The Ultimate Guide to Food Allergen Management for Shopify Merchants
Managing allergens across a Shopify food store requires coordination between your physical labels, online product pages, and production processes. Here's the complete guide.
Allergen management for Shopify food merchants spans three domains: your physical products and labels, your online store, and your production processes. Getting all three aligned is the foundation of genuine compliance — and customer safety.
The Allergen Management Challenge
The core challenge for food merchants on Shopify is maintaining consistency between physical labels and online product pages as recipes evolve, ingredients change, and product catalogues grow. A product page that says "contains: milk, wheat" when the current recipe also contains soy is a compliance failure and a safety risk.
Building Your Allergen Matrix
Start with a comprehensive allergen matrix — a spreadsheet or database record for every product you sell, listing which allergens are present (intentional ingredients), which are absent, and which may be present due to cross-contact. This matrix is your source of truth. Every change to it must trigger updates to both your physical labels and your Shopify product pages simultaneously.
Online Allergen Disclosure Requirements
Both US FALCPA and UK FIC/Natasha's Law require allergen information to be available to customers before they purchase online. For Shopify, this means allergen information on the product page — not in a downloadable PDF, not on a separate FAQ page, not only on the physical label. It must be visible on the product listing that a customer sees before adding to cart.
Using Technology to Maintain Consistency
Manual allergen management across a catalogue of 50+ products is error-prone. SaltAI's Allergen Matrix app centralises your allergen data in Shopify admin — update allergen information once, and it displays correctly across all product pages. For businesses with large catalogues or frequent recipe changes, this dramatically reduces the compliance risk of outdated online allergen information.
Centralise allergen management for your entire Shopify food catalogue with SaltAI.
Understanding Cross-Contact and "May Contain" Labelling
Cross-contact occurs when an allergen is unintentionally transferred from one food to another during production — through shared equipment, shared surfaces, or airborne particles in a production space. This is distinct from cross-contamination in a microbial sense, and the two terms are not interchangeable. For allergen management purposes, cross-contact is the critical risk, because even trace quantities of a major allergen can trigger a severe reaction in a sensitised individual. Your allergen matrix must have a dedicated column for cross-contact risks, separate from intentional ingredients.
"May contain" or "produced in a facility that also handles" statements are precautionary allergen labels, commonly abbreviated as PAL. They are not a legal substitute for declaring allergens that are intentional ingredients, but they serve an important function for cross-contact risks that cannot be fully controlled. In the UK, the Food Standards Agency advises that PAL should only be used where a genuine, assessed risk exists — not as a blanket disclaimer applied to every product to avoid responsibility. Overusing precautionary statements erodes consumer trust and makes your labelling less useful to the customers who rely on it most.
When managing PAL online, apply the same standard you apply to declared allergens: the precautionary information must appear on the product page before purchase. A customer with a tree nut allergy who sees a "may contain tree nuts" statement on delivery has not been given the information they needed to make a safe purchasing decision. Review your cross-contact risks formally — ideally in a documented allergen risk assessment — and reflect accurate, current precautionary statements on every product page in your Shopify store.
Managing Allergen Information Across Product Variants
Shopify's variant system creates a specific allergen management challenge that many food merchants underestimate. When a single product listing contains multiple variants — different flavours, sizes, or formats — each variant may have a distinct allergen profile. A biscuit available in plain and almond versions contains a tree nut allergen in one variant and not the other, but a single product page with a shared description can easily obscure that difference. Customers selecting variants quickly may not notice that allergen information has changed, or that the default display reflects a different variant than the one they selected.
The practical solution is to ensure allergen information updates dynamically when a customer selects a variant, rather than displaying static text that applies to only one option. This requires either custom theme development or an app that handles variant-level allergen data natively. Storing allergen data at the variant level in your allergen matrix — rather than at the product level — is the underlying discipline that makes dynamic display possible. If your current system records allergens per product title rather than per SKU or variant, rebuilding that structure is a worthwhile investment before your catalogue grows further.
For merchants with large variant sets, the manual effort of maintaining per-variant allergen data is substantial, which is why centralised tools matter. Allergen Matrix is built to handle variant-level allergen data within Shopify admin, so the information displayed to customers reflects the specific variant they are looking at. This is not a minor UX improvement — it is a compliance requirement for products with genuinely different allergen profiles across variants, and getting it wrong creates real liability.
Handling Recipe Changes and Supplier Substitutions
Recipe changes and supplier substitutions are among the most common causes of allergen incidents for small food businesses. A supplier runs out of a standard ingredient and substitutes an alternative that introduces a new allergen. A cost-saving reformulation changes the flour blend. A packaging run uses slightly different quantities of an ingredient that triggers a labelling threshold change. Each of these events should trigger a formal allergen review, but in practice, busy production environments mean these reviews are sometimes skipped or delayed — and online product pages are the last thing to be updated.
Building a documented change control process does not need to be bureaucratic to be effective. A simple checklist that accompanies every recipe or supplier change — covering physical label update, Shopify product page update, and allergen matrix update — catches the gaps that cause incidents. The checklist should name a responsible person for each step and require sign-off before the new product version is sold. For businesses selling wholesale or through multiple channels alongside Shopify, the checklist should also cover channel-specific updates, because inconsistency between your own website and a marketplace listing creates the same risk as inconsistency between label and page.
The timing of updates matters as well. Ideally, your Shopify product page reflects the allergen information for the current production batch — not the previous one, and not the next planned formulation. If a recipe change is in progress and batches with different allergen profiles are being sold simultaneously, consider using product variants or separate listings to distinguish them, with explicit allergen information for each. This level of rigour is unusual among small food businesses, but it reflects the standard that regulators and courts apply when incidents occur.
Training Your Team on Allergen Responsibilities
Allergen compliance is not solely a labelling function — it involves everyone who touches your products, your recipes, and your online store. In small food businesses, the person updating Shopify product pages may be a general administrator with no food safety background, while the person reformulating recipes may have no visibility into what the product page currently says. This disconnect is where compliance failures originate. Establishing clear ownership of allergen information — and ensuring that the person responsible for online content is notified of every recipe or ingredient change — is a structural fix that no software tool can substitute for.
Training does not require formal certification for every team member, but it does require everyone involved in the product lifecycle to understand why allergen accuracy matters and what their specific responsibilities are. For the person managing your Shopify catalogue, that means understanding the legal requirement for pre-purchase disclosure, knowing how to update allergen fields correctly, and understanding that a product page is a legal document as much as a marketing asset. For production staff, it means knowing how to flag an ingredient substitution as an allergen-relevant event, not just a procurement matter.
Document your training, even informally. A brief record of who was trained, when, and on what topics provides evidence of due diligence if a compliance question arises later. Regulators and courts look more favourably on businesses that can demonstrate a systematic approach to allergen management, even if a specific error occurred, than on businesses with no documented process at all. Building this culture early — before your catalogue grows and before an incident prompts a review — is the most effective form of allergen risk management available to small food merchants.
Try Allergen Matrix free at saltai.app — no credit card required.
SaltAI Team
SaltAI builds focused Shopify apps for food merchants and general merchants. Every app is tested in production at a real food store — including Vanda's Kitchen — before it ships.