5 MIN READ

The US Vape Crackdown and Shopify: Why Brands Are Migrating to Medusa

Shopify Payments prohibits nicotine. The PACT Act killed your shipping options. Here is what actually happens when a vape brand gets deplatformed — and the migration path off Shopify onto self-hosted Medusa.

BY SHUBHAM VERMAUPDATED
Illustration for “The US Vape Crackdown and Shopify: Why Brands Are Migrating to Medusa” — Vape

Every vape brand selling online in the United States is running on borrowed infrastructure. Not because the products are illegal — most are not — but because the platform layer underneath them was built by companies whose risk teams would rather lose your GMV than defend your category to a card network.

We have now moved several nicotine and high-risk merchants off hosted SaaS platforms. The pattern is always the same: everything is fine, and then one Tuesday it is not. This post is what we tell brands before that Tuesday.

What Shopify actually prohibits

There are two separate policies, and conflating them is where most brands get their timeline wrong.

The first is Shopify Payments' prohibited business list, which has long named tobacco, e-cigarettes, e-liquid and related products. This is not really Shopify's rule — it is inherited from the acquiring banks and card network rules that sit behind Shopify Payments. If you sell nicotine, you cannot use Shopify Payments. Full stop.

The second is Shopify's Acceptable Use Policy and Terms of Service, which govern whether you can use the platform at all. Historically, nicotine merchants have operated on Shopify by bolting on a third-party high-risk gateway and paying the extra transaction fee Shopify charges for not using Shopify Payments. That works right up until a policy review, a chargeback spike, or a complaint puts the store in front of a human.

The practical consequence is that a vape brand on Shopify is running with:

LayerWho controls itWhat happens if they say no
Storefront and checkoutShopifyStore goes offline; theme and content are exportable, checkout is not
PaymentsThird-party high-risk PSPRevenue stops; funds may be held 90–180 days
Customer and order dataShopify (CSV export)Recoverable, but only if you exported before suspension
SubscriptionsApp vendor on Shopify's APITokens are gateway-bound; often non-portable
Domain and emailYouThe only part nobody can take

Three of those five rows are held by companies with no obligation to keep you. That is the actual risk, and it is not priced into the monthly plan.

The regulatory layer that changed everything

The platform question sits on top of a legal one that shifted sharply in 2021.

The PACT Act — the Prevent All Cigarette Trafficking Act — was extended to cover ENDS (electronic nicotine delivery systems) through the Consolidated Appropriations Act, 2021. The practical effects for a direct-to-consumer brand:

  1. USPS will not ship ENDS to consumers, outside narrow exceptions requiring an approved application.
  2. FedEx, UPS and DHL each announced they would stop carrying vapor products in 2021, pushing merchants onto age-verified regional couriers and specialist logistics.
  3. Registration and reporting obligations apply — with the ATF, and with the tax administrator of every state you ship into, on a monthly cadence.
  4. Delivery must be age-verified, with an adult signature at handover, on top of verification at checkout.

Layer on Tobacco 21 (federal minimum age of 21 since December 2019), the FDA's PMTA regime — where products lacking marketing authorisation are subject to enforcement — and state-level flavour restrictions such as California's Proposition 31, and the compliance surface is enormous.

The reason this matters for a platform decision is simple: none of these requirements are things a generic SaaS checkout will implement for you. Monthly per-state reporting, adult-signature routing, PMTA-status flags on variants, flavour bans that vary by ship-to address — these are custom commerce logic. On a closed platform you approximate them with apps. On an open one you build them properly.

Why the answer is usually Medusa

Medusa is an open-source, TypeScript-native commerce platform. You run it on your own infrastructure, against your own Postgres database. There is no vendor whose terms of service can end your business, because there is no vendor.

For a regulated category, four properties matter more than anything on a feature comparison:

  • You own the database. Products, customers, orders and subscriptions live in Postgres that you control. A payment processor dropping you becomes an integration change, not an extinction event.
  • Payments are pluggable. Medusa treats payment providers as modules. Running two high-risk PSPs simultaneously — one primary, one warm standby — is an afternoon of work, not a replatform. See payment providers in Medusa.
  • Business logic is first-class. Age verification, per-state shipping rules, PACT reporting exports and flavour-ban enforcement are workflows and custom modules, not app-store compromises.
  • Nothing phones home. No usage-based platform fee, no review of what you sell.

The trade-off is real and worth stating plainly: you now own uptime, security patching and deployment. That is a genuine cost. For a brand doing meaningful revenue in a category that platforms actively avoid, it is a much smaller cost than being switched off.

What a state-restriction rule looks like in practice

Here is the shape of the thing you cannot express in a hosted checkout — a workflow step that rejects a cart whose contents are not permitted at the destination:

src/workflows/steps/validate-shipping-restrictions.tsts
import { createStep, StepResponse } from "@medusajs/framework/workflows-sdk"
import { MedusaError } from "@medusajs/framework/utils"

type Input = {
  cart_id: string
  state_code: string
}

export const validateShippingRestrictionsStep = createStep(
  "validate-shipping-restrictions",
  async ({ cart_id, state_code }: Input, { container }) => {
    const query = container.resolve("query")
    const compliance = container.resolve("compliance")

    const { data: [cart] } = await query.graph({
      entity: "cart",
      fields: ["id", "items.*", "items.variant.*"],
      filters: { id: cart_id },
    })

    const rules = await compliance.getStateRules(state_code)

    const blocked = cart.items.filter((item) =>
      rules.blockedFlavors.includes(item.variant.flavor_profile) ||
      (rules.requiresPmta && !item.variant.pmta_authorized)
    )

    if (blocked.length) {
      throw new MedusaError(
        MedusaError.Types.NOT_ALLOWED,
        `Not available for delivery to ${state_code}: ${
          blocked.map((i) => i.title).join(", ")
        }`
      )
    }

    return new StepResponse({ validated: true })
  }
)

That is ordinary application code, reviewable and testable, running inside your checkout. The equivalent on a closed platform is a script tag and a prayer.

