Buyer clicks an ad for acme.com. Lands on acme.com. Adds to cart on acme.com. Hits Buy — redirects to checkout.acme.com. Enters card, pays, gets a receipt from a descriptor called ACME on their card statement. At no point does the buyer see a third-party checkout URL, a gateway brand, a marketplace domain, or a "powered by X" giveaway. Your brand at the URL bar, on the page, in the descriptor. That is anonymous checkout.
Three third-party URL patterns leak provider identity to the buyer mid-checkout:
shop.app or Shopify's hosted checkout subdomain. Not the merchant's brand.whop.com/checkout/… or similar third-party marketplace domain. Definitely not the merchant's brand.Anonymous checkout replaces all three with a subdomain of the merchant's own brand. The buyer never sees any of them.
Trust survives a checkout only when the domain matches the domain the buyer clicked. A buyer who saw an ad for acme.com, clicked through and added to cart on acme.com, gets a domain-consistency signal when checkout also runs on acme.com (or a clear subdomain of it). Any other URL — shop.app, whop.com, a random gateway domain — breaks that signal. Some buyers close the tab at that break point. Others complete the checkout but at a lower approval rate because their card issuer sees a cross-context transaction pattern.
Own-domain checkout closes that specific leak. Domain, TLS certificate, checkout page design and descriptor are consistent across ad, storefront, checkout and receipt.
Scope of buyer-facing anonymity. The buyer sees the merchant's brand. Behind the scenes, the acquirer sees an authorization request on the merchant's MID under the merchant's true product category, exactly as the acquirer's underwriting expected. Shopify Admin sees the order record. The bank sees the settlement. Anonymous checkout is a buyer-visible cloak of the provider, not a mask of transaction data to the parties that see the money.
The descriptor that appears on the buyer's card statement is the merchant descriptor configured on your MID with your acquirer. It reads as your brand (ACME * ORDER123 or similar), not as CascadeCheckout, not as the gateway processor, not as a marketplace intermediary. Descriptor language is set at MID onboarding — we do not modify it, but we do preserve it end-to-end.
The anonymity cloak requires suppressing Shopify Payments' native express buttons (Shop Pay, Apple Pay, Google Pay when wired through Shopify Payments). If those buttons rendered, they would resolve to Shopify Payments' hosted express flow and break the URL consistency. Suppression is on by default. Where your underlying gateway supports Apple Pay or Google Pay through its own tokenization, wallet buttons can be re-enabled inside the cascaded checkout page — same brand, same URL, same descriptor, wallet capture through your gateway.
Anonymous checkout (buyer-facing) is one of four cloak layers. The others:
The URL bar shows your brand's subdomain. The TLS certificate is issued to your brand. The checkout page design matches your storefront. The descriptor on the buyer's card statement is your merchant descriptor from your MID. From ad click to receipt, the buyer never sees a third-party checkout provider or a gateway brand.
Yes. Post-capture the order writes to Shopify Admin API tagged [cascade] with full buyer, line items and shipping. Shopify apps, ERPs, fulfillment integrations, subscription tools and analytics keep firing on the standard order-created event.
In tested drops it usually lifts conversion. Domain consistency from ad to checkout is a trust signal. Buyers who click an ad for acme.com convert better on checkout.acme.com than on a marketplace URL under a third-party's domain.
Shop Pay is a Shopify Payments product and is suppressed by the cloak layer. Apple Pay and Google Pay depend on the underlying gateway — where your gateway supports wallet capture, the cascade keeps working with wallets. When Shopify Payments is off the table, so is Shop Pay by definition.
Your brand at every touchpoint. No provider giveaway.