Everything you need to set up and get the most out of Locket. Browse by topic or email us directly.
Can't find the answer below? Send us an email with your shop URL and a description of the issue. We aim to reply within one business day (AEST, Monday–Friday).
support@beauii.com.auLocket lets you password-protect specific products on your Shopify store — without locking your entire store. Customers can browse freely, but when they reach a protected product page they'll see a password prompt instead of the Add to Cart and Buy Now buttons. Once they enter the correct password, the buttons become visible for the rest of their session.
Common uses:
Locket uses Shopify's Theme App Extension system, so you need to enable it in your theme once. It then runs automatically on every page and survives theme updates.
You only need to do this once. The Locket dashboard will show a green tick next to "Theme embed active" once it detects the embed is enabled.
BEAUTY90).Visit the product on your storefront to confirm the password prompt appears.
Follow the same steps as creating a single-product lock, but in the Add products picker select multiple products at once. All selected products will share the same lock and password.
Locking by collection means every product inside that collection is automatically protected — including any products added to it in the future.
Note: If a product belongs to multiple collections and only one of those collections is locked, the product will still be locked. Locket applies the lock if any of a product's collections are targeted.
Locking by vendor protects all products where the Vendor field matches your chosen value — useful if you stock a brand that requires restricted online sales.
Tip: Check your product vendor spelling under Products → [any product] → Organisation → Vendor. If your products say "ZO Skin Health" and you type "ZO skin health", the lock will not apply.
Locking by tag protects all products that have a specific tag. This is useful when you want to group products across different collections or vendors under one access rule.
Tip: Product tags are case-sensitive. Verify the exact tag under Products → [any product] → Tags.
Yes. You can add multiple targets of different types to a single lock — for example, a specific product and a vendor. A product is locked if it matches any of the lock's targets.
On the Locks list page, each lock has an Enabled toggle. Switching it off pauses the lock — the password prompt disappears from your storefront — without deleting any settings. Toggle it back on to reactivate instantly. You can also toggle from inside the lock editor.
Deleting a lock removes its targets, passwords, and magic links permanently. This cannot be undone. If you just want to pause it, toggle it off instead.
The introduction text is a short message shown to customers above the password field on a locked product page. Use it to explain why the product is restricted, or give customers instructions on how to get access.
If you leave the intro text blank on a lock, Locket uses the shop-wide default text you set in Settings. If neither is set, no intro text is shown.
Wrap the text in double asterisks:
**your text here**
Example:
Enter your **trade password** below to continue.
Displays as: Enter your trade password below to continue.
Use this format: [link text](https://your-url.com)
Example:
Visit our [trade portal](https://yourstore.com/pages/trade) to register for access.
Displays as: Visit our trade portal to register for access.
Use the same link format but with mailto: before the email address:
[hello@yourstore.com](mailto:hello@yourstore.com)
Example:
Email us at [hello@yourstore.com](mailto:hello@yourstore.com) to request the password.
Displays as: Email us at hello@yourstore.com to request the password.
Press Enter to start a new line. Locket preserves line breaks exactly as you type them.
Example:
This product is available to verified trade clients only.
Please contact us to request access.
The blank line between the two paragraphs creates a visual gap in the storefront.
Yes — all formatting options work together. Example:
This product is restricted to **verified stockists only**.
To apply for access, email [trade@yourstore.com](mailto:trade@yourstore.com) or visit our [wholesale portal](https://yourstore.com/pages/wholesale).
Passwords are stored using argon2id hashing — the plaintext is never saved anywhere.
Passwords cannot be edited in place — to change one:
Customers who already unlocked the product with the old password will remain unlocked for up to 24 hours. After that, they will need to enter the new password.
Yes — on the Pro plan you can add multiple passwords to a single lock. This is useful when different groups of customers need their own password (e.g. a wholesale team and a VIP group).
Any valid password will unlock the product. Customers only need to know their own group's password.
Yes — on the Pro plan, each password has its own Enabled toggle. Disabling a password means it will no longer unlock the product, but you can re-enable it later without re-entering it. Useful for temporarily revoking access to a specific group.
Yes. Passwords are case-sensitive. If your password is Summer2025, entering summer2025 will not unlock the product. Make sure you share the password to customers with the correct capitalisation.
The exemption list lets specific customers bypass all locks in your store without needing a password. This is useful for staff, trusted wholesale accounts, or VIP customers who should always have full access. The customer must be logged in to their Shopify account for the exemption to apply.
That customer will now see all locked products without being prompted for a password, as long as they are logged in.
The customer will be asked for a password on their next visit to a locked product.
No — exemptions apply to all locks in your store. If you need per-lock access control, use Customer Tag Auto-Unlock (Pro plan) instead, which lets you assign different Shopify customer tags to different locks.
Tag auto-unlock lets you automatically grant access to a specific lock based on a customer's Shopify customer tag. Any logged-in customer with a matching tag will see locked products without being prompted for a password. Unlike the exemption list, this is per-lock — so customer group A can unlock Lock 1 and customer group B can unlock Lock 2.
wholesale or vip-2025).Any logged-in customer with that tag can now view the locked product without a password.
Yes. A customer with any of the listed tags will be auto-unlocked. Simply add multiple tags to the same lock.
A magic link is a special URL that unlocks a lock automatically when clicked — no password required. You generate the link in Locket and share it however you like: email, SMS, QR code, or anywhere else. When a customer clicks it, they are instantly taken to your store with the lock lifted for their session.
