SaltAISaltAI
New York Allergen Law2 March 20269 min read

New York Food Allergy Menus: How to Create a Compliant One

If you run a food business in New York — whether that's a restaurant, a ghost kitchen, a meal kit brand on Shopify, or a catering operation — allergen compliance is no longer optional. It is a legal r

If you run a food business in New York — whether that's a restaurant, a ghost kitchen, a meal kit brand on Shopify, or a catering operation — allergen compliance is no longer optional. It is a legal requirement, and the rules are specific. New York State and New York City both have allergen disclosure laws on the books, and failing to follow them exposes your business to fines, lawsuits, and far worse: a customer having a serious allergic reaction because your menu didn't tell them what was in the food.

The problem many food business owners face isn't a lack of care — it's a lack of clarity. The legislation uses technical language, the requirements differ slightly between state and city rules, and translating those requirements into an actual working menu is harder than it sounds. If you're selling food online through Shopify, the challenge grows further because your "menu" is effectively a product catalogue, and you need to build compliance directly into how you present your products.

In this post, you'll learn exactly what New York allergen menu law requires, how to identify and disclose the major allergens, how to structure your menu or product pages for compliance, and what practical tools can help you manage this at scale without rebuilding your entire store from scratch.

What New York Allergen Law Actually Requires

New York State requires food service establishments to provide written allergen information to customers upon request, under the Food Allergy Awareness Act. More importantly, New York City Local Law 31 goes further: it requires all food service establishments operating in the five boroughs to prominently display a food allergy notice in a conspicuous location, and to have staff trained to handle allergen inquiries. The notice must list the major allergens and direct customers to speak with a manager or staff member before ordering.

The major allergens recognised under US federal law — and mirrored in New York's requirements — are the Big Nine: milk, eggs, fish, shellfish, tree nuts, peanuts, wheat, soybeans, and sesame. Sesame was added to the federal list under the FASTER Act, which came into full effect on 1 January 2023, so if your menus or product pages were last updated before that date, they are almost certainly already out of compliance on that point alone.

For online food businesses, the relevant guidance comes from the FDA's labelling requirements for packaged foods, which apply to anything shipped to consumers. If you're selling ready-to-eat meals, baked goods, or prepared foods through your Shopify store and shipping them to New York customers, your product pages need to function as compliant labels. That means clearly listing every ingredient and calling out allergens in bold or by some other visually distinct method.

How to Identify Allergens Across Your Entire Menu

Before you can disclose allergens, you need to know what's in everything you sell — and that sounds obvious until you realise how many hidden allergen sources exist in a typical commercial kitchen. Cross-contact is one of the biggest compliance gaps food businesses miss. Even if a dish doesn't contain peanuts as an ingredient, if it's prepared on shared equipment that also processes peanut-containing items, that needs to be disclosed to customers at risk.

The practical starting point is building an ingredient matrix for every product you sell. For each menu item or Shopify product, list every ingredient — including sauces, marinades, stock bases, garnishes, and cooking oils — and trace each one back to its supplier's allergen declaration. Many food businesses are surprised to find that a standard vegetable stock contains celery (a UK allergen, though not a US one), or that a supposedly "plain" bread contains sesame seeds as part of a topping blend.

Once you have that ingredient-level data, mapping it against the Big Nine becomes straightforward. A spreadsheet works as a starting point, but it breaks down quickly once you have more than twenty or thirty products. Tools like Allergen Matrix are designed specifically for this problem — letting you build your ingredient data once and automatically generate compliant allergen disclosures across all your Shopify product pages without manually updating each one when a recipe changes.

Writing Allergen Disclosures That Actually Communicate Risk

The legal requirement to disclose allergens is a floor, not a ceiling. A disclosure buried in tiny text at the bottom of a menu, or hidden behind a "more info" button on a product page, technically satisfies the letter of the law but fails the customer who needs the information. The FDA requires that allergen labelling be clear and conspicuous, and for good reason — a customer scanning a menu quickly in a restaurant, or browsing on a phone, needs to be able to see the allergen information without hunting for it.

The most practical format for menu allergen disclosures is a combination of in-line labelling and a summary table. In-line labelling means calling out allergens directly in the product description: "Contains: milk, wheat, eggs." A summary table at the bottom of the menu or on a dedicated page gives customers a full-picture view across all items, which is particularly useful for customers managing multiple allergies. For online menus and Shopify stores, a dedicated allergen page linked from every product page is considered best practice.