The migration, step by step

We run this as a six-to-ten week project depending on catalog size and subscription complexity. The full technical detail lives in the Shopify to Medusa migration guide; here is the shape of it for a regulated brand.

1. Export everything, today

Before anything else. Products, variants, inventory, customers, orders, and — critically — your full order history. Do this even if you never migrate. An export you have is worth more than a platform you rent.

2. Model the compliance domain first

Most migrations model the catalog first. For nicotine, invert it. Age gates, PMTA status, per-state rules, licence numbers and reporting obligations become a custom module before a single product is imported, because they constrain the data model.

3. Line up payments early

High-risk underwriting takes weeks, not days. Start applications at project kickoff. Plan for two providers from day one — the second one is insurance, and Medusa's provider abstraction makes carrying both cheap.

4. Migrate catalog, then customers, then orders

Products and variants first, so orders have something to reference. Customers next — passwords do not migrate; plan a reset flow. Historical orders last, imported as records rather than replayed through the checkout.

5. Rebuild the storefront on Next.js

A Medusa storefront in Next.js gives you the age gate as a real route guard, ISR for catalog pages, and full control of storefront SEO — including the redirect map that decides whether you keep your rankings.

6. Map redirects before you cut over

This is where replatforms lose money. Shopify's URL structure (/products/, /collections/) is not Medusa's. Every ranking URL needs a 301 to its new home, in place on launch day.

7. Cut over on a low-traffic window, with a rollback

DNS switch, smoke test the full purchase path including age verification and adult-signature shipping selection, then watch error rates for 48 hours.

What it costs

Rough numbers for a mid-size brand, so nobody has to guess:

Line itemShopify (high-risk)Self-hosted Medusa
Platform feePlan fee + surcharge for external gatewayNone
HostingIncluded~$100–400/mo (app, Postgres, Redis, CDN)
PaymentsHigh-risk PSP rateSame high-risk PSP rate
Apps / subscriptions$200–800/mo typicalBuilt in, or self-hosted
BuildTheme cost6–10 week engagement
Compliance logicConstrained by platformOwned outright
Deplatforming riskStructuralRemoved

The build is a real capital cost. It is also the last time you pay it, and the fee curve stops scaling with your revenue.


If you sell nicotine online in the US, the question is not whether the platform layer is a risk. It is whether you would rather migrate on your schedule or theirs. Talk to us about a migration — we have done this for brands in exactly this position.

Frequently asked questions

Does Shopify allow vape and e-cigarette stores?

Shopify Payments' prohibited business list covers tobacco, e-cigarettes and e-liquid, so nicotine merchants cannot use it and must run a third-party high-risk gateway. Whether a given store may use the wider Shopify platform is governed separately by Shopify's Terms of Service and Acceptable Use Policy, and enforcement varies. Many nicotine brands have operated on Shopify for years; others have been suspended. Treat continued access as a business risk, not a guarantee.

What did the PACT Act change for online vape sales?

The Consolidated Appropriations Act, 2021 extended the PACT Act to cover ENDS products. The practical effects were that USPS will not ship them to consumers outside a narrow exception process, the major private carriers stopped carrying vapor products in 2021, sellers must register with the ATF and with state tax administrators and file monthly reports, and deliveries require age verification with an adult signature.

Can I keep my SEO rankings when migrating from Shopify to Medusa?

Yes, if you build the redirect map before launch. Shopify's `/products/<handle>` and `/collections/<handle>` URLs need 301 redirects to their Medusa equivalents, and your metadata, structured data and internal links need to carry over. Rankings usually dip for two to four weeks and recover. Migrations that skip the redirect map are the ones that do not recover.

How long does a Shopify to Medusa migration take?

Six to ten weeks for a mid-size brand with a few thousand SKUs. Catalog and customer migration is fast; the time goes into checkout, payment provider integration, subscription rebuilds and — for regulated categories — the compliance logic. Subscriptions are the single biggest schedule risk, because payment tokens are usually bound to the old gateway.

Do I need a developer to run Medusa?

Yes. Medusa is a framework you deploy and operate, not a hosted store builder. You need someone who can deploy a Node application, run Postgres, and maintain the codebase — in-house or an agency on retainer. If you are not doing meaningful revenue yet, the hosted platform is genuinely the right call until you are.

What payment processors work with Medusa for high-risk merchants?

Any of them. Medusa's payment provider abstraction means you integrate the PSP that underwrote you, rather than choosing from an approved list. Brands in this category typically run a specialist high-risk acquirer as primary with a second provider configured as a fallback, so a single account closure does not stop revenue.

[ Keep reading ]