Good uses: email marketing campaigns, QR codes at events, influencer access, press previews, trade show follow-ups, VIP drops.
/products/my-product), an Expiry date, or a Use limit.The customer does not need an account or a password. The unlock lasts for 24 hours.
Expiry date: When generating a magic link, set an expiry date and time. After that moment, the link automatically stops working. Useful for closing presale access at a specific moment.
Use limit: Set a maximum number of clicks. Once reached, the link stops working. Useful for exclusive drops where you want to cap how many people get early access.
Both can be set together — the link stops whichever condition is reached first.
Each magic link shows a use count in the Locket admin next to the link label. This tells you how many times the link has been successfully clicked.
Disable: Toggle the link off. The URL will return an error if clicked. You can re-enable it at any time — the URL remains the same.
Delete: Click the delete (trash) icon. This is permanent — the URL will immediately stop working and cannot be recovered. If you need the link again you'll need to generate a new one (with a new URL).
A lock expiry date tells Locket to automatically lift the lock at a specific date and time. After the expiry, the locked products become publicly accessible without you needing to manually disable the lock. The lock itself is not deleted — it's simply treated as disabled until you remove the expiry or set a new one.
To set: Open the lock, find the Expiry date field, select the date and time, and click Save.
To remove: Clear the Expiry date field and click Save. The lock will remain active indefinitely.
| Feature | Free | Starter | Pro |
|---|---|---|---|
| Active locks | 1 | Unlimited | Unlimited |
| Product targets | ✓ | ✓ | ✓ |
| Collection targets | — | ✓ | ✓ |
| Vendor targets | — | ✓ | ✓ |
| Tag targets | — | ✓ | ✓ |
| Custom intro text per lock | — | ✓ | ✓ |
| Customer exemption list | — | ✓ | ✓ |
| Multiple passwords per lock | — | — | ✓ |
| Password labels | — | — | ✓ |
| Customer tag auto-unlock | — | — | ✓ |
| Magic unlock links | — | — | ✓ |
| Lock expiry dates | — | — | ✓ |
| Free trial | — | 30 days | 30 days |
All features of the new plan are available immediately after confirmation. Billing is handled by Shopify and appears on your regular Shopify invoice.
Your configuration is preserved, but features outside your new plan become inactive:
Work through these checks in order:
Ctrl+Shift+R (Windows) or Cmd+Shift+R (Mac) to clear the cache.Ask the customer to:
If the issue persists, contact support@beauii.com.au with the customer's browser and device details.
Unlock sessions last for up to 24 hours or until the customer closes their browser. If they cleared cookies or switched devices, they'll need to enter the password again. This is expected behaviour for security reasons.
The Locket embed must be enabled in each theme separately. Go to Online Store → Themes → Customise → App embeds and re-enable Locket in your new theme, then save.
Check each of the following:
If none of these apply, email support@beauii.com.au with the lock name and link label.
Locket automatically hides Quick Add buttons on collection, search, and home pages for locked products. This runs via JavaScript and may take a brief moment after the page loads.
If Quick Add buttons remain visible: confirm the theme embed is enabled, confirm the product is targeted by an active lock. Some custom Quick Add implementations use non-standard HTML — if the issue persists, email support@beauii.com.au with your theme name.
All passwords are hashed using argon2id before being saved — a modern, memory-hard algorithm designed specifically for password storage. The plaintext password is never stored anywhere: not in the database, not in logs, not in Shopify metafields. Even Beauii cannot retrieve your passwords.
Once a customer successfully enters a password or clicks a magic link, their unlock session lasts 24 hours. After that, they will need to enter the password again. The unlock is tied to that browser and device — it does not carry over to other browsers, devices, or incognito windows.
Locket limits password attempts to 10 per IP address per 15 minutes. If that limit is reached, further attempts are blocked for the remainder of the window. We recommend using a reasonably complex password — avoid single words or obvious combinations.
All data associated with your store — locks, password hashes, targets, magic links, exemptions — is permanently deleted within 48 hours of uninstall, in compliance with Shopify's GDPR requirements.
Yes — create a separate lock for each product (or group of products) and set a different password on each. Each lock is fully independent.
The product will be locked. Locket checks all active locks — if any lock targets the product, it is protected. The customer only needs to unlock one of the matching locks to gain access.
Locket hides the Add to Cart and Buy Now buttons and Quick Add buttons for locked products — it does not remove products from listings or search results. Customers can still browse to the product page; they just see a password prompt instead of the purchase options. If you need to hide products entirely, Shopify's draft status may be a better fit.
Yes — Locket can complement Shopify B2B. You can lock your trade catalogue by vendor or collection, then use the customer exemption list or customer tag auto-unlock (Pro) so verified buyers never see the password prompt.
Locket uses Shopify's Theme App Extension system, which requires a standard Liquid-based Shopify theme. Headless storefronts using the Storefront API or Hydrogen are not currently supported.
Not directly — Locket works at the product level, not geographically. For geographic restrictions, you would need Shopify Markets or a dedicated geo-blocking app used alongside Locket.
Locket's password prompt runs in the browser storefront. The Shop app uses its own interface and may not apply the lock in all cases. We recommend testing your specific setup and contacting us if you encounter issues.
Email us at support@beauii.com.au with your shop URL and a description of the issue. We're a small Sydney team and aim to respond within one business day (AEST, Monday–Friday).