Language precision matters more than many food business owners realise. "May contain traces of nuts" is a precautionary allergen label (PAL) and should only be used when there is a genuine, assessed risk of cross-contact — not as a blanket disclaimer designed to limit liability. Overusing PALs erodes customer trust and, increasingly, draws scrutiny from trading standards bodies. If your kitchen truly has no risk of cross-contact for a given allergen, don't label it as a "may contain."

Structuring Your Shopify Menu Pages for Compliance

If you're running a food business on Shopify, your product pages are your menu — and they need to be structured with that in mind. A standard Shopify product page is set up to sell a product, not to communicate nutritional or allergen information. That means the default template will rarely be sufficient for a food business operating under New York allergen law, and you'll likely need to either customise your theme or use a dedicated app to add compliant allergen disclosures to every product.

The key structural elements every food product page needs are: a full ingredient list, a clearly formatted allergen summary (e.g., "Contains: wheat, milk, soya"), a precautionary statement if cross-contact risk exists, and a way for customers to contact you with questions before purchasing. This last point mirrors the in-restaurant requirement under NYC Local Law 31 to direct customers to a staff member — for an online store, that means a clearly visible customer service link or chat option.

If you have a large catalogue — say, forty or more SKUs — managing allergen information manually across individual product pages creates serious version-control risk. When a supplier changes an ingredient in one of your base sauces, every affected product needs to be updated immediately. An automated system that pulls from a central ingredient database and pushes updates to product pages is not a luxury at that scale; it's basic risk management and a practical compliance necessity.

Training Your Team and Keeping Records

No allergen disclosure system works reliably without the people behind it understanding why it matters. Under NYC Local Law 31, food service staff are required to be trained on allergen awareness, and that training needs to be documented. If your business is ever inspected or faces a complaint, the question won't just be "does your menu say the right thing?" — it will also be "can you show that your staff understood and followed allergen protocols?"

Practical training doesn't need to be expensive. The NYC Department of Health publishes free resources specifically for food service operators, including guidance on handling allergen requests, avoiding cross-contact in the kitchen, and what to do when a customer discloses a serious allergy. Pairing that with your own written SOPs — standard operating procedures — for handling allergen queries gives you a defensible paper trail if something goes wrong.

For online food businesses, "training your team" also includes whoever manages your Shopify store. The person updating product descriptions needs to understand that removing an ingredient from the description without checking the allergen matrix first is a compliance failure. Build allergen review into your product update workflow as a mandatory step, not an afterthought.

Common Compliance Mistakes and How to Avoid Them

The most common allergen compliance mistake is outdated menus. Ingredient formulations change, suppliers change, and seasonal menus rotate — but allergen information on websites and printed menus often doesn't get updated at the same time. A dish that was nut-free six months ago may not be today if your supplier changed the recipe for a base sauce you use. Establishing a formal review process — at minimum quarterly, and any time a recipe or supplier changes — is essential.

The second most common mistake is inconsistency between channels. A food business might have perfectly accurate allergen information on their printed in-restaurant menu but outdated information on their Shopify store, their Deliveroo listing, and their catering PDF. Each channel needs to reflect the same underlying allergen data, which is another strong argument for managing that data centrally rather than channel by channel.

A third mistake is misunderstanding the difference between "free from" and "does not contain." A product that does not contain gluten as an ingredient is not necessarily safe for a coeliac customer if it's produced in a facility that handles wheat. "Free from" is a claim that requires verified production controls and, in many cases, testing. Using "free from" language loosely to market your products is both a compliance risk and a serious safety risk for the customers who rely on it.

Conclusion

New York allergen menu law is specific, enforceable, and grounded in genuine public safety needs. For food business owners, compliance starts with knowing your ingredients at a granular level, disclosing the Big Nine allergens clearly and consistently across every customer touchpoint, training your team, and maintaining accurate records. For Shopify food businesses in particular, building allergen disclosure into your product pages — not bolting it on as an afterthought — is the difference between a compliant store and a liability.

The key takeaways: audit your ingredient data now, update your menus to include sesame if you haven't already, never use "may contain" as a blanket disclaimer, and build a review process that keeps allergen information current across every channel you sell through. Compliance isn't a one-time task — it's an ongoing operational discipline.

Try Allergen Matrix free at saltai.app — no credit card required.

SaltAI Team

SaltAI builds focused Shopify apps for food merchants and general merchants. Every app is tested in production at a real food store — including Vanda's Kitchen — before it ships.