Access control lets you decide exactly who can reach your storefront based on device type, country of origin, and whether the visitor is using a VPN or proxy. Settings are per-store and take effect immediately after you save. You need the Settings permission to change them.
Opening access control
- Go to Settings.
- Open the Access control card.
- A single panel opens with the Devices field, the VPNs or proxies blocked toggle, the Restriction Method selector, and the Countries picker. Make your changes and click Save.
Devices
The Devices multi-select chooses which device types may view your store. The four options are:
- Desktop
- Mobile
- Tablet
- Television
The device type is detected automatically from the visitor's browser. You must keep at least one device selected; saving with none selected returns the error "Please select at least one device". If all four are selected the restriction is cleared and every device is allowed (nothing is stored). A visitor on a device type you did not select is blocked from the store.
VPNs or proxies blocked
Turn on the VPNs or proxies blocked toggle to stop anyone whose connection is detected as a VPN or proxy from reaching your store. This check applies to every visitor regardless of country, not only the countries in your list, so a masked visitor is blocked even when no country restriction is set. It is most useful for cash-on-delivery stores that want to keep out orders placed from hidden locations.
Restriction Method
The Restriction Method selector controls how the country list is applied. The detected country comes from the visitor's IP location. There are three options:
- None - Allow traffic from all countries: no country filtering. This is the default and the Countries list is ignored.
- Blacklist - Allow traffic from all countries except the selected ones: every country is allowed except the ones you add to the Countries list.
- Whitelist - Allow traffic only from selected countries: only visitors whose detected country is in the Countries list get in. Everyone else is blocked.
If you pick None, or leave the Countries list empty, no country filtering is applied no matter which method is chosen (the list is saved as empty).
Countries
The Countries searchable multi-select is where you pick the countries the chosen method applies to. Each country shows its flag and name. A Selected Countries table underneath lists what is currently saved. Adding or removing a country only takes effect when you click Save. Submitting a country code the system does not recognize returns an inline error and saves nothing.
What a blocked visitor sees
Blocked visitors (wrong device, detected VPN or proxy, or a country the method excludes) are shown a forbidden page instead of your store. The page does not reveal which rule blocked them.
Verified search-engine crawlers (such as Googlebot, Bingbot, and Facebook's link-preview fetcher) skip all of these gates, so your store stays indexable and link previews keep working even with VPN blocking, a country whitelist, or device limits in place.
Saving
Click Save. A success message confirms the update and the rules apply on the next page load. If you submit an invalid device value or an unrecognized country, an inline error appears and nothing is saved. Setting everything back to default (all devices, no countries, VPN blocking off) removes the stored configuration entirely.
If legitimate visitors are blocked
- Confirm the Restriction Method is the mode you intend. Whitelist blocks everyone not on the list; blacklist blocks only the listed countries.
- Check whether the customer's country is, or is not, in the Countries list as expected.
- If a customer is blocked despite being in an allowed country, they may be on a VPN or proxy. Ask them to disconnect, or turn off VPNs or proxies blocked.
- Confirm the customer's device type is included in the Devices selection.
Related
Access control filters traffic by rules. To review or release individual IP and device bans, open Banned sessions in Settings.