legal requirement that information is clearly presented before purchase. The ideal pattern is for this description text to be generated automatically from your metafield data, so you are never maintaining two separate versions of the same information. Shopify themes with Liquid templating make this possible, and any allergen compliance app worth using should handle this rendering for you. Testing your storefront from the perspective of an allergic customer — navigating to a product page without prior knowledge of the product — is a practical way to audit whether your current setup actually meets the visibility standard the law requires.

Handling Recipe Changes and Supplier Substitutions Safely

Supplier substitutions are one of the highest-risk events in food product allergen management. When a raw material becomes unavailable and your procurement team sources an alternative, the allergen profile of that ingredient may change — and if your compliance system does not catch it, neither will your customer-facing content until it is too late.

A robust process for supplier substitutions starts with a change control gate: no new ingredient enters production until its full allergen specification has been verified from the supplier's technical data sheet and entered into your compliance system. This sounds obvious, but under the time pressure of a stock shortage, this step is frequently skipped. Building it into your purchasing workflow — so that raising a purchase order for a new ingredient triggers an allergen data request — converts a procedural best practice into a reliable system.

Allergen compliance software supports this by flagging products whose ingredient list references an ingredient with an incomplete or unverified allergen profile. Some platforms allow you to set an ingredient to a "pending verification" status that automatically suppresses that product from being published on your Shopify store until the allergen data is confirmed. This is a genuinely useful safeguard for growing food businesses where the person managing ingredients is not always the same person publishing products on the website.

Preparing for Food Safety Inspections and Due Diligence Requests

Food safety inspections — whether from a local authority environmental health officer in the UK or a state department of agriculture inspector in the US — increasingly include scrutiny of allergen management systems, not just physical premises. An inspector asking to see your allergen management documentation is a routine part of a higher-risk food business inspection, and the quality of your response directly affects your compliance rating.

What inspectors want to see is traceability: the ability to demonstrate that for any product you sell, you can identify every ingredient, confirm the allergen status of each, and show when that information was last verified. A well-maintained allergen compliance system should be able to produce this in minutes. A folder of supplier spec sheets and a colour-coded spreadsheet that was last updated in Q1 will not give the same impression, even if the underlying data is accurate.

For merchants supplying retail or foodservice clients — the kind of businesses that supply accounts like Selfridges or corporate catering contracts — due diligence questionnaires are a standard part of the onboarding process. Buyers at major retailers require product specifications that include full allergen declarations, cross-contamination controls, and evidence of your management system. Having your allergen data structured and accessible in a compliance platform means you can respond to these requests quickly and accurately, which is itself a competitive advantage in pitching for larger accounts.

Conclusion

Allergen compliance on Shopify is a three-layer challenge: understanding the law, managing ingredient data accurately, and surfacing that data clearly for customers. Manual processes — spreadsheets, copy-pasted descriptions, static PDFs — are adequate when you start out, but they introduce compounding risk as your catalogue grows, your supplier base diversifies, and your customer base scales. The consequences of a mislabelling incident are severe enough — from customer harm to enforcement action to reputational damage — that investing in proper compliance infrastructure is one of the most important operational decisions a food merchant can make.

The key takeaways are practical: map allergens at the ingredient level, not the product level; use Shopify metafields for structured data; build supplier change control into your procurement process; and maintain an audit trail you can present to inspectors and buyers alike.

Try Allergen Matrix free at saltai.app — no credit card required.

SaltAI Team

SaltAI builds focused Shopify apps for food merchants and general merchants. Every app is tested in production at a real food store — including Vanda's Kitchen — before it ships.